# Logstash Parsing Issue - Community Input request

**URL:** <https://discuss.elastic.co/t/logstash-parsing-issue-community-input-request/84807>\
**Category:** Logstash\
**Created:** [May 6, 2017, 6:45am UTC](https://discuss.elastic.co/t/logstash-parsing-issue-community-input-request/84807 "2017-05-06T06:45:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![andynz2017](https://avatars.discourse-cdn.com/v4/letter/a/e47c2d/32.png) [@andynz2017](https://discuss.elastic.co/u/andynz2017)\
**Post date:** [May 6, 2017, 6:45am UTC](https://discuss.elastic.co/t/logstash-parsing-issue-community-input-request/84807/1 "2017-05-06T06:45:22Z")

</div>

Hi All,

Got a bit of a curly issue which I'm reaching out to the community to help resolve.

I have parsed out a field within Exchange 2010 Transport log which appears to be presentative of a string, but contains both a substring that I wish to convert to unique date field with unique name as well as split the two non-date values using the ";" delimiter and store in the source-context field as sub-fields (I hope I've got the lingo right here).

Field Name: Source-Context  
Field Value: 08D48EEB952EE1A6;2017-05-06T06:28:04.718Z;0

I have attempted a mutate on that field using split ";" but I get a field mismatch in logstash-plain.log file and the message is lost. Is there a simple/graceful way of achieving what I want here? The original message uses grok pattern to parse the original message and I convert a lot of the fields to appropriate type depending on usage.

The other field that I believe has a similar issue is

Field Name: message-info  
Field Value: 2017-05-06T06:27:56.113Z;[SRV=excsvr2010.test.domain.com](http://SRV=excsvr2010.test.domain.com):TOTAL=8|SMR=8

Ideally I would want to also split this field and convert the date time field and then split out the other SRV, TOTAL and SMR values into their own fields. As the format isn't consistent, I'm finding it difficult to mutate the data to a state that is storable and ability to be queried.

Is there a mutate solution to this problem or would this potentially require an extra grok filter that applies to the two fields above? Keeping in mind that the date contained in these fields may vary in terms of length and the field delimiters may not be consistent.

Thought I would run this question past the community just in case I'm missing a simple fix here.

Any help or guidance is hugely appreciated.

Cheers,  
Andrew

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 8, 2017, 6:28am UTC](https://discuss.elastic.co/t/logstash-parsing-issue-community-input-request/84807/2 "2017-05-08T06:28:38Z")

</div>

For the first field I'd either use a grok filter to split it or use the mutate filter's split option, e.g. like this:

```nohighlight
grok {
  match => {
    "Source-Context" => "^%{BASE16NUM:whatever};%{GREEDYDATA:timestamp}"
  }
}

```

You should be able to use something similar for the `message-info` field, possibly in conjunction with a kv filter. What's ultimately best depends on _how_ the data is inconsistent.

---

<div class="post-metadata">

**Author:** ![andrewh](https://avatars.discourse-cdn.com/v4/letter/a/ce7236/32.png) [@andrewh](https://discuss.elastic.co/u/andrewh)\
**Post date:** [May 8, 2017, 6:58am UTC](https://discuss.elastic.co/t/logstash-parsing-issue-community-input-request/84807/3 "2017-05-08T06:58:13Z")

</div>

Hi Magnus,

Thanks for the quick and insightful response. I’ll play around with the different combinations and see what works best – will need to take a number of samples for each to ensure I get the best match.

Thanks for providing sanity around this for me, awesome service.

Cheers,  
Andrew

![](https://us1.discourse-cdn.com/elastic/original/2X/f/f464dd1c7c382c015b3fc53eebe1cd1aadffee61.jpg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2017, 7:02am UTC](https://discuss.elastic.co/t/logstash-parsing-issue-community-input-request/84807/4 "2017-06-05T07:02:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
