# Parsing input in to logstash

**URL:** <https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539>\
**Category:** Logstash\
**Created:** [February 7, 2019, 9:44pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539 "2019-02-07T21:44:40Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 7, 2019, 9:44pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/1 "2019-02-07T21:44:40Z")

</div>

I configure snmp to get information from PDU  
Run only two get to test, and output is long.

{  
"iso.org.dod.internet.private.enterprises.apc.products.hardware.rPDU2.rPDU2Device.rPDU2DeviceConfigTable.rPDU2DeviceConfigEntry.rPDU2DeviceConfigLocation.1" =\> "Racl 240 TOP",

"@timestamp" =\> 2019-02-07T21:21:47.493Z,  
"iso.org.dod.internet.private.enterprises.apc.products.hardware.rPDU2.rPDU2Device.rPDU2DeviceConfigTable.rPDU2DeviceConfigEntry.rPDU2DeviceConfigName.1" =\> "DataCenter1-P1-R240T",  
"@version" =\> "1",  
}

Ho do I parse this to remove all leading entry like "iso.org.dod.internet.private......." all the way to second last word? like rPDU2DeviceConfigName ?

Something needs to be done in filter section can't figure out which filter to use. as string will be different for each OID that I will get.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 7, 2019, 10:06pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/2 "2019-02-07T22:06:01Z")

</div>

This filter

```
    ruby {
        code => '
            event.to_hash.each { |k, v|
                if k.start_with? "iso.org."
                    newk = k.sub(/.*\.([^\.]+\.[^\.]+)$/, "\\1")
                    event.set(newk, v)
                    event.remove(k)
                end
            }
        '
    }

```

will reduce those down to

```
    "rPDU2DeviceConfigName.1" => "DataCenter1-P1-R240T",
"rPDU2DeviceConfigLocation.1" => "Racl 240 TOP",
```

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 7, 2019, 10:16pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/3 "2019-02-07T22:16:30Z")

</div>

Badger, Man you rock. when will I buy you lunch. 🙂 😀

Great.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 7, 2019, 11:28pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/4 "2019-02-07T23:28:10Z")

</div>

while we are on this ruby topic  
how do I do math on field?  
rPDULoadStatusLoad = new value

ruby {  
code =\> "event.set('rPDULoadStatusLoad', event.get('rPDULoadStatusLoad.1')/10"  
}  
but seems like I am doing something wrong.

I try many different combination with this set and get all gives me error.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 7, 2019, 11:32pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/5 "2019-02-07T23:32:53Z")

</div>

If rPDULoadStatusLoad.1 is a string (it shows up with quotes in a rubydebug output) then you will need to .to\_f it.

```
event.set('rPDULoadStatusLoad', event.get('rPDULoadStatusLoad.1').to_f/10
```

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 7, 2019, 11:33pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/6 "2019-02-07T23:33:10Z")

</div>

well this one just worked. LOL  
ruby {  
code =\> "event.set('rPDULoadStatusLoad',(event.get('rPDULoadStatusLoad.1')/10))"  
}

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 8, 2019, 10:11pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/7 "2019-02-08T22:11:22Z")

</div>

I didn't understand or to understand that.  
now I have new problem on same parsing.  
I have some value that ends with .2 and/or .3 and/or .4

k.sub(/.\*.([^.]+.[^.]+)$/, "\1") ---\> how is this doing parsing?  
how do I tackle that?

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 8, 2019, 10:22pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/8 "2019-02-08T22:22:28Z")

</div>

actually it works for any number. I didn't test it thought it will not work.  
but will be good to know how?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 8, 2019, 11:04pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/9 "2019-02-08T23:04:29Z")

</div>

> [@elasticforme](#):
>
> ```
> k.sub(/.*\.([^\.]+\.[^\.]+)$/, "\\1")
> 
> ```

That says anything (.\*) followed by a dot, followed by one or more characters that are not dots, followed by a dot, followed by one or more characters that are not dots, followed by the end of the string. So it matches foo.1, foo.2, or even foo.bar

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [February 11, 2019, 2:27pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/10 "2019-02-11T14:27:39Z")

</div>

> [@Badger](#):
>
> .

so  
([^.]+.[^.]+)$ = one or more character that are not dot, dot, one or more char not dot till end of strings

Thanks. got it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2019, 2:27pm UTC](https://discuss.elastic.co/t/parsing-input-in-to-logstash/167539/11 "2019-03-11T14:27:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
