# Logstash line break

**URL:** <https://discuss.elastic.co/t/logstash-line-break/32511>\
**Category:** Logstash\
**Created:** [October 19, 2015, 4:48pm UTC](https://discuss.elastic.co/t/logstash-line-break/32511 "2015-10-19T16:48:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Erik\_Parienty](https://avatars.discourse-cdn.com/v4/letter/e/a587f6/32.png) [@Erik\_Parienty](https://discuss.elastic.co/u/Erik_Parienty)\
**Post date:** [October 19, 2015, 4:48pm UTC](https://discuss.elastic.co/t/logstash-line-break/32511/1 "2015-10-19T16:48:16Z")

</div>

**i have this config with a long line**  
grok {  
match =\> {  
"message" =\> "%{DATESTAMP:LogDate},%{NUMBER:RamUsedPercent:float},%{NUMBER:CpuPercent:float},%{NUMBER:DiskFreePercentC:float},%{NUMBER:DiskFreePercentD:float},%{NUMBER:ASPRequestExecutionTime:float},%{NUMBER:ASPRequestWaitTime:float},%{NUMBER:ASPRequestCurrent:float},%{NUMBER:ASPRequestQueued:float},%{NUMBER:ASPRequestRejected:float},%{NUMBER:ASPApplicationsPipelineInstanceCount:float},%{NUMBER:ASPApplicationsRequestWaitTime:float},%{NUMBER:ASPApplicationsRequestsFailed:float},%{NUMBER:ASPApplicationsRequestsInApplication Queue:float},%{NUMBER:ASPApplicationsRequestsRejected:float},%{NUMBER:ASPApplicationsRequestsTimedOut:float},%{NUMBER:ASPApplicationsRequestsSec:float},%{NUMBER:AzureQueueLastLiveSessionsDequeueTime:float}"  
}

**How can i break it like this:**

```
grok {
		match => {
			"message" => "%{DATESTAMP:LogDate},

```

%{NUMBER:RamUsedPercent:float},%  
{NUMBER:CpuPercent:float},  
%{NUMBER:DiskFreePercentC:float},  
%{NUMBER:DiskFreePercentD:float},  
%{NUMBER:ASPRequestExecutionTime:float},  
%{NUMBER:ASPRequestWaitTime:float},  
%{NUMBER:ASPRequestCurrent:float},  
%{NUMBER:ASPRequestQueued:float},  
%{NUMBER:ASPRequestRejected:float},  
%{NUMBER:ASPApplicationsPipelineInstanceCount:float},  
%{NUMBER:ASPApplicationsRequestWaitTime:float},  
%{NUMBER:ASPApplicationsRequestsFailed:float},  
%{NUMBER:ASPApplicationsRequestsInApplication Queue:float},%{NUMBER:ASPApplicationsRequestsRejected:float},  
%{NUMBER:ASPApplicationsRequestsTimedOut:float},  
%{NUMBER:ASPApplicationsRequestsSec:float},  
%{NUMBER:AzureQueueLastLiveSessionsDequeueTime:float}"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2015, 6:42pm UTC](https://discuss.elastic.co/t/logstash-line-break/32511/2 "2015-10-19T18:42:59Z")

</div>

Because of the formatting of the message it's hard to see any difference between the two samples you posted (hint: use the preview pane to the right to inspect what you're about to post), but I'm assuming you want to be ample to break the otherwise very long line.

It would've been desired with an ability to concatenate string via

```
"string1" "string2"

```

or

```
"string1" + "string2"

```

but unfortunately I don't think that's possible. The Logstash configuration language just isn't a fully-fledged programming language.

Well, impossible without ugly hacks anyway. You could use a mutate or ruby filter to create a temporary array field with all the comma separated values, join them with an mutate filter, then pass the resulting string to the grok filter.

---

<div class="post-metadata">

**Author:** ![Erik\_Parienty](https://avatars.discourse-cdn.com/v4/letter/e/a587f6/32.png) [@Erik\_Parienty](https://discuss.elastic.co/u/Erik_Parienty)\
**Post date:** [October 20, 2015, 3:00pm UTC](https://discuss.elastic.co/t/logstash-line-break/32511/3 "2015-10-20T15:00:39Z")

</div>

Thanks will work with 1 very long file 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:26am UTC](https://discuss.elastic.co/t/logstash-line-break/32511/4 "2017-07-06T05:26:01Z")

</div>


