# Logstash not parser correctly with dissect

**URL:** <https://discuss.elastic.co/t/logstash-not-parser-correctly-with-dissect/199511>\
**Category:** Logstash\
**Created:** [September 14, 2019, 6:09pm UTC](https://discuss.elastic.co/t/logstash-not-parser-correctly-with-dissect/199511 "2019-09-14T18:09:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![McFly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mcfly/32/54213_2.png) [@McFly](https://discuss.elastic.co/u/McFly)\
**Post date:** [September 14, 2019, 6:09pm UTC](https://discuss.elastic.co/t/logstash-not-parser-correctly-with-dissect/199511/1 "2019-09-14T18:09:51Z")

</div>

Hello everyone! how are they? I need to consult them. I am parsing the logs of a service, the following come this way:

> |@ TIMESTAMP || DATE1 || DATE2 || DATE3 || DATE4 || DATE5 || DATE6 @|

However, when I see the logs in Kibana, in the field message it returns 2, 3 or even 4 records together:

> |@ TIMESTAMP || DATE1 || DATE2 || DATE3 || DATE4 || DATE5 || DATE6 @| |@ TIMESTAMP || DATE1 || DATE2 || DATE3 || DATE4 || DATE5 || DATE6 @| |@ TIMESTAMP || DATE1 || DATE2 || DATE3 || DATE4 || DATE5 || DATE6 @| |@ TIMESTAMP || DATE1 || DATE2 || DATE3 || DATE4 || DATE5 || DATE6 @|

my configuration is as follows:

> input {  
> beats {  
> port =\> 5444  
> }  
> }
> 
> filter {  
> mutate {  
> gsub =\> ["message", "\n", " "]  
> }  
> dissect {  
> mapping =\> {  
> "message" =\> "|@ %{logtimestamp} || %{addr} || %{user} || %{type} || %{info} || %{blank} || %{interface} @|"  
> }  
> }  
> mutate {  
> add\_field =\> { "newtimestamp" =\> "%{logtimestamp}" }  
> remove\_field =\> ["logtimestamp"]  
> }  
> date {  
> locale =\> "es-AR"  
> match =\> ["newtimestamp", "yyyy-MM-dd-HH.mm.ss.SSSSSS"]  
> timezone =\> "America/Argentina/Buenos\_Aires"  
> target =\> "@timestamp"  
> add\_field =\> { "debug" =\> "timestampMatched"}  
> }  
> }
> 
> output {  
> stdout {  
> codec =\> rubydebug  
> }  
> elasticsearch {  
> index =\> "gvplogs"  
> hosts =\> "elasticsearch:9200"  
> }  
> }

What I can be doing wrong? I'm missing something that I don't have in mind?

Thank you!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 15, 2019, 9:43am UTC](https://discuss.elastic.co/t/logstash-not-parser-correctly-with-dissect/199511/2 "2019-09-15T09:43:05Z")

</div>

Is each entry coming on a separate line? It looks like you may be missing newlines between the records there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 13, 2019, 9:43am UTC](https://discuss.elastic.co/t/logstash-not-parser-correctly-with-dissect/199511/3 "2019-10-13T09:43:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
