# How to take the first two lines after splitting on new lines

**URL:** <https://discuss.elastic.co/t/how-to-take-the-first-two-lines-after-splitting-on-new-lines/130061>\
**Category:** Logstash\
**Created:** [April 30, 2018, 8:02pm UTC](https://discuss.elastic.co/t/how-to-take-the-first-two-lines-after-splitting-on-new-lines/130061 "2018-04-30T20:02:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Harsh\_Verma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harsh_verma/32/26136_2.png) [@Harsh\_Verma](https://discuss.elastic.co/u/Harsh_Verma)\
**Post date:** [April 30, 2018, 8:02pm UTC](https://discuss.elastic.co/t/how-to-take-the-first-two-lines-after-splitting-on-new-lines/130061/1 "2018-04-30T20:02:54Z")

</div>

I want to store first two lines in one of my logs in a different variable using split() function of Mutate filter and then concatenating using a delimiter like comma, is that possible using split() and add\_field() commands ? I didn't find much examples of using split() function. I want to take the first two lines in stacktrace as exception.  
I tried something like this:

```
  mutate { add_field => { "exception" => "%{stacktrace}" } }
  mutate { split => { "exception" => "\n\t" } } 
  mutate { update => { "exception" => {%{exception}[0] + %{exception}[1] } } }

```

But get compile error, "/n/t" is the delimiter

I also tried with the ruby filter but it is not splitting at all

```
 if [stacktrace]{
    mutate { add_field => { "exception" => "%{stacktrace}" } }
    ruby {
      code => 
        "
          exception_array = event['exception'].split('\n\t')
          event['exception'] = exception_array[0] + '->' + exception_array[1]
         "
      
    }
  }

```

my log lines are separated by "\n\t" and they look like:

`"org.someException: Some message\n\tat some.package(SomeClass.java:1000)\n\tat some.package(SomeClass.java:1000)\n\tat...`

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 30, 2018, 9:59pm UTC](https://discuss.elastic.co/t/how-to-take-the-first-two-lines-after-splitting-on-new-lines/130061/2 "2018-04-30T21:59:57Z")

</div>

> [@Harsh\_Verma](#):
>
> get compile error

What is the compile error? At first glance, it looks like you're trying to give a curly-brace _thing_ in the `update` directive, but we need a string there, perhaps something like this:

```auto
  mutate { update => { "exception" => "%{exception[0]} -> %{exception[1]}" } }

```

* * *

In ruby, a single-quoted string does not convert backslash-escaped character sequences, so your `'\n\t'` is being interpreted literally as the four-character sequence `backslash`+`n`+`backslash`+`t`. Off the top of my head, the only way around this would be to provide the code in single-quote block, and to use double-quotes inside it:

```auto
 if [stacktrace]{
    mutate { add_field => { "exception" => "%{stacktrace}" } }
    ruby {
      code => 
        '
          exception_array = event["exception"].split("\n\t")
          event["exception"] = exception_array[0] + "->" + exception_array[1]
        '
    }
  }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2018, 9:59pm UTC](https://discuss.elastic.co/t/how-to-take-the-first-two-lines-after-splitting-on-new-lines/130061/3 "2018-05-28T21:59:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
