# Mutate "message" don't understand example

**URL:** <https://discuss.elastic.co/t/mutate-message-dont-understand-example/77985>\
**Category:** Logstash\
**Created:** [March 9, 2017, 1:15pm UTC](https://discuss.elastic.co/t/mutate-message-dont-understand-example/77985 "2017-03-09T13:15:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pgrzec2s](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pgrzec2s/32/14345_2.png) [@pgrzec2s](https://discuss.elastic.co/u/pgrzec2s)\
**Post date:** [March 9, 2017, 1:15pm UTC](https://discuss.elastic.co/t/mutate-message-dont-understand-example/77985/1 "2017-03-09T13:15:04Z")

</div>

I read the [Example](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-remove_field) about mutating a fiel in logstash but I don't understand the syntax correctly.

After parsing I want to replace the whole "message" with the %{GREEDYDATA} part.

so i tried:  
`if [type] == "apache-error" { grok { match => { "message" => "\[%{DATA:LogID}\]\s\[%{TIMESTAMP_ISO8601:timestamp}\]\s\[.*: %{LOGLEVEL:loglevel}\]\s\[\w+: %{NUMBER:pid}\]\s\[%{IPORHOST:client}\:%{POSINT:port}\]\s\[%{DATA:src filename}\]\s(\[%{DATA:errorstatus}\])?%{GREEDYDATA:message}" } } date { #match => ["timestamp", "TIMESTAMP_ISO8601"] match => ["timestamp", "YYYY-MM-dd HH:mm:ss.SSSSSS"] } mutate { replace=> { "message" => "%{GREEDYDATA}" } remove_field => ["timestamp", "tags", "input_type"] remove_tag => ["beat.name","beat.version","_score","_type"] } }`

But Kibana shows me only **message: %GREEDYDATA**  
So how can i replace the message after parsing with %GREEDYDATA ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 9, 2017, 1:21pm UTC](https://discuss.elastic.co/t/mutate-message-dont-understand-example/77985/2 "2017-03-09T13:21:30Z")

</div>

The GREEDYDATA part should already be stored in the message field as that is what your configuration shows. If this is not working, possibly as the message field is being processed, you could change the name of the captured field to something else, e.g. message1. You can then replace the message field with the message1 field in your mutate filter and then drop the message1 field.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2017, 1:27pm UTC](https://discuss.elastic.co/t/mutate-message-dont-understand-example/77985/3 "2017-03-09T13:27:37Z")

</div>

You need to include `overwrite => ["message"]` in your grok filter.

> ```
> #match => ["timestamp", "TIMESTAMP_ISO8601"]
> 
> ```

Don't conflate grok patterns with date patterns. You could've used ISO8601 here.

> ```
> replace=> { "message" => "%{GREEDYDATA}" }
> 
> ```

This doesn't make sense since you don't have a field named `GREEDYDATA`. Remove it.

> ```
> remove_tag => ["beat.name","beat.version","_score","_type"]
> 
> ```

Multiple problems:

- Use `remove_field` to remove fields, not `remove_tag`.
- `_score` and `_type` aren't actual fields in the event so you can't remove them.
- You're not using the correct syntax for nested fields. Read more here: [Accessing event data and fields | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references)

---

<div class="post-metadata">

**Author:** ![pgrzec2s](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pgrzec2s/32/14345_2.png) [@pgrzec2s](https://discuss.elastic.co/u/pgrzec2s)\
**Post date:** [March 9, 2017, 1:29pm UTC](https://discuss.elastic.co/t/mutate-message-dont-understand-example/77985/4 "2017-03-09T13:29:35Z")

</div>

Thank you both for fast responding, trying again.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2017, 1:29pm UTC](https://discuss.elastic.co/t/mutate-message-dont-understand-example/77985/5 "2017-04-06T13:29:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
