# How can split the log data source separete by , in that result field i need to split multiple field

**URL:** <https://discuss.elastic.co/t/how-can-split-the-log-data-source-separete-by-in-that-result-field-i-need-to-split-multiple-field/171436>\
**Category:** Logstash\
**Created:** [March 8, 2019, 6:35am UTC](https://discuss.elastic.co/t/how-can-split-the-log-data-source-separete-by-in-that-result-field-i-need-to-split-multiple-field/171436 "2019-03-08T06:35:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![muralasandeep](https://avatars.discourse-cdn.com/v4/letter/m/73ab20/32.png) [@muralasandeep](https://discuss.elastic.co/u/muralasandeep)\
**Post date:** [March 8, 2019, 6:35am UTC](https://discuss.elastic.co/t/how-can-split-the-log-data-source-separete-by-in-that-result-field-i-need-to-split-multiple-field/171436/1 "2019-03-08T06:35:45Z")

</div>

Hi Every one,

This is Sandeep ,

My data source is like this (1st row )

"1102417","2018-11-01 02:00:02","ERROR","QUERY-\> update emp set statues='No-Show' where DATE\_FORMAT(tpam\_app\_start\_epoch,'%Y-%m-%d') \< (CURDATE() - INTERVAL 2 DAY) AND tpam\_status\<\>'Attended' AND tpam\_app\_id\<\>'' ERROR-\> Table 'emp' doesn't exist","Sytem"

and another row is like this (2nd row)

"1112311","2018-11-03 18:45:25","ERROR","QUERY-\> insert emp (log\_datetime,log\_type,log\_component,log\_message,log\_user) values ('2018-11-03 18:45:25','4','CORE','New Appointment (Client Mobile -\> 972\* Doctor id -\> 3451 Master Schedule id -\> 1238) : Unable to send email to [abc@gmail.com](mailto:abc@gmail.com) (Doctor) Reason: Email template is not enabled for abc's Clinic Institution','System') ERROR-\> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 's Clinic Institution','System')' at line 1

and another row is like this (3rd row)

"1103849","2018-11-01 08:00:49","ERROR","CRON (Appointment reminder today - Client): Failed to send email to Reason-\>","System"

here data source is separate by ,(comma) not .csv file it is text file ,  
i need to split each field separate by ,(comma) like

Log\_id :"1102417"  
date: "2018-11-01 02:00:02"  
Log\_type: "ERROR"  
Log\_message: "QUERY-\> update emp set statues='No-Show' where DATE\_FORMAT(tpam\_app\_start\_epoch,'%Y-%m-%d') \< (CURDATE() - INTERVAL 2 DAY) AND tpam\_status\<\>'Attended' AND tpam\_app\_id\<\>'' ERROR-\> Table 'emp' doesn't exist"  
Log\_user:"Sytem"

above results are separator by ,(comma) in those fields i need to split log\_message field into QUERY field and Error field etc ,

this is my expected results (from 1st row)

Log\_id :"1102417"  
date: "2018-11-01 02:00:02"  
Log\_type: "ERROR"  
Log\_message: "QUERY-\> update emp set statues='No-Show' where DATE\_FORMAT(tpam\_app\_start\_epoch,'%Y-%m-%d') \< (CURDATE() - INTERVAL 2 DAY) AND tpam\_status\<\>'Attended' AND tpam\_app\_id\<\>'' ERROR-\> Table 'emp' doesn't exist"  
Query:"QUERY-\> update emp set statues='No-Show' where DATE\_FORMAT(tpam\_app\_start\_epoch,'%Y-%m-%d') \< (CURDATE() - INTERVAL 2 DAY) AND tpam\_status\<\>'Attended' AND tpam\_app\_id\<\>''  
Error: Table 'emp' doesn't exist"  
Log\_user:"System"

this is my expected results (from 2st row) diff is added some data in log\_message field like mobile no,id's etc

Log\_id: "1112311"  
date: "2018-11-03 18:45:25"  
Log\_type: "ERROR"  
Log\_message: "QUERY-\> insert emp (log\_datetime,log\_type,log\_component,log\_message,log\_user) values ('2018-11-03 18:45:25','4','CORE','New Appointment (Client Mobile -\> 9741\* Doctor id -\> 345 Master Schedule id -\> 1238) : Unable to send email to [abc@gmail.com](mailto:abc@gmail.com) (Doctor) Reason: Email template is not enabled for abc's Clinic Institution','System') ERROR-\> You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 's Clinic Institution','System')' at line 1

Query: insert emp (log\_datetime,log\_type,log\_component,log\_message,log\_user) values ('2018-11-03 18:45:25','4','CORE','New Appointment (Client Mobile -\> 9741\* Doctor id -\> 345 Master Schedule id -\> 1238) : Unable to send email to [abc@gmail.com](mailto:abc@gmail.com) (Doctor) Reason: Email template is not enabled for abc's Clinic Institution','System')

Error: You have an error in your SQL syntax  
Doctor id:3451  
Master Schedule id : 1238  
Client Mobile : 9712\*  
Log\_user:"system"

Log\_id:"1103849"  
date:"2018-11-01 08:00:49"  
Log\_type:"ERROR"  
Log\_message: "CRON (Appointment reminder today - Client): Failed to send email to Reason-\>"  
Query:"CRON (Appointment reminder today - Client):  
Error: Failed to send email to Reason-\>"  
Log\_user:"System"

some times log\_messaga is like this

Query-\> select \* from emp Error:Table doesn't exist (instead of Error -\>)

Pleace help from this problem .

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2019, 6:35am UTC](https://discuss.elastic.co/t/how-can-split-the-log-data-source-separete-by-in-that-result-field-i-need-to-split-multiple-field/171436/2 "2019-04-05T06:35:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
