# Logstash field split

**URL:** <https://discuss.elastic.co/t/logstash-field-split/78693>\
**Category:** Logstash\
**Created:** [March 15, 2017, 11:53am UTC](https://discuss.elastic.co/t/logstash-field-split/78693 "2017-03-15T11:53:15Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 15, 2017, 11:53am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/1 "2017-03-15T11:53:15Z")

</div>

How to split

"content" =\> "command hitesh.restaurants command: drop { drop: "restaurants" } keyUpdates:0 writeConflicts:0 numYields:0 reslen:81 locks:{ Global: { acquireCount: { r: 1, w: 1 } }, Database: { acquireCount: { W: 1 } } } protocol:op\_query 39ms\r"

into different fields????

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 12:04pm UTC](https://discuss.elastic.co/t/logstash-field-split/78693/2 "2017-03-15T12:04:42Z")

</div>

You can definitely do it with a grok filter but a dissect filter might be faster or easier to maintain.

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 15, 2017, 12:31pm UTC](https://discuss.elastic.co/t/logstash-field-split/78693/3 "2017-03-15T12:31:47Z")

</div>

filter {  
grok {

```
      match => { message => 

```

"%{TIMESTAMP\_ISO8601:@timestamp} %{MONGO3\_SEVERITY:severity} %{MONGO3\_COMPONENT:component}%{SPACE}(?:[%{DATA:context}])? %{GREEDYDATA:content}" }

```
        }   

```

if [component] != "COMMAND" {  
drop { }  
}   
mutate{  
remove\_field =\> "message"  
}  
}

This is my logstash conf file

and its output is

{  
"severity" =\> "I",  
"path" =\> "C:/data/log/mongo.log",  
"component" =\> "COMMAND",  
"@timestamp" =\> 2017-03-15T11:42:35.230Z,  
"@version" =\> "1",  
"host" =\> "DESKTOP-PKMSR1Q",  
"context" =\> "conn3",  
"content" =\> "command hitesh.restaurants command: insert { insert: "restaurants", ordered: false, documents: 1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 numYields:0 reslen:40 locks:{ Global: { acquireCount: { r: 17, w: 17 } }, Database: { acquireCount: { w: 16, W: 1 } }, Collection: { acquireCount: { w: 16, W: 1 } } } protocol:op\_query 194ms\r"  
}

I wants to split content field

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 15, 2017, 12:49pm UTC](https://discuss.elastic.co/t/logstash-field-split/78693/4 "2017-03-15T12:49:44Z")

</div>

Multiple problems:

- The field you want to parse is `content` but you've configured the grok filter to parse the `message` field.
- Your grok filter doesn't even resemble what you want to parse. For starters, your messages doesn't begin with a timestamp but you've configured grok to begin by looking for an ISO8601 timestamp.

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 15, 2017, 1:45pm UTC](https://discuss.elastic.co/t/logstash-field-split/78693/5 "2017-03-15T13:45:10Z")

</div>

my log ooks like

2017-03-14T17:08:12.615+0530 I COMMAND [conn2] command hitesh.zips command: insert { insert: "zips", ordered: false, documents: 1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 numYields:0 reslen:40 locks:{ Global: { acquireCount: { r: 17, w: 17 } }, Database: { acquireCount: { w: 16, W: 1 } }, Collection: { acquireCount: { w: 16, W: 1 } } } protocol:op\_query 541ms

This is message field for logstash

And inside message field content field so how to split only content field???

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 16, 2017, 7:33am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/6 "2017-03-16T07:33:42Z")

</div>

As you told me i tried dissect filter

dissect {  
mapping =\> {  
"content" =\> "%{query} %{+command} %{+ninserted} %{+keyUpdates} %{+writeConflicts} %{+numYields} %{+reslen} %{+locks} %{+database} %{+collection} %{+protocol} [%{pid}]: %{content}"  
}  
}

and it is giving output as

```
       "context" => "conn6",
        "reslen" => "\"zips\","

