# Logstash Filter

**URL:** <https://discuss.elastic.co/t/logstash-filter/272734>\
**Category:** Logstash\
**Created:** [May 11, 2021, 5:56pm UTC](https://discuss.elastic.co/t/logstash-filter/272734 "2021-05-11T17:56:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elk\_huh](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Post date:** [May 11, 2021, 5:56pm UTC](https://discuss.elastic.co/t/logstash-filter/272734/1 "2021-05-11T17:56:49Z")

</div>

`<166>1 2021-05-11T17:50:40+0000 flowIdLog, applianceName=nameofsight, app=app1`

How do i parse this, the KV section works but i dont know how to deal with this section  
" \<166\>1 2021-05-11T17:50:40+0000 flowIdLog "

```
filter{
dissect { mapping => { "message" => "%{[@metadata][ts]} %{} %{[@metadata][restOfLine]}" } }
kv { source => "%{[@metadata][restOfLine]}" field_split => "," value_split => "=" }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 11, 2021, 6:34pm UTC](https://discuss.elastic.co/t/logstash-filter/272734/2 "2021-05-11T18:34:30Z")

</div>

I would change the dissect to be

```
"%{} %{[@metadata][ts]} %{} %{[@metadata][restOfLine]}"

```

The first %{} will consume the \<166\>1

You may want to use trim\_key in the kv filter to remove spaces, or else use field\_split\_pattern match comma and space.

---

<div class="post-metadata">

**Author:** ![Elk\_huh](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Post date:** [May 11, 2021, 6:39pm UTC](https://discuss.elastic.co/t/logstash-filter/272734/3 "2021-05-11T18:39:05Z")

</div>

I have it changed to this . but it is not paring at all

```
filter{
dissect { mapping => { "message" => "%{} %{[@metadata][ts]} %{}, %{[@metadata][restOfLine]}" } }
kv { source => "%{[@metadata][restOfLine]}" field_split => "," value_split => "=" }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 11, 2021, 8:11pm UTC](https://discuss.elastic.co/t/logstash-filter/272734/4 "2021-05-11T20:11:05Z")

</div>

Can you post an example of a message that it fails to parse? Please use \</\> in the toolbar to quote it.

---

<div class="post-metadata">

**Author:** ![Elk\_huh](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Post date:** [May 12, 2021, 8:25pm UTC](https://discuss.elastic.co/t/logstash-filter/272734/5 "2021-05-12T20:25:35Z")

</div>

`<166>1 2021-05-12T13:26:21+0000 flowIdLog, applianceName=asdasdas, tenantName=fgdfdcbcvb, flowId=234234, flowCookie=1620826004, sourceIPv4Address=10.0.0.0, destinationIPv4Address=0.0.0.0, sourcePort=55838, destinationPort=443, tenantId=1, vsnId=0, applianceId=1, ingressInterfaceName=vni-0/4.4, egressInterfaceName=vni-0/0.0, fromCountry=, toCountry=United States, protocolIdentifier=6, fromZone=Intf-LAN-Zone, fromUser=Unknown, toZone=Intf-DIA-Zone, icmpTypeIPv4=0`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 12, 2021, 8:50pm UTC](https://discuss.elastic.co/t/logstash-filter/272734/6 "2021-05-12T20:50:29Z")

</div>

> [@Elk\_huh](#):
>
> ```
> source => "%{[@metadata][restOfLine]}"
> 
> ```

That should be

```
source => "[@metadata][restOfLine]"

```

I suggest you also add

```
trim_key => " "

```

Otherwise you will have spaces at the start of the keys, like this:

```
    " protocolIdentifier" => "6",
            " tenantName" => "fgdfdcbcvb",
                 " vsnId" => "0",

```

---

<div class="post-metadata">

**Author:** ![Elk\_huh](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Post date:** [May 14, 2021, 4:15pm UTC](https://discuss.elastic.co/t/logstash-filter/272734/7 "2021-05-14T16:15:41Z")

</div>

> [@Elk\_huh](#):
>
> ```auto
> filter{
> dissect { mapping => { "message" => "%{} %{[@metadata][ts]} %{}, %{[@metadata][restOfLine]}" } }
> kv { source => "%{[@metadata][restOfLine]}" field_split => "," value_split => "=" }
> }
> 
> ```

thanks that did the trick!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2021, 4:16pm UTC](https://discuss.elastic.co/t/logstash-filter/272734/8 "2021-06-11T16:16:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
