# How to split message fields when we have dynamic logs

**URL:** <https://discuss.elastic.co/t/how-to-split-message-fields-when-we-have-dynamic-logs/228497>\
**Category:** Logstash\
**Created:** [April 17, 2020, 11:09am UTC](https://discuss.elastic.co/t/how-to-split-message-fields-when-we-have-dynamic-logs/228497 "2020-04-17T11:09:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![hemant\_472](https://avatars.discourse-cdn.com/v4/letter/h/6bbea6/32.png) [@hemant\_472](https://discuss.elastic.co/u/hemant_472)\
**Post date:** [April 17, 2020, 11:09am UTC](https://discuss.elastic.co/t/how-to-split-message-fields-when-we-have-dynamic-logs/228497/1 "2020-04-17T11:09:36Z")

</div>

I am able to split fields using GROK in my logstash config file but have no idea how to split every log because the logs are dynamic for eg:

```auto
log 1 : Dec 28 05:05:47 ff402-srv1 MC: DEBUG {2416824} [PlanJob] EXPLICIT: DuraNoRamp=5.652 MaxMinDuraNoRamp=5.652 MaxSpeed=0.500 MinActP=0.000000

Log 2 : Dec 28 04:36:11 desk.outlet12 MD: Request state change enter standby to UI

```

Please let me know what can i use like some conditional statements or any or operator for different patterns in my logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2020, 11:09am UTC](https://discuss.elastic.co/t/how-to-split-message-fields-when-we-have-dynamic-logs/228497/2 "2020-05-15T11:09:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
