# How to parse more similar fields with Logstash?

**URL:** <https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347>\
**Category:** Logstash\
**Created:** [March 3, 2018, 2:02am UTC](https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347 "2018-03-03T02:02:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Francesca\_P](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@Francesca\_P](https://discuss.elastic.co/u/Francesca_P)\
**Post date:** [March 3, 2018, 2:02am UTC](https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347/1 "2018-03-03T02:02:41Z")

</div>

Hi,  
I'm new with Logstash. I'm trying to parse a log file that contain the following fields:

```
2017-02-02 07:19:16,908 [varMes: <audio source="au/speak1.wav" />
<audio source="au/speak2.wav" /> <audio source="au/speak3.wav" />
<audio source="au/speak4.wav" />]

2017-02-02 07:19:17,812 [varMes: &lt;audio source="au/speak1.wav" /&gt;
&lt;audio source="au/speak2.wav" /&gt;]

```

I would like to load them both in the same ES Index, but it does not work with just the grok filter. I can't understand how to manage the various fields.

Please, any help on how to load it?

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [March 3, 2018, 12:25pm UTC](https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347/2 "2018-03-03T12:25:46Z")

</div>

This is always a tough issue to deal with. Grok while incredibly powerful occasionally has limits. I have never found a good answer to deal with this. But there are options.

Here is an old article for one way to do it

> [@How do we match multiple random ips?](https://discuss.elastic.co/t/how-do-we-match-multiple-random-ips/1507/2):
>
> If you're okay with getting all IPs in an array field you can just use [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) extract all the IPs to a string and use the [mutate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html) to split that string. filter { grok { match =\> ["message", "^(?\<ip\>%{IP}(, %{IP})\*) ..."] } mutate { split =\> ["ip", ", "] } } It looks like you might always have at least two IPs, each followed by a space, followed by a comma-separated list of IPs. In that you'll have to adjust the filters a bit but it shouldn't be too hard.

another would be to do it in the ruby filter

> **[Ruby filter plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html)**

A final option might be to use the KV filter as all your data is in "source=file"

> **[Kv filter plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2018, 12:26pm UTC](https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347/3 "2018-03-31T12:26:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
