# Logstash configuration remove everything after "-"

**URL:** <https://discuss.elastic.co/t/logstash-configuration-remove-everything-after/355672>\
**Category:** Logstash\
**Tags:** elastic-stack-monitoring\
**Created:** [March 19, 2024, 3:52am UTC](https://discuss.elastic.co/t/logstash-configuration-remove-everything-after/355672 "2024-03-19T03:52:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ska/32/132769_2.png) [@ska](https://discuss.elastic.co/u/ska)\
**Post date:** [March 19, 2024, 3:52am UTC](https://discuss.elastic.co/t/logstash-configuration-remove-everything-after/355672/1 "2024-03-19T03:52:56Z")

</div>

ELK 7.16.x

In my logstash file, I have the following configuration:

```auto
....
if [kubernetes][namespace] == 'webservices' or [kubernetes][namespace] =~ /webservices-frontend\d+$/ {
        mutate {
          replace => { 'pod_name' => "%{[kubernetes][pod][name]}" }
        }
..
.....
# Example: 
# pod_name is == some-running-pod-frontend1-1234567-975cf7cd9-nzzxl
# or
# pod_name is == some-running-pod-frontend2-76c54B21-8at6C9a7v-baczi
# or
# pod_name is == some-running-pod-frontend1-76c54B21-8at6C9a7v-baczi
# or
# pod_name is == some-running-pod-frontend2-7564321-8at6C9a7v-baczi

# I'm using the following configuration to see if pod_name contains the following pattern using "=~" /somevalue/
....
        else if [pod_name] =~ /some-running-pod-frontend\d+-\d+/ {
          mutate {
            replace => { 'message' => "P00:FRONTEND:%{pod_name}" }
          }
        }

I want message to just contain the pod name stripped value i.e. logical name (rather than using the full pod name which includes "-<number>-<alnum>" part: 
"P00:FRONTEND:some-running-pod-frontend1" 
and 
"P00:FRONTEND:some-running-pod-frontend2"

```

How can I easily test this config (before committing it to GIT.

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [March 19, 2024, 9:56am UTC](https://discuss.elastic.co/t/logstash-configuration-remove-everything-after/355672/2 "2024-03-19T09:56:43Z")

</div>

Hi @ska,

Welcome back! Have you tried running it locally with an output file configured to try out your change? There is an example in [this blog](https://medium.com/@mikerogers1357/testing-logstash-configuration-with-json-input-output-9b781962cc2) that could help.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 19, 2024, 11:22am UTC](https://discuss.elastic.co/t/logstash-configuration-remove-everything-after/355672/3 "2024-03-19T11:22:59Z")

</div>

> [@ska](#):
>
> How can I easily test this config (before committing it to GIT.

You can use a sample of your raw logs and test it locally.

---

<div class="post-metadata">

**Author:** ![ska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ska/32/132769_2.png) [@ska](https://discuss.elastic.co/u/ska)\
**Post date:** [March 20, 2024, 8:23pm UTC](https://discuss.elastic.co/t/logstash-configuration-remove-everything-after/355672/4 "2024-03-20T20:23:34Z")

</div>

```auto
        else if [pod_name] =~ /some-running-pod-frontend\d+-antenna\d+-/ {
          mutate {
            gsub => [
               "pod_name", "(.*-antenna\d{1,2})-.*", "\1"
            ]
            replace => { 'message' => "P00:FRONTEND:%{pod_name}" }
          }
        }

```

gsub within mutate did the trick

`(.*-antenna\d{1,2})-.*` == catch string from start up to antenna1, antenna2, or antenna99 first using '(' and ')' i.e. **\1** and then ignore anything after (....antennaN)-.\*

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2024, 8:24pm UTC](https://discuss.elastic.co/t/logstash-configuration-remove-everything-after/355672/5 "2024-04-17T20:24:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
