# Not able to create separate fields all log data in message field

**URL:** <https://discuss.elastic.co/t/not-able-to-create-separate-fields-all-log-data-in-message-field/188296>\
**Category:** Logstash\
**Created:** [July 1, 2019, 11:06am UTC](https://discuss.elastic.co/t/not-able-to-create-separate-fields-all-log-data-in-message-field/188296 "2019-07-01T11:06:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raghu.rajanna](https://avatars.discourse-cdn.com/v4/letter/r/ea666f/32.png) [@Raghu.rajanna](https://discuss.elastic.co/u/Raghu.rajanna)\
**Post date:** [July 1, 2019, 11:06am UTC](https://discuss.elastic.co/t/not-able-to-create-separate-fields-all-log-data-in-message-field/188296/1 "2019-07-01T11:06:58Z")

</div>

I am new to Grock filter tried with grok debugger working fine in it  
but not able to create new fields all log data are in the message field  
this is my configuration file.  
#Windows Firewall  
input {  
beats {  
port =\> 5044  
}  
}

filter {  
if [fileset][module] == "iis" {  
grok {  
break\_on\_match =\> false

# match log structure using grok

match =\> { "message" =\> "%{GREEDYDATA:Date} %{GREEDYDATA:Time} %{WORD:action} %{WORD:protocol} %{IP:source\_ip} %{IP:destination\_ip} %{INT:SrcPort} %{INT:DstPort} %{INT:Size} %{GREEDYDATA:Size}" }  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"

```
   }

   stdout { codec => rubydebug }
   }
```

---

<div class="post-metadata">

**Author:** ![Raghu.rajanna](https://avatars.discourse-cdn.com/v4/letter/r/ea666f/32.png) [@Raghu.rajanna](https://discuss.elastic.co/u/Raghu.rajanna)\
**Post date:** [July 1, 2019, 11:11am UTC](https://discuss.elastic.co/t/not-able-to-create-separate-fields-all-log-data-in-message-field/188296/2 "2019-07-01T11:11:12Z")

</div>

this is my log  
2019-06-29 12:49:40 ALLOW UDP 192.168.1.1 x.x.x.x 59445 53 0 - - - - - - - SEND

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 1, 2019, 1:26pm UTC](https://discuss.elastic.co/t/not-able-to-create-separate-fields-all-log-data-in-message-field/188296/3 "2019-07-01T13:26:55Z")

</div>

x.x.x.x is not a valid IP address, so it does not match. If you replace that with, for example, 192.168.2.2 then, provided that your event contains a [fileset][module] field with the right value, it matches and you will get

```
          "Date" => "2019-06-29",
"destination_ip" => "192.168.2.2",
     "source_ip" => "192.168.1.1",
          "Time" => "12:49:40",
          "Size" => [
    [0] "0",
    [1] "- - - - - - - SEND"
],
       "message" => "2019-06-29 12:49:40 ALLOW UDP 192.168.1.1 192.168.2.2 59445 53 0 - - - - - - - SEND",
       "DstPort" => "53",
        "action" => "ALLOW",
       "SrcPort" => "59445",
      "protocol" => "UDP"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2019, 1:26pm UTC](https://discuss.elastic.co/t/not-able-to-create-separate-fields-all-log-data-in-message-field/188296/4 "2019-07-29T13:26:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
