# How to parse more similar fields with Logstash?

**URL:** <https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347>\
**Category:** Logstash\
**Created:** [March 3, 2018, 2:02am UTC](https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347 "2018-03-03T02:02:40Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [March 3, 2018, 12:25pm UTC](https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347/2 "2018-03-03T12:25:46Z")

</div>

This is always a tough issue to deal with. Grok while incredibly powerful occasionally has limits. I have never found a good answer to deal with this. But there are options.

Here is an old article for one way to do it

> [@How do we match multiple random ips?](https://discuss.elastic.co/t/how-do-we-match-multiple-random-ips/1507/2):
>
> If you're okay with getting all IPs in an array field you can just use [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) extract all the IPs to a string and use the [mutate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html) to split that string. filter { grok { match =\> ["message", "^(?\<ip\>%{IP}(, %{IP})\*) ..."] } mutate { split =\> ["ip", ", "] } } It looks like you might always have at least two IPs, each followed by a space, followed by a comma-separated list of IPs. In that you'll have to adjust the filters a bit but it shouldn't be too hard.

another would be to do it in the ruby filter

> **[Ruby filter plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html)**

A final option might be to use the KV filter as all your data is in "source=file"

> **[Kv filter plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html)**

---

_[View the full topic](https://discuss.elastic.co/t/how-to-parse-more-similar-fields-with-logstash/122347)._
