# Ignore unwanted data from message field multiline logstash

**URL:** <https://discuss.elastic.co/t/ignore-unwanted-data-from-message-field-multiline-logstash/73016>\
**Category:** Logstash\
**Created:** [January 27, 2017, 1:01pm UTC](https://discuss.elastic.co/t/ignore-unwanted-data-from-message-field-multiline-logstash/73016 "2017-01-27T13:01:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aditya\_Srivastava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aditya_srivastava/32/43287_2.png) [@Aditya\_Srivastava](https://discuss.elastic.co/u/Aditya_Srivastava)\
**Post date:** [January 27, 2017, 1:01pm UTC](https://discuss.elastic.co/t/ignore-unwanted-data-from-message-field-multiline-logstash/73016/1 "2017-01-27T13:01:29Z")

</div>

I am using multiline input codec in logstash with currently no filter.  
Below is a sample of how my output looks.

```
"@timestamp" => "2017-01-27T12:03:46.189Z",
   "message" => "{\"@timestamp\":\"2017-01-27T11:35:55.477Z\",\"beat\":{\"hostname\":\"ip-10-1-2-9\",\"name\":\"ip-10-1-2-9\",\"version\":\"5.0.0\"},\"input_type\":\"log\",\"message\":\"Jan 13 11:12:13 ip-10-0-0-23 abc [LOGBACK] 00:00:15.767 [INFO] Outgoing Message\",\"offset\":120923590,\"source\":\"/rescue_109/dataLogging/10.130.2.114/newfile.log\",\"type\":\"core_demo_001\"}\n{\"@timestamp\":\"2017-01-27T11:35:55.477Z\",\"beat\":{\"hostname\":\"ip-10-44-55-9\",\"name\":\"ip-10-1-2-9\",\"version\":\"5.0.0\"},\"input_type\":\"log\",\"message\":\"Jan 13 11:12:13 ip-10-02-33-23 abc ---------------------------\",\"offset\":120923651,\"source\":\"/rescue_109/dataLogging/10.10.20.14/newfile.log\",\"type\":\"core_demo_001\"}\n{\"@timestamp\":\"2017-01-27T11:35:55.477Z\",\"beat\":{\"hostname\":\"ip-10-1-2-9\",\"name\":\"ip-10-1-2-9\",\"version\":\"5.0.0\"},\"input_type\":\"log\",\"message\":\"Jan 13 11:12:13 ip-10-2-3-23 abc ID: 574245\",\"offset\":120923695,\"source\":\"/rescue_109/dataLogging/10.1.40.14/newfile.log\",\"type\":\"core_demo_001\"}\n{\"@timestamp\":\"2017-01-27T11:35:55.477Z\",\"beat\":{\"hostname\":\"ip-10-2-3-9\",\"name\":\"ip-10-3-4-9\",\"version\":\"5.0.0\"},\"input_type\":\"log\",\"message\":\"Jan 13 11:12:13 ip-10-0-0-23 abc Encoding: UTF-8\",\"offset\":120923744,\"source\":\"/rescue_109/dataLogging/10.10.20.14/newfile.log\",\"type\":\"core_demo_001\"}107]\",\"offset\":120924874,\"source\":\"/rescue_109/dataLogging/10.10.20.14/newfile.log\",\"type\":\"core_demo_001\"}",
  "@version" => "1",
      "tags" => [
    [0] "multiline",
    [1] "groked"
]

```

}

As it is visible that inside my message, there are multiple tags of timestamp, message,beat, hostname etc.  
I want to only take the all the hostname field and ignore rest of the unwanted data from main message.

What filter should I use. Should I use mutate or any other filter.

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 30, 2017, 6:33am UTC](https://discuss.elastic.co/t/ignore-unwanted-data-from-message-field-multiline-logstash/73016/2 "2017-01-30T06:33:41Z")

</div>

Why are you using the multiline input? It doesn't look like you need it.

Use a json filter to deserialize the JSON string in the `message' field. If possible, use a json or json\_lines codec in your input configuration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2017, 6:33am UTC](https://discuss.elastic.co/t/ignore-unwanted-data-from-message-field-multiline-logstash/73016/3 "2017-02-27T06:33:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