```

}  
{  
"severity" =\> "I",  
"numYields" =\> "insert:",  
"query" =\> "command",  
"pid" =\> "",  
"collection" =\> "documents:",  
"locks" =\> "ordered:",  
"content" =\> "1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 num  
Yields:0 reslen:40 locks:{ Global: { acquireCount: { r: 16, w: 16 } }, Database:  
{ acquireCount: { W: 16 }, acquireWaitCount: { W: 14 }, timeAcquiringMicros: {  
W: 9529 } }, Collection: { acquireCount: { w: 16 } } } protocol:op\_query 81ms\r"  
,  
"command" =\> "admin.zips",  
"tags" =\> [],  
"path" =\> "C:/Data/log/mongodb2.log",  
"writeConflicts" =\> "{",  
"component" =\> "COMMAND",  
"database" =\> "false,",  
"protocol" =\> "",  
"@timestamp" =\> 2017-03-16T06:41:29.146Z,  
"ninserted" =\> "command:",  
"keyUpdates" =\> "insert",  
"@version" =\> "1",  
"host" =\> "Admin-PC",  
"context" =\> "conn2",  
"reslen" =\> ""zips","  
}  
{  
"severity" =\> "I",  
"numYields" =\> "insert:",  
"query" =\> "command",  
"pid" =\> "",  
"collection" =\> "documents:",  
"locks" =\> "ordered:",  
"content" =\> "1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 num  
Yields:0 reslen:40 locks:{ Global: { acquireCount: { r: 16, w: 16 } }, Database:  
{ acquireCount: { W: 16 }, acquireWaitCount: { W: 2 }, timeAcquiringMicros: { W  
: 1723 } }, Collection: { acquireCount: { w: 16 } } } protocol:op\_query 12ms\r",

```
       "command" => "admin.zips",
          "tags" => [],
          "path" => "C:/Data/log/mongodb2.log",
"writeConflicts" => "{",
     "component" => "COMMAND",
      "database" => "false,",
      "protocol" => "",
    "@timestamp" => 2017-03-16T06:41:29.147Z,
     "ninserted" => "command:",
    "keyUpdates" => "insert",
      "@version" => "1",
          "host" => "Admin-PC",
       "context" => "conn2",
        "reslen" => "\"zips\","

```

}  
{  
"severity" =\> "I",  
"numYields" =\> "insert:",  
"query" =\> "command",  
"pid" =\> "",  
"collection" =\> "documents:",  
"locks" =\> "ordered:",  
"content" =\> "1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 num  
Yields:0 reslen:40 locks:{ Global: { acquireCount: { r: 16, w: 16 } }, Database:  
{ acquireCount: { W: 16 }, acquireWaitCount: { W: 8 }, timeAcquiringMicros: { W  
: 4354 } }, Collection: { acquireCount: { w: 16 } } } protocol:op\_query 17ms\r",

```
       "command" => "admin.zips",
          "tags" => [],
          "path" => "C:/Data/log/mongodb2.log",
"writeConflicts" => "{",
     "component" => "COMMAND",
      "database" => "false,",
      "protocol" => "",
    "@timestamp" => 2017-03-16T06:41:29.147Z,
     "ninserted" => "command:",
    "keyUpdates" => "insert",
      "@version" => "1",
          "host" => "Admin-PC",
       "context" => "conn6",
        "reslen" => "\"zips\","

