# Parse one line as two lines

**URL:** <https://discuss.elastic.co/t/parse-one-line-as-two-lines/289073>\
**Category:** Logstash\
**Created:** [November 12, 2021, 2:16pm UTC](https://discuss.elastic.co/t/parse-one-line-as-two-lines/289073 "2021-11-12T14:16:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sjap1](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Sjap1](https://discuss.elastic.co/u/Sjap1)\
**Post date:** [November 12, 2021, 2:16pm UTC](https://discuss.elastic.co/t/parse-one-line-as-two-lines/289073/1 "2021-11-12T14:16:45Z")

</div>

Hello,

I'm trying to parse multiple items in one line. My grok pattens match but logstash are outputting the data as arrays; How can i make the output look the where are two lines?

input data:

```auto
2021-11-01 14:09:34 CET Address: 2a03:1234:1234:4::142 has been assigned for 7257600 seconds to a device with DUID: 00:03:00:01:00:1e:80:ec:8a:f4 connected via relay at address: fe80::21e:80ff:feec:8af4 for client on link address: 2a03:1234:1234:4::1, connected at location interface-id: 61:65:33:32:30:3a:32:36:36:39:2d:34Prefix: 2a03:1234:1234:1900::/56 has been assigned for 7257600 seconds to a device with DUID: 00:03:00:01:00:1e:80:ec:8a:f4 connected via relay at address: fe80::21e:80ff:feec:8af4 for client on link address: 2a03:1234:1234:4::1, connected at location interface-id: 61:65:33:32:30:3a:32:36:36:39:2d:34

```

I've created two grok patterns to match the input:

```auto
%{TIMESTAMP_ISO8601:time} .* Address: .* has been .* for .* seconds to a device with DUID: .* connected via relay at address: .* for client on link address: .* connected at location interface-id: .*Prefix: %{GREEDYDATA:client_ip} has been %{WORD:action} for %{INT:leasetime} seconds to a device with DUID: .* connected via relay at address: .* for client on link address: .* connected at location interface-id: (?<interfaceid>[0-9a-f]{2}(:[0-9a-f]{2})*)
%{TIMESTAMP_ISO8601:time} .* Address: %{GREEDYDATA:client_ip} has been %{WORD:action} for %{INT:leasetime} seconds to a device with DUID: .* connected via relay at address: .* for client on link address: .* connected at location interface-id: (?<interfaceid>[0-9a-f]{2}(:[0-9a-f]{2})*)

```

My issue is the output is an array:

```auto
{
      "client_ip" => [
        [0] "2a03:1234:1234:4::142 has been assigned for 7257600 seconds to a device with DUID: 00:03:00:01:00:1e:80:ec:8a:f4 connected via relay at address: fe80::21e:80ff:feec:8af4 for client on link address: 2a03:1234:1234:4::1, connected at location interface-id: 61:65:33:32:30:3a:32:36:36:39:2d:34Prefix: 2a03:1234:1234:1900::/56",
        [1] "2a03:1234:1234:1900::/56"
    ],

```

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [November 17, 2021, 1:10pm UTC](https://discuss.elastic.co/t/parse-one-line-as-two-lines/289073/2 "2021-11-17T13:10:04Z")

</div>

I'm not sure why it is splitting it into an array.. there may be an invisible newline character. However, you can cheat a little bit and ensure that `client_ip` is flattened out by using the `mutate join` filter.

```auto
   filter {
     mutate {
       join => { "client_ip" => " " }
     }
   }

```

> **[Mutate filter plugin | Logstash Reference \[7.15\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-join)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2021, 1:11pm UTC](https://discuss.elastic.co/t/parse-one-line-as-two-lines/289073/3 "2021-12-15T13:11:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
