# Logstash Filter, is there a better way than mine

**URL:** <https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879>\
**Category:** Logstash\
**Created:** [April 7, 2022, 2:14pm UTC](https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879 "2022-04-07T14:14:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cRaZyT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crazyt/32/90071_2.png) [@cRaZyT](https://discuss.elastic.co/u/cRaZyT)\
**Post date:** [April 7, 2022, 2:14pm UTC](https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879/1 "2022-04-07T14:14:01Z")

</div>

Hi,

I have the following Logstash filter, which works, but I find it anything but good, that should work better, right?

Input:

> "The container group started for TEST"

```auto
  if "The container group started for" in [message] {
    grok {
      match => { "message" => "%%{WORD:w1}\s+%%{WORD:w2}\s+%%{WORD:w3}\s+%%{WORD:w4}\s+%%{WORD:w5}\s+%%{WORD:check}" }
    }
    mutate { remove_field => ["w1", "w2", "w3", "w4", "w5"]
    }
  }

```

Output:

> check: "TEST"

The message always consists of 6 words and I have to add the last word in a "check" field.

I had already tried the following ruby ​​filter, which didn't work:

```auto
if "The container group started for" in [message] {
    ruby { code => 'event.set("check",event.get("message").split("\s+")[-1])' }
  }

```

Does somebody has any idea?

Regards  
Thorsten

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 7, 2022, 4:57pm UTC](https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879/2 "2022-04-07T16:57:27Z")

</div>

> [@cRaZyT](#):
>
> `match => { "message" => "%%{WORD:w1}\s+%%{WORD:w2}\s+%%{WORD:w3}\s+%%{WORD:w4}\s+%%{WORD:w5}\s+%%{WORD:check}" }`

If you do not want to keep fields then do not name them.

```
match => { "message" => "^%{WORD}\s+%{WORD}\s+%{WORD:\s+%{WORD}\s+%{WORD}\s+%{WORD:check}" }

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 7, 2022, 5:18pm UTC](https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879/3 "2022-04-07T17:18:58Z")

</div>

If the message has always the same format, you can use a dissect filter instead of grok.

```auto
if "The container group started for" in [message] {
    dissect {
        mapping => {
            "message" => "The container group started for %{check}"
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![cRaZyT](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/crazyt/32/90071_2.png) [@cRaZyT](https://discuss.elastic.co/u/cRaZyT)\
**Post date:** [April 8, 2022, 7:57am UTC](https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879/4 "2022-04-08T07:57:40Z")

</div>

Thank you very much, both solutions work perfect, I like the "disect" solution better as I'm at loggerheads with "grok".

Regards  
Thorsten

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2022, 7:58am UTC](https://discuss.elastic.co/t/logstash-filter-is-there-a-better-way-than-mine/301879/5 "2022-05-06T07:58:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
