# Parsing MongoDB with Logstash

**URL:** <https://discuss.elastic.co/t/parsing-mongodb-with-logstash/251780>\
**Category:** Logstash\
**Created:** [October 12, 2020, 2:17pm UTC](https://discuss.elastic.co/t/parsing-mongodb-with-logstash/251780 "2020-10-12T14:17:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hawasli](https://avatars.discourse-cdn.com/v4/letter/h/dfb087/32.png) [@Hawasli](https://discuss.elastic.co/u/Hawasli)\
**Post date:** [October 12, 2020, 2:17pm UTC](https://discuss.elastic.co/t/parsing-mongodb-with-logstash/251780/1 "2020-10-12T14:17:25Z")

</div>

Hi,

I am running Logstash 6.8 and trying to parse MongoDB logs which is well- specified [here](https://docs.mongodb.com/manual/reference/log-messages/).

Is there a more elegant/efficient way to parse MongoDB logs? Here is my filter

```auto
    filter {
        if [fields][application] == 'mongodb' {
            json {
                source => "message"
                target => "json_msg"
            }
            if "_jsonparsefailure" not in [tags] {
                grok { match => { "[json_msg][log]" => "^([^,]*),(?<s>[^,]*),(?<c>[^,]*),(?<i>[^,]*),(?<ctx>[^,]*),(?<m>[^,]*),(?<attr>[^,]*),(?<ci>[^,]*),%{GREEDYDATA:cc}"} }
                grok { match => { "s" => "^[^:]*[^\"]*\"(?<level>[^\"]*)" } }
                grok { match => { "c" => "^[^:]*[^\"]*\"(?<component>[^\"]*)" } }
                grok { match => { "ctx" => "^[^:]*[^\"]*\"(?<context>[^\"]*)" } }
                grok { match => { "i" => "^[^:]*:(?<id>[\d]*)" } }
                grok { match => { "m" => "^[^:]*[^\"]*\"(?<msg>[^\"]*)" } }
                grok { match => { "attr" => "^[^:]*[^\"]*\"(?<attribute>[^\"]*)" } }
                grok { match => { "ci" => "^[^:]*:(?<connection_id>[\d]*)" } }
                grok { match => { "cc" => "^[^:]*:(?<connection_count>[\d]*)" } }
                mutate {
                    replace => { "[@metadata][timestamp]" => "%{[json_msg][time]}"}
                    add_field => {"stream" => "%{[json_msg][stream]}"}
                    remove_field => ["s", "c", "ctx", "i", "m", "attr", "ci", "cc"]
                }
            }
        }
    }

```

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2020, 2:17pm UTC](https://discuss.elastic.co/t/parsing-mongodb-with-logstash/251780/2 "2020-11-09T14:17:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
