# Logmessage map to tags or fields

**URL:** https://discuss.elastic.co/t/logmessage-map-to-tags-or-fields/36259
**Category:** Elasticsearch
**Created:** [December 3, 2015, 8:42am UTC](https://discuss.elastic.co/t/logmessage-map-to-tags-or-fields/36259 "2015-12-03T08:42:04Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![jayaram](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@jayaram](https://discuss.elastic.co/u/jayaram)
#### Post date: [December 3, 2015, 8:42am UTC](https://discuss.elastic.co/t/logmessage-map-to-tags-or-fields/36259/1 "2015-12-03T08:42:04Z")

</div>

Continuing the discussion from [Any Help Un-structure log message to map structure message in Logstash](https://discuss.elastic.co/t/any-help-un-structure-log-message-to-map-structure-message-in-logstash/36258):

> [@Any Help Un-structure log message to map structure message in Logstash](https://discuss.elastic.co/t/any-help-un-structure-log-message-to-map-structure-message-in-logstash/36258/1):
>
> Hello, I have the log message  
> 2015-11-18 21:11:38,693 [WARN] [xx.web.common.filter.RequestFilter] NDC[UserPrincipal(ABCDF22602)] request (/member/control/loginAction) exceeded threshold; elapsed milliseconds since start: 188814
> 
> Can any one help me. How to tag or map the each same stored/moved to elasticsearch or any output resource
> 
> dose GROK plugin help for this mapping? any other plugin available to map/associate the each value to some TAG  
> I am trying like this in grok plugin but not working
> 
> match =\> { "timestamp" =\> "%{TOMCAT\_DATESTAMP:timestamp}"}  
> match =\> { "level" =\> "[%{LOGLEVEL:level}]" }  
> match =\> { "class" =\> "[%{JAVACLASS:class}]" }  
> match =\> { "logmessage" =\> "%{JAVALOGMESSAGE:logmessage}" }

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 3, 2015, 8:47am UTC](https://discuss.elastic.co/t/logmessage-map-to-tags-or-fields/36259/2 "2015-12-03T08:47:09Z")

</div>

This is a Logstash question so I'm not sure why you want to continue the discussion in the Elasticsearch group.

---

<div class="post-metadata">

### Author: ![jayaram](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@jayaram](https://discuss.elastic.co/u/jayaram)
#### Post date: [December 3, 2015, 9:25am UTC](https://discuss.elastic.co/t/logmessage-map-to-tags-or-fields/36259/3 "2015-12-03T09:25:55Z")

</div>

i thought it stored in elasticsearrch so same mapping need in elasticsearch

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 3, 2015, 9:29am UTC](https://discuss.elastic.co/t/logmessage-map-to-tags-or-fields/36259/4 "2015-12-03T09:29:26Z")

</div>

Yes, Logstash can store data in Elasticsearch. If you use the grok filter as described in the other thread you'll get your log entries stored in Elasticsearch with separate fields for the timestamp, log level, class name, and so on. No further action is necessary on the Elasticsearch side.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 5, 2017, 11:33pm UTC](https://discuss.elastic.co/t/logmessage-map-to-tags-or-fields/36259/5 "2017-07-05T23:33:56Z")

</div>


