# How to cut off the part of syslog

**URL:** <https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [March 8, 2023, 3:45am UTC](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242 "2023-03-08T03:45:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![YvesZhi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yveszhi/32/118184_2.png) [@YvesZhi](https://discuss.elastic.co/u/YvesZhi)\
**Post date:** [March 8, 2023, 3:45am UTC](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242/1 "2023-03-08T03:45:33Z")

</div>

I've some micro services, which are deployed with Docker. They send their logs to my Logstash with the log driver `syslog`. Here is the config of my Logstash:

```auto
input {
  syslog {
    port => 9771
    type => "syslog"
  }
}

filter {
}

output {
  file {
    path => "/var/log/logstash/%{+YYYY-MM-dd}/logstash-%{+HH}.log"
  }
  if "www.envoyproxy.io" in [message] {
    file {
      path => "/var/log/logstash/%{+YYYY-MM-dd}/test-%{+HH}.log"
      codec => line { format => "%{message}" }
    }
  }
}

```

I can see logs in the file `test-01.log` like this:

```auto
<30>Mar 8 11:42:45 2867370d06d5[8119]: 172.16.0.226,48982,envoy,2023-03-08T03:42:39.340Z,34.142.199.10,443,-,www.envoyproxy.io,HTTP/1.1,GET,/,HTTP/1.1,200,17304,2023-03-08T03:42:39.340Z,17304,-,-,curl/7.29.0,-,1000,0,0,0,0,0,0,0,0,0,0,0

```

I want to remove the part `<30>Mar 8 11:42:45 2867370d06d5[8119]:` before writing the logs into the file `test-01.log` but I don't know how.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 8, 2023, 2:04pm UTC](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242/2 "2023-03-08T14:04:23Z")

</div>

Welcome to the comunity!

You can use something like this:

```auto
filter {
     grok {
       match => { "message" => "<%{NONNEGINT:syslog_abspri}>%{SYSLOGTIMESTAMP:timestamp} %{PROG:program}\[%{POSINT:pid}\]: %{GREEDYDATA:message}" }
       overwrite => ["message"]
     }
}

```

Result:

```auto
{
              "pid" => "8119",
          "program" => "2867370d06d5",
          "message" => "172.16.0.226,48982,envoy,2023-03-08T03:42:39.340Z,34.142.199.10,443,-,www.envoyproxy.io,HTTP/1.1,GET,/,HTTP/1.1,200,17304,2023-03-08T03:42:39.340Z,17304,-,-,curl/7.29.0,-,1000,0,0,0,0,0,0,0,0,0,0,0",
    "syslog_abspri" => "30",
        "timestamp" => "Mar 8 11:42:45"
}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 11, 2023, 6:25am UTC](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242/3 "2023-03-11T06:25:51Z")

</div>

Or you can use the dissect filter, which I have completely forgotten.

```auto
  dissect {
        mapping => {
            "message" => "%{}]: %{message}"
        }
  }
# and csv filter with columns naming
  csv {
      separator => ","
      skip_header => "true"
      columns => ["source.ip","source.port","name","time","destination.ip","destination.port","method","host","HTTPver"]
  }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2023, 6:26am UTC](https://discuss.elastic.co/t/how-to-cut-off-the-part-of-syslog/327242/4 "2023-04-08T06:26:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
