# Remove part of message string in logstash config

**URL:** <https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913>\
**Category:** Logstash\
**Created:** [August 12, 2019, 7:53pm UTC](https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913 "2019-08-12T19:53:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohitg](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@rohitg](https://discuss.elastic.co/u/rohitg)\
**Post date:** [August 12, 2019, 7:53pm UTC](https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913/1 "2019-08-12T19:53:12Z")

</div>

Hi,

I have a string like - [123RGT78.XY.ABD.COM](http://123RGT78.XY.ABD.COM)  
I need only 123RGT78 from this string and want to remove everything coming after the first dot (.)  
How to achieve this.

filter {  
mutate {  
gsub =\> ["message", "]  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 8:57pm UTC](https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913/2 "2019-08-12T20:57:59Z")

</div>

```
mutate { gsub => ["someField", "\..*", ""] }
```

---

<div class="post-metadata">

**Author:** ![rohitg](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@rohitg](https://discuss.elastic.co/u/rohitg)\
**Post date:** [August 13, 2019, 10:04pm UTC](https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913/3 "2019-08-13T22:04:02Z")

</div>

Hi Badger,

I tried this but it is only removing (dot) and giving result 123RGT78XYABDCOM.  
My need is to remove everything after (dot).

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 13, 2019, 10:24pm UTC](https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913/4 "2019-08-13T22:24:38Z")

</div>

The mutate I posted will remove the first dot in the string and everything after it.

---

<div class="post-metadata">

**Author:** ![rohitg](https://avatars.discourse-cdn.com/v4/letter/r/b77776/32.png) [@rohitg](https://discuss.elastic.co/u/rohitg)\
**Post date:** [August 13, 2019, 10:44pm UTC](https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913/5 "2019-08-13T22:44:37Z")

</div>

Not sure why it didn't work before. But now its working. Thanks Badger.

One more ask. How to remove everything after (-)  
ex: 01234 - ABS HO SDRGE WETX

There is space before and after (-)

I tried this but it removing only (-)  
mutate { gsub =\> ["someField", "-\*", ""] }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 13, 2019, 11:19pm UTC](https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913/6 "2019-08-13T23:19:36Z")

</div>

In a mutate like

```
mutate { gsub => ["someField", "\..*", ""] }

```

the second string "..\*" is a [regexp](https://ruby-doc.org/core-2.5.3/Regexp.html). That particular one says a literal dot, followed by zero or more characters (dot matches any character, which is why the literal dot has to be escaped).

If you want to remove the space, dash, space, and everything after it then use

```
mutate { gsub => ["message", " - .*", ""] }

```

If you want to remove just the dash and everything after it (but not the space before it) then remove the leading space in the regexp. The pattern you tried, "-\*", means zero or more occurrences of dash.

You appear to think that \* matches a string of characters, like it does in a UNIX filename wildcard. That is not true in most regexps. Instead it modifies whatever comes before it, to say "zero or more of".

Ruby regexps are similar-ish to perl regexps, which are similar, but more functional than ed regexps, which are not similar to /bin/sh regexps, which are very different to /bin/csh regexps. There are many other regexp dialects.

In logstash itself you are always dealing with Ruby regexps (although you could be using plugins that interact with external systems that use other types of regexps). It is possible, if you are using a jdbc input, and an http filter for enrichment, you might use three different types of regular expression in a single configuration, but that really would be unusual. For help with any particular dialect just Google "ruby regular expression" or "oracle sql regular expression" or "perl regular expression" and you will find sites that can guide you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2019, 11:19pm UTC](https://discuss.elastic.co/t/remove-part-of-message-string-in-logstash-config/194913/7 "2019-09-10T23:19:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
