# How to give customize name to fields and loop through logs

**URL:** <https://discuss.elastic.co/t/how-to-give-customize-name-to-fields-and-loop-through-logs/56948>\
**Category:** Logstash\
**Created:** [August 2, 2016, 4:48am UTC](https://discuss.elastic.co/t/how-to-give-customize-name-to-fields-and-loop-through-logs/56948 "2016-08-02T04:48:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vandana\_sethi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vandana_sethi/32/10894_2.png) [@vandana\_sethi](https://discuss.elastic.co/u/vandana_sethi)\
**Post date:** [August 2, 2016, 4:48am UTC](https://discuss.elastic.co/t/how-to-give-customize-name-to-fields-and-loop-through-logs/56948/1 "2016-08-02T04:48:24Z")

</div>

I have a log pattern like this

`OTHERS|5HUNVWW|5HUNVWW|1469784588193|1469784588193|`

these pipe separated values represent a key so I want to create fields like

```
field1 = OTHERS
field2 = 5HUNVWW

```

and so on . How can I achieve this ?

---

<div class="post-metadata">

**Author:** ![vandana\_sethi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vandana_sethi/32/10894_2.png) [@vandana\_sethi](https://discuss.elastic.co/u/vandana_sethi)\
**Post date:** [August 2, 2016, 6:01am UTC](https://discuss.elastic.co/t/how-to-give-customize-name-to-fields-and-loop-through-logs/56948/2 "2016-08-02T06:01:29Z")

</div>

```
filter {
  ruby {
    code => '
      ids = event["message"].split("|")
      ids.each_index { |i| event["field#{i}"] = ids[i] }
      end
    '
  }
}

```

I achieve it using this can anyone tell what will be the best logic to give customize name not like field1 and field2 it should be like firstname , lastname schoolname etc

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 2, 2016, 6:45am UTC](https://discuss.elastic.co/t/how-to-give-customize-name-to-fields-and-loop-through-logs/56948/3 "2016-08-02T06:45:35Z")

</div>

You should be able to use the csv filter for this type of data.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:45am UTC](https://discuss.elastic.co/t/how-to-give-customize-name-to-fields-and-loop-through-logs/56948/4 "2017-07-06T04:45:28Z")

</div>


