# LogStash, GROK and a Versa Appliance Log -

**URL:** <https://discuss.elastic.co/t/logstash-grok-and-a-versa-appliance-log/186552>\
**Category:** Logstash\
**Created:** [June 19, 2019, 10:33pm UTC](https://discuss.elastic.co/t/logstash-grok-and-a-versa-appliance-log/186552 "2019-06-19T22:33:16Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 19, 2019, 10:43pm UTC](https://discuss.elastic.co/t/logstash-grok-and-a-versa-appliance-log/186552/2 "2019-06-19T22:43:40Z")

</div>

I think a better approach would be

```
dissect { mapping => { "message" => "%{[@metadata][timestamp]} %{someField}, %{[restOfLine]}" } }
kv { source => restOfLine field_split => ", " remove_field => ["restOfLine"] }
date { match => ["[@metadata][timestamp]", ISO8601 ] }
```

---

_[View the full topic](https://discuss.elastic.co/t/logstash-grok-and-a-versa-appliance-log/186552)._
