# How to handle large message in log

**URL:** <https://discuss.elastic.co/t/how-to-handle-large-message-in-log/209542>\
**Category:** Logstash\
**Created:** [November 26, 2019, 3:38pm UTC](https://discuss.elastic.co/t/how-to-handle-large-message-in-log/209542 "2019-11-26T15:38:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kwanchai\_Jaroensiric](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kwanchai_jaroensiric/32/58353_2.png) [@Kwanchai\_Jaroensiric](https://discuss.elastic.co/u/Kwanchai_Jaroensiric)\
**Post date:** [November 26, 2019, 3:38pm UTC](https://discuss.elastic.co/t/how-to-handle-large-message-in-log/209542/1 "2019-11-26T15:38:57Z")

</div>

i found large message in some log and i count word of log result : 2.5k++  
and i using this code..  
My sample code  
\</\>  
filter {  
if "service\_daily" in [tags] {  
mutate {  
gsub =\> [  
"message", "TIMESTAMP|", "",  
"message", "LOGTYPE|", "",  
"message", "CALL\_SERVICE|", "",  
"message", "THREAD|", "",  
"message", "METHOD|", "",  
"message", "URI|", "",  
"message", "REQID|", "",  
"message", "REQHEADERS|", "",  
"message", "REQBODY|", "",  
"message", "RESPSTATUS|", "",  
"message", "RESPTIME|", "",  
"message", "RESPBODY|", "",  
"message", "ERRORMESSAGE|", "",  
"message", "EXCEPTION|", ""  
]  
}  
#Gsub because i want to set format log \>\> value1|value2|value3|...valueN  
grok {  
break\_on\_match =\> false  
match =\> ["message","%{GREEDYDATA:timestamp}|%{GREEDYDATA:logtype}|%{GREEDYDATA:call\_service}|%{GREEDYDATA:thread}|%{GREEDYDATA:method}|%{GREEDYDATA:uri}|%{GREEDYDATA:reqid}|%{GREEDYDATA:reqheaders}|%{GREEDYDATA:reqbody}|%{GREEDYDATA:respstatus}|%{GREEDYDATA:resptime}|%{GREEDYDATA:respbody}|%{GREEDYDATA:respbody}|%{GREEDYDATA:respbody}|%{GREEDYDATA:errormessage}|%{GREEDYDATA:exception}"]  
}  
.....  
.....  
\</\>  
it's working for this case but another logs filter is not working  
if i using this code

> >

grok {  
break\_on\_match =\> false  
match =\> ["message","%{GREEDYDATA:timestamp}|%{GREEDYDATA:logtype}|%{GREEDYDATA:call\_service}|%{GREEDYDATA:thread}|%{GREEDYDATA:method}|%{GREEDYDATA:uri}|%{GREEDYDATA:reqid}|%{GREEDYDATA:reqheaders}|%{GREEDYDATA:reqbody}|%{GREEDYDATA:respstatus}|%{GREEDYDATA:resptime}|%{GREEDYDATA:respbody}|%{GREEDYDATA:errormessage}|%{GREEDYDATA:exception}"]  
}  
When i run this code value of other field include to timestamp field  
This is error from code  
Invalid format: "2017-10-09T18:15:14.036|[INFO]....." is malformed at "|[INFO]....."

How can i handle with this case (Large message in logfile)  
Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2019, 3:39pm UTC](https://discuss.elastic.co/t/how-to-handle-large-message-in-log/209542/2 "2019-12-24T15:39:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
