# Logstash dublicate message

**URL:** <https://discuss.elastic.co/t/logstash-dublicate-message/91664>\
**Category:** Logstash\
**Created:** [July 3, 2017, 3:41pm UTC](https://discuss.elastic.co/t/logstash-dublicate-message/91664 "2017-07-03T15:41:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [July 3, 2017, 3:41pm UTC](https://discuss.elastic.co/t/logstash-dublicate-message/91664/1 "2017-07-03T15:41:45Z")

</div>

Hi there,  
this is my pepiline.conf:

```
input {
        file {
        path => "c:/logstash.log"
        start_position => "beginning"
        sincedb_path => "/dev/null"
        codec => multiline {
        pattern => "^%{TIME}"
        negate => true
        what => previous
   }}}
filter {
grok{
	  match => { "message" => "%{TIME:date} %{LOGLEVEL:level} %{GREEDYDATA:message}" }
    add_tag => ["groked"]
    remove_tag => ["_grokparsefailure"]
}}
output {
if	"ERROR" in [level]
{
elasticsearch {
  hosts=>"localhost:9200"
  index => "errors"
  document_type => "error"
  } }
stdout { codec => rubydebug }
}

```

I get this result in elasticsearch:

```
message: [
"16:54:46,234 ERROR [stderr] (ServerService Thread Pool -- 42) at org.slf4j.impl.StaticLoggerBinder.<clinit>(StaticLoggerBinder.java:55)",
"[stderr] (ServerService Thread Pool -- 42) at org.slf4j.impl.StaticLoggerBinder.<clinit>(StaticLoggerBinder.java:55)"
]

```

As you see the message error is [dublicated.So](http://dublicated.So),how can i keep juste the seconde message.  
Thank you for your helps.

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [July 3, 2017, 6:15pm UTC](https://discuss.elastic.co/t/logstash-dublicate-message/91664/2 "2017-07-03T18:15:54Z")

</div>

in the grok plugin you can use [the overwrite option](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-overwrite)

```auto
grok{
  match => { "message" => "%{TIME:date} %{LOGLEVEL:level} %{GREEDYDATA:message}" }
  add_tag => ["groked"]
  remove_tag => ["_grokparsefailure"]
  overwrite => ["message"]
}

```

---

<div class="post-metadata">

**Author:** ![baha1](https://avatars.discourse-cdn.com/v4/letter/b/b77776/32.png) [@baha1](https://discuss.elastic.co/u/baha1)\
**Post date:** [July 4, 2017, 9:08am UTC](https://discuss.elastic.co/t/logstash-dublicate-message/91664/3 "2017-07-04T09:08:47Z")

</div>

Thank you so much @jsvd.its works fine.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 1, 2017, 9:08am UTC](https://discuss.elastic.co/t/logstash-dublicate-message/91664/4 "2017-08-01T09:08:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
