# How to split the log data message ( log4j )

**URL:** <https://discuss.elastic.co/t/how-to-split-the-log-data-message-log4j/53123>\
**Category:** Logstash\
**Created:** [June 17, 2016, 8:37am UTC](https://discuss.elastic.co/t/how-to-split-the-log-data-message-log4j/53123 "2016-06-17T08:37:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![venkat-accel](https://avatars.discourse-cdn.com/v4/letter/v/9f8e36/32.png) [@venkat-accel](https://discuss.elastic.co/u/venkat-accel)\
**Post date:** [June 17, 2016, 8:37am UTC](https://discuss.elastic.co/t/how-to-split-the-log-data-message-log4j/53123/1 "2016-06-17T08:37:22Z")

</div>

Hi,

I have log4j data , i created config file and able to load the data in kibana but all the log data , each line is loaded as single filed called  
"message ".

But i want to split each filed in the message as separately for further analysis.  
Please let me know how to achieve this.

mentioned config file as below

input {  
file {  
type =\> "log4j"  
path =\> "C:\WEBLog\_1.log"  
start\_position =\> beginning  
ignore\_older =\> 0  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 18, 2016, 1:32am UTC](https://discuss.elastic.co/t/how-to-split-the-log-data-message-log4j/53123/2 "2016-06-18T01:32:38Z")

</div>

It'd be helpful if you provided the data that you want to match as well.

---

<div class="post-metadata">

**Author:** ![venkat-accel](https://avatars.discourse-cdn.com/v4/letter/v/9f8e36/32.png) [@venkat-accel](https://discuss.elastic.co/u/venkat-accel)\
**Post date:** [June 18, 2016, 7:58am UTC](https://discuss.elastic.co/t/how-to-split-the-log-data-message-log4j/53123/3 "2016-06-18T07:58:35Z")

</div>

Please find the sample line of log file

2013/03/07 00:35:15 HTTP [192.168.xx.xxx](http://192.168.xx.xxx) - - - Allowed - 302 [go.abc.com](http://go.abc.com) 126 0 160 - text/html databasematch ITsample\IT ITsample\IT - - [http://go.abc.com/fwlink/?linkid=45332&abcdd](http://go.abc.com/fwlink/?linkid=45332&abcdd) HTTP/1.1 GET -

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 21, 2016, 5:46am UTC](https://discuss.elastic.co/t/how-to-split-the-log-data-message-log4j/53123/4 "2016-06-21T05:46:34Z")

</div>

The COMBINEDAPACHELOG pattern won't work for this log since it's in another format. I don't recognize it so you probably have to write your own grok expression to parse it. It's similar to COMBINEDAPACHELOG though so you should be able to reuse parts of it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:51am UTC](https://discuss.elastic.co/t/how-to-split-the-log-data-message-log4j/53123/5 "2017-07-06T04:51:39Z")

</div>


