# Help needed for reading Logs

**URL:** https://discuss.elastic.co/t/help-needed-for-reading-logs/65959
**Category:** Logstash
**Created:** [November 14, 2016, 10:48am UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959 "2016-11-14T10:48:11Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![Haribaskar](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Haribaskar](https://discuss.elastic.co/u/Haribaskar)
#### Post date: [November 14, 2016, 10:48am UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/1 "2016-11-14T10:48:12Z")

</div>

Hi there,  
Could someone guide me on how to use pipeline(|) as separator for the Logs.  
I tried gsub. But everytime I use gsub, it says non ascii character found in the log.  
Any help would be appreciated..

Regards,  
Hari

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [November 14, 2016, 11:15am UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/2 "2016-11-14T11:15:27Z")

</div>

Please show an example of the kind of log you want to process. Please show us what you've tried so far. It's not clear why you'd want to use gsub. It sounds like a simple csv filter would work.

---

<div class="post-metadata">

### Author: ![Haribaskar](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Haribaskar](https://discuss.elastic.co/u/Haribaskar)
#### Post date: [November 14, 2016, 12:36pm UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/3 "2016-11-14T12:36:31Z")

</div>

Hi Magnus,

This is my sample log :

21674|glsServer.ec|ServerInit|351|2016-10-23 11:08:02|LOG|lCnt=0, service\_name=ApplPref  
21674|glsServer.ec|ServerInit|351|2016-10-23 11:08:02|LOG|lCnt=1, service\_name=ApplList

And am trying this is filter:  
filter {  
mutate {  
gsub =\> [  
#Replace pipeline  
"message","|"," "  
]  
}  
grok {  
match =\> { "message" =\> "%{NUMBER:col1} %{WORD:col2} %{WORD:col3} %{NUMBER:col4} %{WORD:col5} %{WORD:col6} %{WORD:col7}" }  
}

Is there any direct way to make it accept the pipeline?

---

<div class="post-metadata">

### Author: ![txisme](https://avatars.discourse-cdn.com/v4/letter/t/dbc845/32.png) [@txisme](https://discuss.elastic.co/u/txisme)
#### Post date: [November 14, 2016, 1:22pm UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/4 "2016-11-14T13:22:04Z")

</div>

you dont have to change do pipe(|).

you can write the pipe in the grok pattern like this: |

so you would have something like %{NUMBER:col1}|%{WORD:col2}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [November 14, 2016, 1:48pm UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/5 "2016-11-14T13:48:41Z")

</div>

Indeed, escape the `|` or just use the csv filter instead of the grok filter.

---

<div class="post-metadata">

### Author: ![Haribaskar](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Haribaskar](https://discuss.elastic.co/u/Haribaskar)
#### Post date: [November 15, 2016, 12:17pm UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/6 "2016-11-15T12:17:35Z")

</div>

Hi,

Thanks much. It works. Now that I have followed the instructions and avoided the errors, I am still not able to see the logs in Kibana UI. I do not get any errors when pushing the Logs in. Any idea what could have went wrong? I tried making changes in the Log file once logstashed in. No changes in the window however.

Thanks in advance,  
Hari

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [November 15, 2016, 12:36pm UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/7 "2016-11-15T12:36:21Z")

</div>

What does your configuration look like? Exactly how did you change the file?

---

<div class="post-metadata">

### Author: ![Haribaskar](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Haribaskar](https://discuss.elastic.co/u/Haribaskar)
#### Post date: [November 18, 2016, 6:43am UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/8 "2016-11-18T06:43:55Z")

</div>

Hi there,

Sorry for my delay response. Was little busy in catching up other things. The things worked perfectly. Thanks for all your inputs. Although I am with a new query here.

I want to use URL search using current timestamp. To be precise, I want to take logs that have fallen in the last 15 mins of time.

Am looking for something like:

[http://localhost:9200/\_search?q="sql"](http://localhost:9200/_search?q=%22sql%22) AND @timestamp:"2016-11-16T17:33:19"

Can someone help what should i use in the @timestamp parameter to get the specified result

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [November 18, 2016, 6:53am UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/9 "2016-11-18T06:53:08Z")

</div>

Please post Elasticsearch questions in the Elasticsearch category.

---

<div class="post-metadata">

### Author: ![Haribaskar](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Haribaskar](https://discuss.elastic.co/u/Haribaskar)
#### Post date: [November 18, 2016, 7:11am UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/10 "2016-11-18T07:11:51Z")

</div>

Sure thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 16, 2016, 7:11am UTC](https://discuss.elastic.co/t/help-needed-for-reading-logs/65959/11 "2016-12-16T07:11:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
