# Matching/Finding certain text using logstash filter

**URL:** <https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411>\
**Category:** Logstash\
**Created:** [April 26, 2016, 10:19am UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411 "2016-04-26T10:19:44Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [April 26, 2016, 10:19am UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/1 "2016-04-26T10:19:44Z")

</div>

I have a text with [INFO or ERROR or Warn] concatenated with few other texts, which i am able to get under greedy data, But I want to split those Log Level values under new field.

Sample Text: 2016 Apr 26 15:44:40:603 GMT +0530 BW.Service-1-Service Info [BW-User] - Job-8309-2 [Logger/LogToLocal.process/Log]: Processed Service\_01 with BusinessObjectId:1111 and ConversationId:11111 and MessageId:1111  
If reg ex is the solution, kindly suggest with example.  
Help or suggestion would be very helpful.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 26, 2016, 4:58pm UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/2 "2016-04-26T16:58:24Z")

</div>

Use a grok filter to extract new fields from text in existing fields. Show us what you have so far. Presumably you already have a grok filter to parse the line. In the example above, is "Info" right after "BW.Service-1-Service" the string you want to extract?

---

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [April 30, 2016, 9:16am UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/3 "2016-04-30T09:16:33Z")

</div>

Hi Magnus  
Thanks for the reply,

Yes it is right after that. I am now able parse the text like below using the grok filter.

Text: 2016 Apr 26 15:44:40:603 GMT +0530 BW.Service-1-Service Info [BW-User] - Job-8309-2 [Logger/LogToLocal.process/Log]: Processed Service\_01 with BusinessObjectId:1111 and ConversationId:11111 and MessageId:1111

%{YEAR} %{MONTH} %{MONTHDAY} %{TIME} GMT +%{INT} %{PROG:program} %{WORD:loglevel} [%{USER:auth}] %{GREEDYDATA:BwLog1}

Getting matched and able to see the data in kibana.

But in Kibana Visualization, these tags PROG:program is not showing up for filtering.. Same is available in Discover section but not in Visualization.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 30, 2016, 2:31pm UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/4 "2016-04-30T14:31:56Z")

</div>

> But in Kibana Visualization, these tags PROG:program is not showing up for filtering.. Same is available in Discover section but not in Visualization.

Sorry, I don't quite understand what the problem is. Maybe a screenshot would make it easier for you to explain what the problem.

---

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [May 1, 2016, 6:42pm UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/5 "2016-05-01T18:42:05Z")

</div>

Below is the Discover and Visualization /pie chart sections screen shots.

Program section getting displayed under discover is not getting displayed in visualization.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/0/06fc9125ba533071b3d324f5bc366579a21bd2b3.PNG)  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/aea1ad1934ac5122d56719069a437e85f29e2831.PNG)

---

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [May 2, 2016, 5:15am UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/6 "2016-05-02T05:15:53Z")

</div>

Hi Magnus,  
I found the solution, By Refreshing the settings section able to get the field in visualization section.

Can you give brief explain for what is Analysed Field and Indexed Field.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 3, 2016, 11:04am UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/7 "2016-05-03T11:04:53Z")

</div>

See the description of the index attribute for fields for a definition of these terms: [https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-intro.html#\_index\_2](https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-intro.html#_index_2)

See [https://www.elastic.co/guide/en/elasticsearch/guide/current/analysis-intro.html](https://www.elastic.co/guide/en/elasticsearch/guide/current/analysis-intro.html) for a description of what analysis is all about.

---

<div class="post-metadata">

**Author:** ![spravn789](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@spravn789](https://discuss.elastic.co/u/spravn789)\
**Post date:** [September 21, 2016, 9:04am UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/8 "2016-09-21T09:04:53Z")

</div>

Hi Magnus,

Everything was working fine. Suddenly facing few issues.

We have 4 different machine running logstash, and shipping data to elasticsearch running in different machine on same network. Issue are as below,

1. In kibana, not able to view data from 3 machines, only one machine data is visible on kibana.
2. In Kibana when i do monitoring particular field, and tried to sort that, receiving error as  
Failed to execute [org.elasticsearch.action.search.SearchRequest@74a9c9f4] lastShard [true],nested: IllegalStateException[Field data loading is forbidden on [jobid]];,Caused by: java.lang.IllegalStateException: Field data loading is forbidden on [jobid]

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 21, 2016, 10:57am UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/9 "2016-09-21T10:57:01Z")

</div>

Please start new threads for your new problems instead of reviving old threads that discuss something else.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:37am UTC](https://discuss.elastic.co/t/matching-finding-certain-text-using-logstash-filter/48411/10 "2017-07-06T04:37:40Z")

</div>


