# Parsing with logstash

**URL:** <https://discuss.elastic.co/t/parsing-with-logstash/85377>\
**Category:** Logstash\
**Created:** [May 11, 2017, 11:31am UTC](https://discuss.elastic.co/t/parsing-with-logstash/85377 "2017-05-11T11:31:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [May 11, 2017, 11:31am UTC](https://discuss.elastic.co/t/parsing-with-logstash/85377/1 "2017-05-11T11:31:24Z")

</div>

Hello EveryOne ,

I need your help to extract information from a document contained in a log.  
The document is as follows :

> 2017-05-10T14:28:42.387 Int 22000 ##### EI\_COFBE\_SICRC04\_GestionHO\_SSTR-v8 - 01df028ded513257  
> \_I\_I\_01df028ded513257 [09:04] ASSIGN: zFlow(LOCAL) \<- STRING: **"379000:376000:COFBE\_070\_FR\_CIBLE:HO:COFBE\_DEVELOPPEMENT\_FR:19:TO:COFBE\_OUTSOURCER\_FR:8:TO:COFBE\_SEDUCTION\_FR:6:5307:OK:"**  
> \_I\_I\_01df028ded513257 [09:04] ASSIGN: iTimeStamp(LOCAL) \<- INTEGER: 413961

I want to extrat only what is highlighted.  
I try this filter :

> match =\> {"message" =\> "zFlow(LOCAL) \<- STRING: %{GREEDYDATA:Flow}[\n]"}

He sends me back what I want but also the rest of the document.  
How could I remove the rest of the document ?

Thanks for your help !

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 11, 2017, 11:58am UTC](https://discuss.elastic.co/t/parsing-with-logstash/85377/2 "2017-05-11T11:58:33Z")

</div>

You can e.g. use

```
zFlow\(LOCAL\) <- STRING: "(?<Flow>[^"]*)"

```

to extract everything inbetween the double quotes. Note that you'll have to make the grok expression string a single-quoted string (it's currently double-quoted). Another option is to use the QS grok pattern but it keeps the surrounding double quotes in the extracted string.

---

<div class="post-metadata">

**Author:** ![Sam67000](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@Sam67000](https://discuss.elastic.co/u/Sam67000)\
**Post date:** [May 11, 2017, 12:40pm UTC](https://discuss.elastic.co/t/parsing-with-logstash/85377/3 "2017-05-11T12:40:27Z")

</div>

Thank you for your help.

I changed my filter by the one you provided :  
`match => {"message" => "zFlow\(LOCAL\) <- STRING: "(?<Flow>[^"]*)"}`

But it does not work. The logstash configuration file no longer launches.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 11, 2017, 12:55pm UTC](https://discuss.elastic.co/t/parsing-with-logstash/85377/4 "2017-05-11T12:55:15Z")

</div>

As I said: Note that you'll have to make the grok expression string a single-quoted string (it's currently double-quoted). That means this:

```
match => {"message" => 'zFlow\(LOCAL\) <- STRING: "(?<Flow>[^"]*)'}

```

> But it does not work. The logstash configuration file no longer launches.

In this particular case I was able to spot the error anyway, but please try to anticipate the questions are you going to get. If Logstash doesn't start we're going to want to see the logs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2017, 1:07pm UTC](https://discuss.elastic.co/t/parsing-with-logstash/85377/5 "2017-06-08T13:07:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