```

}  
{  
"severity" =\> "I",  
"numYields" =\> "insert:",  
"query" =\> "command",  
"pid" =\> "",  
"collection" =\> "documents:",  
"locks" =\> "ordered:",  
"content" =\> "1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 num  
Yields:0 reslen:40 locks:{ Global: { acquireCount: { r: 16, w: 16 } }, Database:  
{ acquireCount: { W: 16 }, acquireWaitCount: { W: 11 }, timeAcquiringMicros: {  
W: 6108 } }, Collection: { acquireCount: { w: 16 } } } protocol:op\_query 18ms\r"  
,  
"command" =\> "admin.zips",  
"tags" =\> [],  
"path" =\> "C:/Data/log/mongodb2.log",  
"writeConflicts" =\> "{",  
"component" =\> "COMMAND",  
"database" =\> "false,",  
"protocol" =\> "",  
"@timestamp" =\> 2017-03-16T06:41:29.147Z,  
"ninserted" =\> "command:",  
"keyUpdates" =\> "insert",  
"@version" =\> "1",  
"host" =\> "Admin-PC",  
"context" =\> "conn3",  
"reslen" =\> ""zips","  
}  
{  
"severity" =\> "I",  
"numYields" =\> "insert:",  
"query" =\> "command",  
"pid" =\> "",  
"collection" =\> "documents:",  
"locks" =\> "ordered:",  
"content" =\> "1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 num  
Yields:0 reslen:40 locks:{ Global: { acquireCount: { r: 16, w: 16 } }, Database:  
{ acquireCount: { W: 16 }, acquireWaitCount: { W: 16 }, timeAcquiringMicros: {  
W: 9847 } }, Collection: { acquireCount: { w: 16 } } } protocol:op\_query 19ms\r"  
,  
"command" =\> "admin.zips",  
"tags" =\> [],  
"path" =\> "C:/Data/log/mongodb2.log",  
"writeConflicts" =\> "{",  
"component" =\> "COMMAND",  
"database" =\> "false,",  
"protocol" =\> "",  
"@timestamp" =\> 2017-03-16T06:41:29.147Z,  
"ninserted" =\> "command:",  
"keyUpdates" =\> "insert",  
"@version" =\> "1",  
"host" =\> "Admin-PC",  
"context" =\> "conn5",  
"reslen" =\> ""zips","  
}  
{  
"severity" =\> "I",  
"numYields" =\> "insert:",  
"query" =\> "command",  
"pid" =\> "",  
"collection" =\> "documents:",  
"locks" =\> "ordered:",  
"content" =\> "1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 num  
Yields:0 reslen:40 locks:{ Global: { acquireCount: { r: 16, w: 16 } }, Database:  
{ acquireCount: { W: 16 }, acquireWaitCount: { W: 12 }, timeAcquiringMicros: {  
W: 8421 } }, Collection: { acquireCount: { w: 16 } } } protocol:op\_query 17ms\r"  
,  
"command" =\> "admin.zips",  
"tags" =\> [],  
"path" =\> "C:/Data/log/mongodb2.log",  
"writeConflicts" =\> "{",  
"component" =\> "COMMAND",  
"database" =\> "false,",  
"protocol" =\> "",  
"@timestamp" =\> 2017-03-16T06:41:29.148Z,  
"ninserted" =\> "command:",  
"keyUpdates" =\> "insert",  
"@version" =\> "1",  
"host" =\> "Admin-PC",  
"context" =\> "conn2",  
"reslen" =\> ""zips","  
}

but the values are not exact

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 6:22am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/7 "2017-03-17T06:22:21Z")

</div>

It seems you and @Nikparab are asking the exact same question. Let's deal with the problem in one thread, please. See [Logstash configuration](https://discuss.elastic.co/t/logstash-configuration/74982).

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 17, 2017, 6:33am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/8 "2017-03-17T06:33:12Z")

</div>

Sure, no problem on that.

But, can i only split the last field from,

2017-03-14T17:08:12.615+0530 I COMMAND [conn2] command hitesh.zips command: insert { insert: "zips", ordered: false, documents: 1000 } ninserted:1000 keyUpdates:0 writeConflicts:0 numYields:0 reslen:40 locks:{ Global: { acquireCount: { r: 17, w: 17 } }, Database: { acquireCount: { w: 16, W: 1 } }, Collection: { acquireCount: { w: 16, W: 1 } } } protocol:op\_query 541ms

I just want that ms and it's value as '541' and i am not having consistent logs.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 6:44am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/9 "2017-03-17T06:44:38Z")

</div>

I'm focusing on the other thread, but if you only care about the final millisecond value that's very easy to do with a grok filter.

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 17, 2017, 6:48am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/10 "2017-03-17T06:48:42Z")

</div>

I am having one grok for splitting that one line of log.

How to split content with grok again ,i am confused here.

can you guide me,please?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 6:56am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/11 "2017-03-17T06:56:44Z")

</div>

You can have multiple grok fields in your configuration. Each filter can parse different fields, and the fields produced by one filter can be parsed by a second filter. If you don't care about the stuff you've extracted to the `content` field (except the millisecond duration at the end) you can just add `.*%{INT:duration:int}$` to the end of your first grok filter.

