# Remove extra lines from output message

**URL:** <https://discuss.elastic.co/t/remove-extra-lines-from-output-message/214538>\
**Category:** Logstash\
**Created:** [January 10, 2020, 6:01am UTC](https://discuss.elastic.co/t/remove-extra-lines-from-output-message/214538 "2020-01-10T06:01:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saravana37](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravana37/32/85237_2.png) [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Post date:** [January 10, 2020, 6:01am UTC](https://discuss.elastic.co/t/remove-extra-lines-from-output-message/214538/1 "2020-01-10T06:01:28Z")

</div>

Hi , I am using multiline pattern to filter my output message from Exec plugin , Now I am able to get the lines separately according to my required pattern ^D122, But i am getting some extra characters in the message like below.

Output :  
'\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*  
\<D1220001022A SvrTblCleanup Shutdown Manual 0 1 Server Tables Cleanup

223 rows returned.

srvrmgr\> list server show SBLSRVR\_NAME,SBLSRVR\_STATE

SBLSRVR\_NAME SBLSRVR\_STATE  
------------ ------------- /\>

* * *

My Logstash config file looks like this :

'# Sample Logstash configuration for creating a simple

# Beats -\> Logstash -\> Elasticsearch pipeline.

input {

beats {  
port =\> 5044  
tags =\> ["srvr\_logs"]  
}

exec {  
command =\> "E:\ELK\logstash\scripts\DEV\_Srvrmgr.bat"  
interval =\> 120  
#type =\> "string"  
tags =\> ["srvrmgr"]  
codec =\> multiline {  
pattern =\> "^D122"  
negate =\> true  
what =\> "previous"

```
    }

  }

```

}

filter {

mutate {  
remove\_field =\> ["host"]  
gsub =\> ["message", "\n", ""]  
}  
if "srvr\_logs" in [tags]

{  
grok {  
match =\> {"message" =\> "%{WORD:EventType}%{SPACE}%{WORD:EventSubType}%{SPACE}%{INT:Severity}%{SPACE}%{WORD:SARMID}%{NOTSPACE}%{SPACE}%{PROG:EventDate}%{SPACE}%{TIME:EventTime}%{SPACE}%{GREEDYDATA:LogMessage}"}  
}

}

else {  
grok {  
match =\> {  
"message" =\> [  
#Most specific grok:  
"%{WORD:ServerName}%{SPACE}%{WORD:Comp\_Alias}%{SPACE}%{WORD:CompStatus}%{SPACE}%{WORD:CompStartMode}%{SPACE}%{WORD:RunningTasks}%{SPACE}%{WORD:MaxTasks}%{SPACE}%{GREEDYDATA:CompName}",  
#Less specific:  
"%{WORD:SBLSRVR\_NAME}%{SPACE}%{WORD:SBLSRVR\_STATE}"  
]  
}  
}  
}  
}

output {

if "srvr\_logs" in [tags] {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "srvrlog-%{+YYYY.MM.dd}"  
}

}

else  
{  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "srvrmgr-%{+YYYY.MM.dd}"  
}  
}

}  
'

* * *

Here GREEDY DATA Gives me extra lines as well which is not at all required , Checked forums,stackoverflow and all . Not able to get proper solution .Please let me know how can we omit extra lines ? In other words , how can say logstash to process message till new line \n ?

---

<div class="post-metadata">

**Author:** ![Saravana37](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/saravana37/32/85237_2.png) [@Saravana37](https://discuss.elastic.co/u/Saravana37)\
**Post date:** [January 11, 2020, 4:45am UTC](https://discuss.elastic.co/t/remove-extra-lines-from-output-message/214538/2 "2020-01-11T04:45:46Z")

</div>

Hi ,

This got fixed with below ruby code.

```
     ruby {
        code => '
            event.set("message", event.get("message").split("\n"))
        '
			}
    split {
        field => "message"
			}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2020, 4:46am UTC](https://discuss.elastic.co/t/remove-extra-lines-from-output-message/214538/3 "2020-02-08T04:46:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
