# Indexing data by getting substring of each row

**URL:** <https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391>\
**Category:** Logstash\
**Created:** [October 8, 2018, 7:01am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391 "2018-10-08T07:01:34Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![prasad.ram1431](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Post date:** [October 8, 2018, 7:01am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/1 "2018-10-08T07:01:35Z")

</div>

Hi All,

I am new to logstash, I would like to index attached format of data into Elasticsearch using logstash. Could you please provide some samples, so that I can work on them.

The Attached file doesn't contains headers, we need to extract each field value from a row using column index.

For example, column 5 to column 10 - is value for a particular field.

Sample Data:

`

```
0000C28417401370200000690856000TTEYAA KAKU IND CO.,LTD. TAEYMA KAKU IND CO.,LTD. 13, SHIMAN TOYMA 00105200YAMA TYM 930-1305 PAN 3692 000 000 NKATSITO MIZCHI Pres 00005 363936793676 0001958 000000090135954 0000000096032340000 000000058390306 0000000062210000000 000000000715035 00000000007618100000000060200000852Y -- 0000000000020180828 G 003002N17230001001637 00099764834012 311NMNNANP NNN006908560003690069085600000690856000369Y00015 01201809260 N20180926 043000YN0081Mfg household appliances 0280 TAMA KAGU IND CO.,LTD. 30, SHOBAN TOYA 001052TOYA TYM 930-1305 000PAN 2TATMA INDU CO.,LTD. 30, SHIMAN TOYA 001052TOA TYM 930-1305 000PAN 2TATGA IND CO.,LTD. 30, SHIMAN TOYA 001052TAMA TYM 930-1305 369 1958M20331 N 11

```

Above provided is a sample single row, similarly I will be having multiple rows. Each row contains value for multiple fields.

Thanks,  
Ram Prasad G

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 8, 2018, 7:38am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/2 "2018-10-08T07:38:21Z")

</div>

What is the expected output?

---

<div class="post-metadata">

**Author:** ![prasad.ram1431](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Post date:** [October 8, 2018, 8:14am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/3 "2018-10-08T08:14:25Z")

</div>

Hi Christian,

Expected output would be like, customer\_id: C2841, customer\_nameL KAKU, etc.

Thanks,  
Ram Prasad G

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 8, 2018, 9:06am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/4 "2018-10-08T09:06:33Z")

</div>

Can you please show how the full event should be parsed and look?

---

<div class="post-metadata">

**Author:** ![prasad.ram1431](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Post date:** [October 8, 2018, 9:53am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/5 "2018-10-08T09:53:24Z")

</div>

Hi Christian,

We need to read the file from logstash, each row should be splited based on the fixed column array index value, below i have given example.  
For example,

0000C28417401370200000690856000TTEYAA KAKU IND CO.,LTD. - this is the sample data which contains in a file.  
From the above data, we have to index into ES using logstash like,  
customer\_id : column[5] to column[10] -\> C2841  
customer\_idproof\_number: column[11] to column[15] -\> 74013, etc

which means we need to extract the data for each field based on the given column index.

Kindly let me know if you need further more information.

Thanks,  
Ram Prasad G

---

<div class="post-metadata">

**Author:** ![prasad.ram1431](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Post date:** [October 9, 2018, 10:49am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/6 "2018-10-09T10:49:08Z")

</div>

Any Updates please.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 9, 2018, 11:58am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/7 "2018-10-09T11:58:59Z")

</div>

Use a grok filter as this support specification of fixed length patterns.

---

<div class="post-metadata">

**Author:** ![prasad.ram1431](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Post date:** [October 9, 2018, 1:22pm UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/8 "2018-10-09T13:22:52Z")

</div>

Thank you very much for your suggestion.  
Could you please provide me some example, as I am new to this.

---

<div class="post-metadata">

**Author:** ![prasad.ram1431](https://avatars.discourse-cdn.com/v4/letter/p/c89c15/32.png) [@prasad.ram1431](https://discuss.elastic.co/u/prasad.ram1431)\
**Post date:** [October 10, 2018, 10:56am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/9 "2018-10-10T10:56:20Z")

</div>

Any updates please.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2018, 10:56am UTC](https://discuss.elastic.co/t/indexing-data-by-getting-substring-of-each-row/151391/10 "2018-11-07T10:56:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
