# Problem while using dissect plugin to parse logs

**URL:** <https://discuss.elastic.co/t/problem-while-using-dissect-plugin-to-parse-logs/137354>\
**Category:** Logstash\
**Created:** [June 26, 2018, 4:44am UTC](https://discuss.elastic.co/t/problem-while-using-dissect-plugin-to-parse-logs/137354 "2018-06-26T04:44:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [June 26, 2018, 4:44am UTC](https://discuss.elastic.co/t/problem-while-using-dissect-plugin-to-parse-logs/137354/1 "2018-06-26T04:44:46Z")

</div>

Hi

i have a requirement of parsing netstat logs using logstash, sample logs looks like bellow:

 ![samplelog](https://us1.discourse-cdn.com/elastic/original/3X/e/e/eea423d8027fba0604d6f34dec2399f8482a6307.png)  
the logstash configuration which i tried is here:

> input {  
> file  
> {  
> path =\> "/home/samplelog"  
> start\_position =\> "beginning"  
> }  
> }
> 
> filter {  
> dissect {  
> mapping =\> {  
> "message" =\> "TIME: %{time}  
> %{}"  
> }  
> }
> 
> if [message] =~ /^\s+(TCP|UDP)/ {  
> dissect {  
> mapping =\> {  
> "message" =\> "%{?tmp-\>} %{Protocol-\>} %{localAdd-\>} %{Foreign Address-\>} %{state}"  
> }  
> }  
> } else {  
> drop {}  
> }
> 
> }
> 
> output  
> {  
> if "\_grokparsefailure" not in [tags]  
> {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> index =\> "anyindex"  
> }  
> }
> 
> stdout { codec =\> rubydebug }  
> }

resulted outcome from above configuration is :

> {  
> "Protocol" =\> "TCP",  
> "localAdd" =\> "",  
> "time" =\> "",  
> "path" =\> "/home/avk03/JarAndZip/jar-file/config/logstash-6.1.1/Logs/try.txt",  
> "state" =\> " 0.0.0.0:445 0.0.0.0:0 LISTENING",  
> "@timestamp" =\> 2018-06-15T10:08:19.779Z,  
> "@version" =\> "1",  
> "message" =\> " TCP 0.0.0.0:445 0.0.0.0:0 LISTENING",  
> "host" =\> "avk03-Vostro-3800",  
> "Foreign Address" =\> ""  
> }

the parser is not reading lines Which contains **TIME** data, i am not able to resolve this issue please help.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 26, 2018, 5:50am UTC](https://discuss.elastic.co/t/problem-while-using-dissect-plugin-to-parse-logs/137354/2 "2018-06-26T05:50:07Z")

</div>

The pattern for the `TIME` field has a newline in it. If you are not using multiline codec and split as described [in this thread](https://discuss.elastic.co/t/problem-with-parsing-multiline-filter-plugin/135906) it will not work as all lines will be processed separately and therefore not contain any newline.

---

<div class="post-metadata">

**Author:** ![RamyaGowda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramyagowda/32/27440_2.png) [@RamyaGowda](https://discuss.elastic.co/u/RamyaGowda)\
**Post date:** [June 26, 2018, 9:53am UTC](https://discuss.elastic.co/t/problem-while-using-dissect-plugin-to-parse-logs/137354/3 "2018-06-26T09:53:37Z")

</div>

Yes i got where i did mistake now after using multiline codec and split filter, parser is working fine.🙂

> @timestamp": "2018-06-26T07:50:10.161Z",  
> "Foreign Address": "0.0.0.0:0",  
> "message": " TCP 0.0.0.0:10 0.0.0.0:0 Ramya",  
> "localAdd": "0.0.0.0:10",  
> "tags": [  
> "multiline"  
> ],  
> "Protocol": "TCP",  
> "@version": "1",  
> "host": "avk03-Vostro-3800",  
> "path": "/home/avk03/JarAndZip/jar-file/config/logstash-6.1.1/Logs/abc",  
> "state": "ESTABLISHED",  
> "time": "16:14:30.13"

Now i have to convert above **time** to date object using **date** filter, is it possible only for time in logstash ?? Please reply

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2018, 9:53am UTC](https://discuss.elastic.co/t/problem-while-using-dissect-plugin-to-parse-logs/137354/4 "2018-07-24T09:53:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
