# Logstack dissect missing delimiter

**URL:** <https://discuss.elastic.co/t/logstack-dissect-missing-delimiter/127647>\
**Category:** Logstash\
**Created:** [April 11, 2018, 1:59pm UTC](https://discuss.elastic.co/t/logstack-dissect-missing-delimiter/127647 "2018-04-11T13:59:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![snewman](https://avatars.discourse-cdn.com/v4/letter/s/5f9b8f/32.png) [@snewman](https://discuss.elastic.co/u/snewman)\
**Post date:** [April 11, 2018, 1:59pm UTC](https://discuss.elastic.co/t/logstack-dissect-missing-delimiter/127647/1 "2018-04-11T13:59:30Z")

</div>

When using the dissect plugin for logstash, it correctly parses most of the message, except for the first field which uses the cat function. The test line that is being parsed is  
2018-02-15|03:00:11.450|TEST|TEST|TEST|TEST|TEST|TEST|TEST|TEST|TEST|TEST|TEST  
The config file looks like  
input{  
beats{ port =\>5044}  
}

filter{  
dissect{  
mapping =\> {  
"message" =\> "%{timestamp}|%{+timestamp}|%{level}|%{application}|%{module}|%{latitude}|%{longitude}|%{heading}|%{speed}|%{distance}|  
%{pulse}|%{thread}|%{cpu}|%{freq}|%{mem}|%{text}"  
}

}  
date{  
match =\> ["timestamp", "yyyy-MM-ddHH:mm:ss.SSS"]  
}

mutate{  
remove\_field =\> [message]  
}  
}

output{  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
}  
}

Ignoring the date plugin, I see the parsed data for the field timestamp to be 2018-02-15|03:00:11.450  
instead of 2018-02-1503:00:11.450

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 11, 2018, 2:14pm UTC](https://discuss.elastic.co/t/logstack-dissect-missing-delimiter/127647/2 "2018-04-11T14:14:04Z")

</div>

Working as expected. See the NOTE in the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dissect.html) for append fields

The delimiter found before the field is appended with the value. If no delimiter is found before the field, a single space character is used.

---

<div class="post-metadata">

**Author:** ![snewman](https://avatars.discourse-cdn.com/v4/letter/s/5f9b8f/32.png) [@snewman](https://discuss.elastic.co/u/snewman)\
**Post date:** [April 11, 2018, 2:35pm UTC](https://discuss.elastic.co/t/logstack-dissect-missing-delimiter/127647/3 "2018-04-11T14:35:48Z")

</div>

Thank you, missed that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2018, 2:36pm UTC](https://discuss.elastic.co/t/logstack-dissect-missing-delimiter/127647/4 "2018-05-09T14:36:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
