# Parsing tabular data into canvas

**URL:** <https://discuss.elastic.co/t/parsing-tabular-data-into-canvas/286496>\
**Category:** Logstash\
**Created:** [October 12, 2021, 1:04pm UTC](https://discuss.elastic.co/t/parsing-tabular-data-into-canvas/286496 "2021-10-12T13:04:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kadhem](https://avatars.discourse-cdn.com/v4/letter/k/49beb7/32.png) [@Kadhem](https://discuss.elastic.co/u/Kadhem)\
**Post date:** [October 12, 2021, 1:04pm UTC](https://discuss.elastic.co/t/parsing-tabular-data-into-canvas/286496/1 "2021-10-12T13:04:28Z")

</div>

hi, how can i parse this output of command to push into into a table in Canvas :

```auto
prec: rqstd, stored, dropped, retried, rtsfail,rtrydrop, psretry, acked,utlisatn,q length,Data Mbits/s,Phy Mbits/s, %air, %effcy (v5)
  00: 0, 0, 0, 0, 0, 0, 0, 0, 0, 236, 0.00, 0.00, 0.0, 0.0
  01: 0, 0, 0, -, -, 0, 0, 0, 0, 236, 0.00, -, -, -
  02: 0, 0, 0, 0, 0, 0, 0, 0, 0, 236, 0.00, 0.00, 0.0, 0.0
  03: 0, 0, 0, -, -, 0, 0, 0, 0, 236, 0.00, -, -, -
  04: 8, 8, 0, 0, 0, 0, 0, 0, 0, 236, 0.00, 0.00, 0.0, 0.0
  05: 0, 0, 0, -, -, 0, 0, 0, 0, 236, 0.00, -, -, -
  06: 0, 0, 0, 0, 0, 0, 0, 0, 0, 236, 0.00, 0.00, 0.0, 0.0
  07: 0, 0, 0, -, -, 0, 0, 0, 0, 236, 0.00, -, -, -
  08: 0, 0, 0, 0, 0, 0, 0, 0, 0, 236, 0.00, 0.00, 0.0, 0.0
  09: 0, 0, 0, -, -, 0, 0, 0, 0, 236, 0.00, -, -, -
  10: 0, 0, 0, 0, 0, 0, 0, 0, 0, 236, 0.00, 0.00, 0.0, 0.0
  11: 0, 0, 0, -, -, 0, 0, 0, 0, 236, 0.00, -, -, -
  12: 0, 0, 0, 0, 0, 0, 0, 0, 0, 236, 0.00, 0.00, 0.0, 0.0
  13: 0, 0, 0, -, -, 0, 0, 0, 0, 236, 0.00, -, -, -
  14: 0, 0, 0, 455, 0, 1, 0, 596, 0, 236, 0.01, 0.00, 0.5, 0.0
  15: 597, 597, 0, -, -, 0, 0, 0, 0, 236, 0.00, -, -, -

```

any help please i need a grok pattern

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 12, 2021, 10:54pm UTC](https://discuss.elastic.co/t/parsing-tabular-data-into-canvas/286496/2 "2021-10-12T22:54:34Z")

</div>

My initial thought was that there had to be a better filter to use, maybe dissect or csv, but then you would have to trim all the resulting fields. So go with grok...

```
 if [message] =~ /^prec:/ { drop {} }
 grok { match => { "message" => "\s*%{NUMBER:prec}:\s*(?<rqstd>([0-9]+|-)),\s*(?<stored>([0-9]+|-)),\s*(?<dropped>([0-9]+|-)),\s*(?<retried>([0-9]+|-)),\s*(?<rtsfail>([0-9]+|-)),\s*(?<rtrydrop>([0-9]+|-)),\s*(?<psretry>([0-9]+|-)),\s*(?<acked>([0-9]+|-)),\s*(?<utlisatn>([0-9]+|-)),\s*(?<qLength>([0-9]+|-)),\s*(?<dataRate>([.0-9]+|-)),\s*(?<physRate>([.0-9]+|-)),\s*(?<percentAir>([.0-9]+|-)),\s*(?<percentEffcy>([.0-9]+|-))" } }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2021, 7:56am UTC](https://discuss.elastic.co/t/parsing-tabular-data-into-canvas/286496/4 "2021-11-10T07:56:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
