# I want to strip out the beginning and ending parts of the log entry

**URL:** <https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447>\
**Category:** Logstash\
**Created:** [March 24, 2018, 6:57pm UTC](https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447 "2018-03-24T18:57:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [March 24, 2018, 6:57pm UTC](https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447/1 "2018-03-24T18:57:20Z")

</div>

Logstash is receiving this, and I want to remove " --------------- Event Log Start Here ---------------\n" and "\n--------------- Event Log End Here ---------------" from it. And, I want to pull Timestamp value and assign it to @timestamp. I've gotten close, but can't get it to do everyting I want. Also, I'm pretty sure that I'm not doing it the best way, either?

```
--------------- Event Log Start Here ---------------\nEventId : 1, Level : Verbose, Message : Validating Fields to Monitor, if available for notifier for MessageQueueID:0, Payload : [message : Validating Fields to Monitor, if available for notifier for MessageQueueID:0] [applicationName : Not Provided] [hostName : STA-APP-02] [currentPrincipal :] [executingPrincipal : STA\Framework] [userMessageGuid : 7137b2f9-0882-4d04-bf88-d2101226bb32] , EventName : DebugInfo, Timestamp : 2018-03-24T17:03:40.1346697Z\n--------------- Event Log End Here ---------------

```

Here's what my Filter script looks like. The @timestamp gets assigned correctly, but am having a hard time replacing the value of "message" with the combo of the new "Message" field and @timestamp. Plus this feels like a kluge, anyway? Any help is greatly appreciated!

```
        grok {
      patterns_dir => ["/etc/logstash/conf.d/patterns"]
      match => ["message", "[-]{12,18} Event Log Start Here [-]{12,18}\\n%{GREEDYDATA:Message}Timestamp : %{TIMESTAMP_ISO8601:logtime}\\n[-]{12,18} Event Log End Here [-]{12,18}"]
    }
    date {
      match => ["logtime", "ISO8601", "yyyy-MM-dd HH:mm:ss.SSSS", "yyyy-MM-dd HH:mm:ss,SSS", "yyyy-MM-dd'T'HH:mm:ss.SSSSSSS'Z'"]
      target => "@timestamp"
    }
    mutate {
      replace => {"message" => "%{[Message]} %{@timestamp}"}
      remove_field => ["logtime"]
      remove_field => ["Message"]
    }

```

RHEL 7, Logstash 6.2.3

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 25, 2018, 9:51pm UTC](https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447/2 "2018-03-25T21:51:48Z")

</div>

Use the gsub function of mutate to remove/replace field values. Something like:

```
filter {
  mutate {
    gsub => [
      "fieldname", "--------------- Event Log Start Here ---------------", "",
      "fieldname", "--------------- Event Log End Here ---------------", ""
    ]
  }
}

```

I'm not sure if you can use do both on a single line like `"fieldname", "(starthere | endhere)", ""` but you could try it out.

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [March 26, 2018, 11:32am UTC](https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447/3 "2018-03-26T11:32:09Z")

</div>

Thank you, I will try this and let you know.

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [March 26, 2018, 7:44pm UTC](https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447/4 "2018-03-26T19:44:57Z")

</div>

Works, thanks!

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 27, 2018, 2:18am UTC](https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447/5 "2018-03-27T02:18:29Z")

</div>

> [@JimP](#):
>
> Works, thanks!

How did you do it, two separate lines like my example or a single line like I mentioned in my closing paragraph?

---

<div class="post-metadata">

**Author:** ![JimP](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@JimP](https://discuss.elastic.co/u/JimP)\
**Post date:** [April 10, 2018, 8:52pm UTC](https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447/6 "2018-04-10T20:52:47Z")

</div>

```
mutate {
  gsub => [
	"message", "--------------- Event Log Start Here ---------------\n","",
	"message", "\n--------------- Event Log End Here ---------------", ""
  ]
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2018, 8:52pm UTC](https://discuss.elastic.co/t/i-want-to-strip-out-the-beginning-and-ending-parts-of-the-log-entry/125447/7 "2018-05-08T20:52:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
