# How to combine text file result?

**URL:** https://discuss.elastic.co/t/how-to-combine-text-file-result/49117
**Category:** Logstash
**Created:** [May 4, 2016, 2:09am UTC](https://discuss.elastic.co/t/how-to-combine-text-file-result/49117 "2016-05-04T02:09:53Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)
#### Post date: [May 4, 2016, 2:09am UTC](https://discuss.elastic.co/t/how-to-combine-text-file-result/49117/1 "2016-05-04T02:09:53Z")

</div>

I have some scheduled batch jobs running automatically during the night and will show the results in separate .txt files. Is there anyway to grab the data from the .txt file and consolidate them to display in kibana? Any tools or reference .conf?

Here is the case:(Windows)

Job Code.txt

> job\_id=0001,description=Ship data from server to elknode1  
> job\_id=0002,description=Ship data from server to elknode2  
> job\_id=0003,description=Ship data from server to elknode3  
> job\_id=0004,description=Ship data from server to elknode4

Job Status.txt

> job\_id=0001,result=OK  
> job\_id=0002,result=Error: Msg...  
> job\_id=0003,result=OK  
> job\_id=0004,result=OK

Here is my very basic logstash.conf file I knew what should be written

> input{  
> file{  
> path =\> "C:/Job/\*.txt"  
> start\_position =\> "beginning"  
> }  
> }  
> filter{}  
> output{  
> elasticsearch { hosts =\> ["localhost:9200"] }  
> stdout { codec =\> rubydebug }  
> }

How can I combine the two into one

Thanks

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [May 4, 2016, 8:44am UTC](https://discuss.elastic.co/t/how-to-combine-text-file-result/49117/2 "2016-05-04T08:44:56Z")

</div>

I think the [collate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-collate.html) is what comes closest to what you need.

---

<div class="post-metadata">

### Author: ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)
#### Post date: [May 4, 2016, 9:25am UTC](https://discuss.elastic.co/t/how-to-combine-text-file-result/49117/3 "2016-05-04T09:25:49Z")

</div>

I don't really know how to make the filter part. It keeps giving result like this.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/6/6bff440bb8af73d61cb74380a150efc2296f13ad.PNG)

This is my filter part in conf file, How can I separate the 3 fields to be seen in kibana

> filter{  
> grok{ match =\> {"message" =\> ["JobID: %{NOTSPACE:job\_id}","description: %{NOTSPACE:description}","result: %{NOTSPACE:message}"]}  
> add\_field =\> {  
> "JobID" =\> "%{job\_id}"  
> "Description" =\> "%{description}"  
> "Message" =\> "%{message}"  
> }  
> }  
> if [job\_id] == "0001" {  
> aggregate {  
> task\_id =\> "%{job\_id}"  
> code =\> "map['time\_elasped']=0"  
> map\_action =\> "create"  
> }  
> }  
> if [job\_id] == "0003" {  
> aggregate {  
> task\_id =\> "%{job\_id}"  
> code =\> "map['time\_elasped']=0"  
> map\_action =\> "update"  
> }  
> }  
> if [job\_id] == "0002" {  
> aggregate {  
> task\_id =\> "%{job\_id}"  
> code =\> "map['time\_elasped']=0"  
> map\_action =\> "update"  
> }  
> }  
> if [job\_id] == "0004" {  
> aggregate {  
> task\_id =\> "%{job\_id}"  
> code =\> "map['time\_elasped']=0"  
> map\_action =\> "update"  
> end\_of\_task =\> true  
> timeout =\> 120  
> }  
> }  
> }

Any advice?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/how-to-combine-text-file-result/49117/4 "2017-07-06T04:59:24Z")

</div>


