# How to parse MQ consle output in logstash

**URL:** <https://discuss.elastic.co/t/how-to-parse-mq-consle-output-in-logstash/180193>\
**Category:** Logstash\
**Created:** [May 8, 2019, 2:20pm UTC](https://discuss.elastic.co/t/how-to-parse-mq-consle-output-in-logstash/180193 "2019-05-08T14:20:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Praful\_Chandra](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/praful_chandra/32/45824_2.png) [@Praful\_Chandra](https://discuss.elastic.co/u/Praful_Chandra)\
**Post date:** [May 8, 2019, 2:20pm UTC](https://discuss.elastic.co/t/how-to-parse-mq-consle-output-in-logstash/180193/1 "2019-05-08T14:20:41Z")

</div>

```
IBMMQ3434
	SYSTEM.ADMIN.QMGR.EVENT CURDEPTH(1) MAXDEPTH(3000)
	SYSTEM.AUTH.DATA.QUEUE CURDEPTH(114) MAXDEPTH(999999999)
	SYSTEM.CHANNEL.SYNCQ CURDEPTH(70) MAXDEPTH(20000)
	SYSTEM.CHLAUTH.DATA.QUEUE CURDEPTH(3000) MAXDEPTH(999999999)
	SYSTEM.CLUSTER.REPOSITORY.QUEUE CURDEPTH(299889) MAXDEPTH(999999999)
	SYSTEM.DURABLE.SUBSCRIBER.QUEUE CURDEPTH(188888899) MAXDEPTH(999999999)
	SYSTEM.HIERARCHY.STATE CURDEPTH(278888) MAXDEPTH(999999999)

```

`SYSTEM.RETAINED.PUB.QUEUE CURDEPTH(782) MAXDEPTH(999999999)`

this is standard output from my AIX console output, i want to read this file

first line is queue Manger ,  
second line will be queue name , its current depth or messages , maxdepth or threshold  
or is there any plugin to read IBM MQ stats

Thanks  
out to elastic should be like this below  
{  
queuemanger = "IBMMQ3434"  
Queue name = "SYSTEM.RETAINED.PUB.QUEUE"  
CurrentDepth = "782"  
Maxdepth = "999999999"  
}  
{  
queuemanger = "IBMMQ3434"  
Queue name = "SYSTEM.HIERARCHY.STATE"  
CurrentDepth = "278888"  
Maxdepth = "999999999"  
}

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 8, 2019, 2:32pm UTC](https://discuss.elastic.co/t/how-to-parse-mq-consle-output-in-logstash/180193/2 "2019-05-08T14:32:41Z")

</div>

If you consume that as a single event (e.g. using a multiline codec with a pattern that never matches plus auto\_flush\_interval) then you can parse it using

```
    grok { match => { "message" => "\A%{HOSTNAME:queueManager}
" } }
    split {}
    grok { match => { "message" => "\s*%{HOSTNAME:queue}\s*CURDEPTH\(%{POSINT:curdepth:int}\) MAXDEPTH\(%{POSINT:maxdepth:int}\)" } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2019, 2:32pm UTC](https://discuss.elastic.co/t/how-to-parse-mq-consle-output-in-logstash/180193/3 "2019-06-05T14:32:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