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 17, 2017, 7:10am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/12 "2017-03-17T07:10:51Z")

</div>

grok {

```
      match => { message => "%{TIMESTAMP_ISO8601:@timestamp} %{MONGO3_SEVERITY:severity} %{MONGO3_COMPONENT:component}%{SPACE}(?:\[%{DATA:context}\])? %{GREEDYDATA:content}.*%{INT:duration:int}ms" }
        }            

```

is this the correct way?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 7:26am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/13 "2017-03-17T07:26:43Z")

</div>

You forgot the final dollar sign but otherwise yes. If you don't care about the other stuff you're capturing with `%{GREEDYDATA:content}` you can just delete it.

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 17, 2017, 7:43am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/14 "2017-03-17T07:43:45Z")

</div>

sorry that i forgot the $ sign.

and now i tried to remove %{GREEDYDATA:content} field but it was not giving output:-

C:\ELK\logstash-5.2.2\>bin\logstash -f bin\logstash.conf  
Could not find log4j2 configuration at path /ELK/logstash-5.2.2/config/log4j2.properties. Using default config which logs to console  
13:15:30.548 [[main]-pipeline-manager] INFO logstash.outputs.elasticsearch - Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
13:15:30.548 [[main]-pipeline-manager] INFO logstash.outputs.elasticsearch - Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
13:15:30.688 [[main]-pipeline-manager] WARN logstash.outputs.elasticsearch - Restored connection to ES instance {:url=\>#\<URI::HTTP:0x355c3142 URL:[http://localhost:9200/](http://localhost:9200/)\>}  
13:15:30.688 [[main]-pipeline-manager] INFO logstash.outputs.elasticsearch - Using mapping template from {:path=\>nil}  
13:15:30.970 [[main]-pipeline-manager] INFO logstash.outputs.elasticsearch - Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>50001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword"}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=\>false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
13:15:30.970 [[main]-pipeline-manager] INFO logstash.outputs.elasticsearch - New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>[#\<URI::Generic:0x2063c524 URL://localhost:9200\>]}  
13:15:31.079 [[main]-pipeline-manager] INFO logstash.pipeline - Starting pipeline {"id"=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>500}  
13:15:31.360 [[main]-pipeline-manager] INFO logstash.pipeline - Pipeline main started  
13:15:31.454 [Api Webserver] INFO logstash.agent - Successfully started Logstash API endpoint {:port=\>9600}  
after this it is not showing anything

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 8:17am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/15 "2017-03-17T08:17:09Z")

</div>

That's unrelated to the GREEDYDATA removal. If you show your input configuration we can probably help.

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 17, 2017, 8:18am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/16 "2017-03-17T08:18:07Z")

</div>

input {  
file {  
path =\> "C:/Data/mongobdg1.log"  
start\_position =\> "beginning" }  
}  
filter {  
grok {

```
      match => { message => "%{TIMESTAMP_ISO8601:@timestamp} %{MONGO3_SEVERITY:severity} %{MONGO3_COMPONENT:component}%{SPACE}(?:\[%{DATA:context}\])? .*%{INT:duration:int}$" }
        }            

```

mutate{  
remove\_field =\> "message"  
}  
if [component] != "COMMAND" {  
drop { }  
}  
}  
output {  
elasticsearch{ hosts =\> ["localhost:9200"] index =\> "deepak2" }  
stdout {codec =\> "rubydebug" }  
}

This is my logstash configuration file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 8:21am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/17 "2017-03-17T08:21:05Z")

</div>

Logstash is tailing the input file. Set `sincedb_path => "nul"` in your file input to disable the sincedb functionality.

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 17, 2017, 8:27am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/18 "2017-03-17T08:27:15Z")

</div>

Still it is not giving any output.

input {  
file {  
path =\> "C:/Data/mongobdg14.log"  
start\_position =\> "beginning"  
sincedb\_path =\> "nul"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 17, 2017, 8:39am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/19 "2017-03-17T08:39:50Z")

</div>

Depending on what Logstash you're running you may need to adjust the `ignore_older` option (see the documentation). If that doesn't help bump up the log level to get more clues.

