# How i can match and replace the log file data in logstash

**URL:** <https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059>\
**Category:** Logstash\
**Created:** [March 27, 2019, 7:30am UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059 "2019-03-27T07:30:54Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mac099](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mac099/32/42853_2.png) [@Mac099](https://discuss.elastic.co/u/Mac099)\
**Post date:** [March 27, 2019, 7:30am UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/1 "2019-03-27T07:30:54Z")

</div>

```
input {

```

beats {  
port =\> 5044  
}  
}  
filter {  
grok {

match=\>{'message'=\>'%{DATESTAMP:time} %{LOGLEVEL:level} '}  
mutate { add\_tag =\> "string in field" }

}  
}  
output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

}  
}

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [March 27, 2019, 9:34am UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/2 "2019-03-27T09:34:44Z")

</div>

It's always a good idea to write what you are trying to achieve if you want help. This post does not say anything in regards to what you have tried or are trying to achieve. You say you want to replace something.. Your filter has a grok, but you don't even include an example log line..

---

<div class="post-metadata">

**Author:** ![Mac099](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mac099/32/42853_2.png) [@Mac099](https://discuss.elastic.co/u/Mac099)\
**Post date:** [March 28, 2019, 4:55am UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/3 "2019-03-28T04:55:58Z")

</div>

message : iso.3.6.1.6.3.1.1.4.1.0 = OID: iso.3.6.1.4.1.8072.2.3.0.77  
i have this message and i am not able to get any idea about how to replace this with any string

---

<div class="post-metadata">

**Author:** ![staodd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/staodd/32/24509_2.png) [@staodd](https://discuss.elastic.co/u/staodd)\
**Post date:** [March 28, 2019, 2:27pm UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/4 "2019-03-28T14:27:07Z")

</div>

You are still saying nothing about what you are trying to do..

---

<div class="post-metadata">

**Author:** ![Mac099](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mac099/32/42853_2.png) [@Mac099](https://discuss.elastic.co/u/Mac099)\
**Post date:** [March 28, 2019, 2:49pm UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/5 "2019-03-28T14:49:12Z")

</div>

```auto
mutate {
    gsub => [
      "message", "iso 1.78.1000.23", "time to check"
    ]
  }

```

I am not able to replace the iso 1.78.1000.23  
With time to check text  
But i can replace it by one word text like cold

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 28, 2019, 3:28pm UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/6 "2019-03-28T15:28:24Z")

</div>

Your example message does not contain the string you are trying to match. I would not expect the filter to do anything in that case.

---

<div class="post-metadata">

**Author:** ![Mac099](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mac099/32/42853_2.png) [@Mac099](https://discuss.elastic.co/u/Mac099)\
**Post date:** [March 28, 2019, 3:51pm UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/7 "2019-03-28T15:51:50Z")

</div>

It can be replaced by single word but not by multiple words or sentence

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 28, 2019, 4:04pm UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/8 "2019-03-28T16:04:00Z")

</div>

Can you provide an example of a mutate filter that fails including the message that it fails to modify?

---

<div class="post-metadata">

**Author:** ![Mac099](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mac099/32/42853_2.png) [@Mac099](https://discuss.elastic.co/u/Mac099)\
**Post date:** [March 28, 2019, 4:49pm UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/9 "2019-03-28T16:49:31Z")

</div>

Above is the example of mutate filter where it fails

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 28, 2019, 6:32pm UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/10 "2019-03-28T18:32:34Z")

</div>

> [@Badger](#):
>
> Your example message does not contain the string you are trying to match. I would not expect the filter to do anything in that case.

As I said, your example message does not contain the string you are trying to match, so I would not expect the filter to do anything in that case.

---

<div class="post-metadata">

**Author:** ![Mac099](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mac099/32/42853_2.png) [@Mac099](https://discuss.elastic.co/u/Mac099)\
**Post date:** [March 29, 2019, 2:49am UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/11 "2019-03-29T02:49:31Z")

</div>

I just want to replace my one iso..... With the string

---

<div class="post-metadata">

**Author:** ![Mac099](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mac099/32/42853_2.png) [@Mac099](https://discuss.elastic.co/u/Mac099)\
**Post date:** [March 29, 2019, 9:45am UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/12 "2019-03-29T09:45:10Z")

</div>

solved....thnx

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2019, 9:45am UTC](https://discuss.elastic.co/t/how-i-can-match-and-replace-the-log-file-data-in-logstash/174059/13 "2019-04-26T09:45:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
