# Processing large amoung of data with Logstash

**URL:** <https://discuss.elastic.co/t/processing-large-amoung-of-data-with-logstash/242020>\
**Category:** Logstash\
**Created:** [July 21, 2020, 11:56am UTC](https://discuss.elastic.co/t/processing-large-amoung-of-data-with-logstash/242020 "2020-07-21T11:56:59Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 21, 2020, 2:05pm UTC](https://discuss.elastic.co/t/processing-large-amoung-of-data-with-logstash/242020/5 "2020-07-21T14:05:14Z")

</div>

I agree with Jenni. Use dissect to parse the first part of the line then use ruby. You could use the .scan method of the String class

```
    ruby {
        code => '
            s = event.get("tests_string")
            if s
                event.set("matches", s.scan(/\s*([^;]+); ([^;]+); ([^;]+)(;|$)/))
            end
        '
    }

```

which will result in a variable length array such as

```
       "matches" => [
    [0] [
        [0] "Test1",
        [1] "Result1",
        [2] "Comment1",
        [3] ";"
    ],
    [1] [
        [0] "Test2",
        [1] "Result2",
        [2] "Comment2",
        [3] ""
    ]
],

```

You will likely want to iterate over the array and reformat the data.

---

_[View the full topic](https://discuss.elastic.co/t/processing-large-amoung-of-data-with-logstash/242020)._