---

<div class="post-metadata">

**Author:** ![wolfghost](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfghost/32/15500_2.png) [@wolfghost](https://discuss.elastic.co/u/wolfghost)\
**Post date:** [March 17, 2017, 8:47am UTC](https://discuss.elastic.co/t/logstash-field-split/78693/20 "2017-03-17T08:47:04Z")

</div>

This is my grok filter  
grok {

```
      match => { message => "%{TIMESTAMP_ISO8601:timestamp} %{MONGO3_SEVERITY:severity} %{MONGO3_COMPONENT:component}%{SPACE}(?:\[%{DATA:context}\])? %{GREEDYDATA:content}.*%{INT:duration:int}ms"}
     }

```

for log

2017-03-07T00:56:57.473-0800 I COMMAND [conn44599] command hgthanka.Recognition command: aggregate { aggregate: "Recognition", pipeline: [{ $match: { Status: "Active", SuppressInFeed: false, Template.Type: { $in: [ "Recognition", "KeyResult", "Objective", "Milestone", "Award", "Context", "Thanks", "Quick", "Congrats", "Newsfeed", "ProductItem", "PollResult", "GoalKeyResultUpdate"] }, Template.GroupId: "c6ce5dc0-1041-11e5-b713-cf230176158d", $and: [{ $or: [ { VisibilityMemberIds: null }, { VisibilityMemberIds: { $in: [ "5b389ed2-1055-11e5-b2e5-75f447e35752"] } } ] }, { $or: [{ VisibilityLocations.hgId: null }, { VisibilityLocations.hgId: { $in: [ "5b09c660-1055-11e5-b2e5-75f447e35752"] } } ] } ] } }, { $group: { \_id: "$BatchId", max: { $max: "$ModifiedDate" } } }, { $sort: { max: -1 } }, { $skip: 40 }, { $limit: 10 }, { $project: { \_id: 0, BatchId: "$\_id" } } ] } keyUpdates:0 writeConflicts:0 numYields:198 reslen:648 locks:{ Global: { acquireCount: { r: 404 } }, Database: { acquireCount: { r: 202 } }, Collection: { acquireCount: { r: 202 } } } protocol:op\_query 157ms

and its output is

{  
"severity" =\> "I",  
"duration" =\> 7,  
"path" =\> "C:/data/log/mongo225.log",  
"component" =\> "COMMAND",  
"host" =\> "DESKTOP-PKMSR1Q",  
"context" =\> "conn44599",  
"content" =\> "command hgthanka.Recognition command: aggregate { aggregate: "Recognition", pipeline: [{ $match: { Status: "Active", SuppressInFeed: false, Template.Type: { $in: [ "Recognition", "KeyResult", "Objective", "Milestone", "Award", "Context", "Thanks", "Quick", "Congrats", "Newsfeed", "ProductItem", "PollResult", "GoalKeyResultUpdate"] }, Template.GroupId: "c6ce5dc0-1041-11e5-b713-cf230176158d", $and: [{ $or: [ { VisibilityMemberIds: null }, { VisibilityMemberIds: { $in: [ "5b389ed2-1055-11e5-b2e5-75f447e35752"] } } ] }, { $or: [{ VisibilityLocations.hgId: null }, { VisibilityLocations.hgId: { $in: [ "5b09c660-1055-11e5-b2e5-75f447e35752"] } } ] } ] } }, { $group: { \_id: "$BatchId", max: { $max: "$ModifiedDate" } } }, { $sort: { max: -1 } }, { $skip: 40 }, { $limit: 10 }, { $project: { \_id: 0, BatchId: "$\_id" } } ] } keyUpdates:0 writeConflicts:0 numYields:198 reslen:648 locks:{ Global: { acquireCount: { r: 404 } }, Database: { acquireCount: { r: 202 } }, Collection: { acquireCount: { r: 202 } } } protocol:op\_query 15",  
"timestamp" =\> "2017-03-07T00:56:57.473-0800"  
}

in duration it is showing as 7  
but i want 157ms?

I think it is only showing last integer number instead of showing whole duration field.

[Next page](https://discuss.elastic.co/t/logstash-field-split/78693.md?page=2)
