# Need help with logstash conf file - spilitting log message

**URL:** <https://discuss.elastic.co/t/need-help-with-logstash-conf-file-spilitting-log-message/158078>\
**Category:** Logstash\
**Created:** [November 24, 2018, 9:52pm UTC](https://discuss.elastic.co/t/need-help-with-logstash-conf-file-spilitting-log-message/158078 "2018-11-24T21:52:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 24, 2018, 9:52pm UTC](https://discuss.elastic.co/t/need-help-with-logstash-conf-file-spilitting-log-message/158078/1 "2018-11-24T21:52:56Z")

</div>

Hello guys,

please could you help me to create logstash conf.d file for splitting following message?

1.234.85.29 \<1.234.85.29\> - - [24/Nov/2018:20:54:11 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" "-"

and following

85.216.232.12 \<141.101.96.139\> - - [24/Nov/2018:19:56:36 +0000] "GET /error/error-pages.css HTTP/1.1" 200 43506 "[https://01exchange.io/dashboard/0](https://01exchange.io/dashboard/0)" "Mozilla/5.0 (X11; Ubuntu; Linux x86\_64; rv:63.0) Gecko/20100101 Firefox/63.0" "85.216.232.12"

I know this can be time sonsuming and meybe I am asking too much to just get solution here. But please if you do not have time, please could you give me some clue how to work this?

I know there is grok debugger but I have no idea how it works.

Thank you

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 24, 2018, 9:55pm UTC](https://discuss.elastic.co/t/need-help-with-logstash-conf-file-spilitting-log-message/158078/2 "2018-11-24T21:55:51Z")

</div>

The biggest problem is how to write following:

1. I know 1.234.85.29 can be written as %{IP:client}  
But how can I write it if it ahs \<\> ? \<41.101.96.139\> ?

2. How can I write those dashes "-" ?

3. How can I process anything which is in quotes "" ?

---

<div class="post-metadata">

**Author:** ![Palino1611](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/palino1611/32/78648_2.png) [@Palino1611](https://discuss.elastic.co/u/Palino1611)\
**Post date:** [November 24, 2018, 11:30pm UTC](https://discuss.elastic.co/t/need-help-with-logstash-conf-file-spilitting-log-message/158078/3 "2018-11-24T23:30:55Z")

</div>

ok I think I got it:

%{IP:client} \<%{IP:host}\> - - [%{HTTPDATE:timestamp}] "%{WORD:method} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response} %{NUMBER:bytes} %{QS:referrer} %{QS:agent} "%{IP:endclient}"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 22, 2018, 11:30pm UTC](https://discuss.elastic.co/t/need-help-with-logstash-conf-file-spilitting-log-message/158078/4 "2018-12-22T23:30:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
