# Line break into log file

**URL:** <https://discuss.elastic.co/t/line-break-into-log-file/75777>\
**Category:** Logstash\
**Created:** [February 20, 2017, 4:40pm UTC](https://discuss.elastic.co/t/line-break-into-log-file/75777 "2017-02-20T16:40:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [February 20, 2017, 4:40pm UTC](https://discuss.elastic.co/t/line-break-into-log-file/75777/1 "2017-02-20T16:40:58Z")

</div>

Hello,

I would like to know how to parse log line who have many empty field and many useless field.

One line have 60 values but only 20 are really usefull.

I have create a grok with sixty %{DATA:name} (I would improve it later) .

How to delete the empty field and fields that I do not need directly into my grok ? Its possible ?

Thank you for your help

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 20, 2017, 11:08pm UTC](https://discuss.elastic.co/t/line-break-into-log-file/75777/2 "2017-02-20T23:08:19Z")

</div>

Use the `remove_field` option, probably under your grok flter.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 23, 2017, 6:40am UTC](https://discuss.elastic.co/t/line-break-into-log-file/75777/3 "2017-02-23T06:40:29Z")

</div>

If you don't want some of the fields, don't capture them in the first place. In other words, use `%{DATA}` instead of `%{DATA:useless-field-to-delete}`.

---

<div class="post-metadata">

**Author:** ![Beuhlet\_Reseau](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@Beuhlet\_Reseau](https://discuss.elastic.co/u/Beuhlet_Reseau)\
**Post date:** [February 23, 2017, 3:10pm UTC](https://discuss.elastic.co/t/line-break-into-log-file/75777/4 "2017-02-23T15:10:39Z")

</div>

Ok thank you a lots for your help.

Last things, when i indicate %{BASE16NUM:hexa\_value} :

This value is not converted in decimal value, it's just an information no ?

To really convert the hexa value to decimal value, i must use it :

=\> Hexa\_value : A2ED

=\> Grok filter : %{BASE16NUM:Hexa\_value}  
and i must add a mutate ? Than :

gsub =\> ["Hexa\_value", "0x8"] ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 23, 2017, 9:27pm UTC](https://discuss.elastic.co/t/line-break-into-log-file/75777/5 "2017-02-23T21:27:07Z")

</div>

There's no native `hexa_value` data type..

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 24, 2017, 6:43am UTC](https://discuss.elastic.co/t/line-break-into-log-file/75777/6 "2017-02-24T06:43:45Z")

</div>

Here's how to convert the hexstring into a decimal number: [http://stackoverflow.com/a/25792807/414355](http://stackoverflow.com/a/25792807/414355)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2017, 6:43am UTC](https://discuss.elastic.co/t/line-break-into-log-file/75777/7 "2017-03-24T06:43:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
