# Newbie Issue with multiple dissects

**URL:** https://discuss.elastic.co/t/newbie-issue-with-multiple-dissects/169245
**Category:** Logstash
**Created:** [February 20, 2019, 3:33pm UTC](https://discuss.elastic.co/t/newbie-issue-with-multiple-dissects/169245 "2019-02-20T15:33:01Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![jerry.browne](https://avatars.discourse-cdn.com/v4/letter/j/a8b319/32.png) [@jerry.browne](https://discuss.elastic.co/u/jerry.browne)
#### Post date: [February 20, 2019, 3:33pm UTC](https://discuss.elastic.co/t/newbie-issue-with-multiple-dissects/169245/1 "2019-02-20T15:33:01Z")

</div>

I am brand new to logstash so apologies in advance for what I'm sure will turn out to be "dumb" questions.

I have a very simple log file with some | separated data in it. Like this:  
1550613490|MANAGER|1|Local/901@internalcalls|ADDMEMBER|

I am using dissect in the filters to split up and store this data and this is working well so far. Note: using if's since there are many different event types to parse that need to result in different field mapping per event.

```
if "ADDMEMBER" in [message] {
    dissect {
        mapping => {
            "message" => "%{dtstamp}|%{callid}|%{qname}|%{bridgechan}|%{event}|"
        }
    }
}
date{
    match => ["dtstamp", "UNIX"]
    target => "dtstamp_datetime"
} 

```

So far so good.

Now, bridgechan has the following in it:  
Local/901@internalcalls

At this point I now want to parse out 901 in this example and put it in a new field called UserID. It is this that I cannot work out yet.

First question is, can you use another dissect on the bridgechan variable from within the filter part of the logstash.conf file? In short, can I parse something that I've already parsed out into a new field? Or perhaps I cannot do this and need to parse something from the original input (message).

I wonder because I tried to do something like the following at the end of the filter section and have not had any success.

dissect {  
mapping =\> { %{bridgechan} =\> "%{firstpart}/%{secondpart"}  
}

Any help for "the new guy" would be greatly appreciated.

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [February 20, 2019, 4:19pm UTC](https://discuss.elastic.co/t/newbie-issue-with-multiple-dissects/169245/2 "2019-02-20T16:19:55Z")

</div>

> [@jerry.browne](#):
>
> dissect {  
> mapping =\> { %{bridgechan} =\> "%{firstpart}/%{secondpart"}  
> }

At that point bridgechan is a field on the event, so you should use

```
dissect { mapping => { "bridgechan" => "%{firstpart}/%{secondpart"} }

```

---

<div class="post-metadata">

### Author: ![jerry.browne](https://avatars.discourse-cdn.com/v4/letter/j/a8b319/32.png) [@jerry.browne](https://discuss.elastic.co/u/jerry.browne)
#### Post date: [February 20, 2019, 7:30pm UTC](https://discuss.elastic.co/t/newbie-issue-with-multiple-dissects/169245/3 "2019-02-20T19:30:59Z")

</div>

> [@Badger](#):
>
> dissect { mapping =\> { "bridgechan" =\> "%{firstpart}/%{secondpart"} }

Works perfectly of course. Thanks for helping out the new guy with basic syntax! 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 20, 2019, 7:30pm UTC](https://discuss.elastic.co/t/newbie-issue-with-multiple-dissects/169245/4 "2019-03-20T19:30:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
