# Logstash mutate not replacing varible

**URL:** <https://discuss.elastic.co/t/logstash-mutate-not-replacing-varible/131515>\
**Category:** Logstash\
**Created:** [May 11, 2018, 4:19pm UTC](https://discuss.elastic.co/t/logstash-mutate-not-replacing-varible/131515 "2018-05-11T16:19:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [May 11, 2018, 4:19pm UTC](https://discuss.elastic.co/t/logstash-mutate-not-replacing-varible/131515/1 "2018-05-11T16:19:31Z")

</div>

I am on 6.2.4 and other variables seem to be working fine but my log\_message is not

Anyone have a clue why logstash is ignoring %{log\_message} ?

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e8dab787dee5e306a610430a22a0a15998551c25.png)

> ```
> {
> 
> ```
> 
> "\_index": "dbinfra-2018.05.11",  
> "\_type": "logs",  
> "\_id": "AWNP9cpRpKvosm9xCQSk",  
> "\_version": 1,  
> "\_score": null,  
> "\_source": {  
> "@timestamp": "2018-05-11T16:08:03.564Z",  
> "@version": "1",  
> "filename": "alert\_DDWOP1.log",  
> "path": "/oracle/product/diag/rdbms/ddwop/DDWOP1/trace/alert\_DDWOP1.log",  
> "INSTANCE\_NAME": "DDWOP1",  
> "tags": [  
> "multiline",  
> "\_grokparsefailure",  
> "\_dateparsefailure"  
> ],  
> "ALERTLOG\_FILE": "alert\_DDWOP1",  
> "oradb\_status": "running",  
> "DBNAME": "ddwop",  
> "host": "hd1mrc15na",  
> "dst\_index": "dbinfra",  
> "type": "alertlog",  
> **\> "message": "%{log\_message}"**  
> },  
> "fields": {  
> "@timestamp": [  
> 1526054883564  
> ]  
> },  
> "sort": [  
> 1526054883564  
> ]  
> }

* * *

## Logstash

> # Extract the date and the rest from the message
> 
> grok {  
> match =\> ["message","%{DAY:day} %{MONTH:month} %{MONTHDAY:monthday} %{TIME:time} %{YEAR:year}(?\<log\_message\>.\*$)"]  
> }  
> grok {  
> match =\> ["path" , "/oracle/product/diag/rdbms/%{WORD:DBNAME}/%{WORD:INSTANCE\_NAME}/trace/%{WORD:ALERTLOG\_FILE}"]  
> }
> 
> mutate {  
> add\_field =\> {  
> "timestamp" =\> "%{year} %{month} %{monthday} %{time}"  
> }  
> }
> 
> # replace the timestamp by the one coming from the alert.log
> 
> date {  
> locale =\> "en"  
> match =\> ["timestamp" , "yyyy MMM dd HH:mm:ss"]  
> }
> 
> # replace the message (remove the date)
> 
> mutate { replace =\> ["message", "%{log\_message}"] }

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [May 14, 2018, 9:31am UTC](https://discuss.elastic.co/t/logstash-mutate-not-replacing-varible/131515/2 "2018-05-14T09:31:56Z")

</div>

In your example there is a \__grokparsefailure_ tag, meaning it failed to apply the first grok.  
So the _log\_message_ field is never created, and as such the last replace fails to interpolate the variable and just inserts it as a literal string.

You should probably check why the initial grok fails in the first place.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [May 14, 2018, 11:39am UTC](https://discuss.elastic.co/t/logstash-mutate-not-replacing-varible/131515/3 "2018-05-14T11:39:53Z")

</div>

Ah that would make sense, I found out the person who wrote that config and some other pieces I did not post just copy and pasted it from a blog. I went and re-wrote the whole thing, as there were lots of unneeded or meaningless mutates.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2018, 11:39am UTC](https://discuss.elastic.co/t/logstash-mutate-not-replacing-varible/131515/4 "2018-06-11T11:39:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
