# Removing a part of every line on a multiple codec

**URL:** <https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874>\
**Category:** Logstash\
**Created:** [March 9, 2016, 8:01am UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874 "2016-03-09T08:01:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jervdv](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@jervdv](https://discuss.elastic.co/u/jervdv)\
**Post date:** [March 9, 2016, 8:01am UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874/1 "2016-03-09T08:01:46Z")

</div>

Hi

I'm combining a stack trace with a mutiline codec everything is going great my multiline codec combines evertyhing to one logstash event. But as you can see in the logstash event below i need to delete a part of the log every line is this possible with grok? ("INFO | jvm 1 | main | 2016/03/01 04:03:03.503 |" This is the part that needs to be removed.)

INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | 04:03:03,407 [SitemapGeneratorCronjob::com.test.foo.types.job.SitemapGeneratorJob] ERROR [SitemapGenerator] Error while exporting the the facet '/ -\> Trio (brand) -\> Series 3401 (collection)'.  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | de.hybris.platform.servicelayer.exceptions.UnknownIdentifierException: No ProductCollectionInfo found with collectionValue [Series 3401] and brandValue [Trio]  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.foo.dao.impl.DefaultCollectionDao.getCollectionBySolrValue(DefaultCollectionDao.java:77)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.foo.services.impl.DefaultfooCollectionService.getCollectionBySolrValue(DefaultfooCollectionService.java:46)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.solr.services.impl.DefaultFilterPageUrlService.generateUrl(DefaultFilterPageUrlService.java:242)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.solr.services.impl.DefaultFilterPageUrlService.fabricateUrl(DefaultFilterPageUrlService.java:122)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.services.SitemapUrlService$7.apply(SitemapUrlService.java:117)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.services.SitemapUrlService$7.apply(SitemapUrlService.java:1)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.converters.LanguageTranslator.getAllTranslations(LanguageTranslator.java:41)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.converters.LanguageTranslator.getAllTranslations(LanguageTranslator.java:27)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.services.SitemapUrlService.generateFacetUrls(SitemapUrlService.java:114)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.services.SitemapElementService.generateFacetElement(SitemapElementService.java:45)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.SitemapGenerator.exportFacets(SitemapGenerator.java:106)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.SitemapGenerator.generateSitemaps(SitemapGenerator.java:73)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.foo.types.job.SitemapGeneratorJob.performCronJob(SitemapGeneratorJob.java:44)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at de.hybris.platform.cronjob.jalo.Job.execute(Job.java:1262)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at de.hybris.platform.cronjob.jalo.Job.performImpl(Job.java:793)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at de.hybris.platform.cronjob.jalo.Job.access$1(Job.java:752)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at de.hybris.platform.cronjob.jalo.Job$JobRunable.run(Job.java:657)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at de.hybris.platform.util.threadpool.PoolableThread.run(PoolableThread.java:131)

---

<div class="post-metadata">

**Author:** ![michalterbert](https://avatars.discourse-cdn.com/v4/letter/m/848f3c/32.png) [@michalterbert](https://discuss.elastic.co/u/michalterbert)\
**Post date:** [March 9, 2016, 8:06am UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874/2 "2016-03-09T08:06:58Z")

</div>

You can use grok parsing and mutate for remove fileds.  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html)

---

<div class="post-metadata">

**Author:** ![jervdv](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@jervdv](https://discuss.elastic.co/u/jervdv)\
**Post date:** [March 9, 2016, 8:11am UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874/3 "2016-03-09T08:11:40Z")

</div>

I'm using a multiline codec who puts everything of my stacktrace in to one field.  
So it is impossible to remove fields i think.

Is it possible to make an array of your fields with your multiline codec?  
Like for example, is it posibble to make an array of log\_level where then would be INFO for every line of my stacktrace?

---

<div class="post-metadata">

**Author:** ![michalterbert](https://avatars.discourse-cdn.com/v4/letter/m/848f3c/32.png) [@michalterbert](https://discuss.elastic.co/u/michalterbert)\
**Post date:** [March 9, 2016, 8:20am UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874/4 "2016-03-09T08:20:41Z")

</div>

So if you have all stacktrace in to one filed you can use GROK and parsed this filed to other fields - its simple.  
You can test your groks patterns here:  
[https://grokdebug.herokuapp.com](https://grokdebug.herokuapp.com)

Your next step will be droping all events with other value for log\_level than INFO.

---

<div class="post-metadata">

**Author:** ![jervdv](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@jervdv](https://discuss.elastic.co/u/jervdv)\
**Post date:** [March 9, 2016, 8:34am UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874/5 "2016-03-09T08:34:56Z")

</div>

But i also have fields without a stacktrace.

My grok works to get all the fields out of the log file.

But now i need to delete a part of that line if i have a stacktrace.

You suggest to do a new grok on the field of my stacktrace?  
But there are also normal error messages in that don't have a stacktrace.

I don't see how that is possible?

Here is an example of a log event without a stacktrace.

INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | 04:03:03,407 [SitemapGeneratorCronjob::com.test.foo.types.job.SitemapGeneratorJob] ERROR [SitemapGenerator] Error while exporting the the facet '/ -\> Trio (brand) -\> Series 3401 (collection)'.

**When i have a stacktrace i have this in my stacktrace field:** [SitemapGeneratorCronjob::com.test.foo.types.job.SitemapGeneratorJob] ERROR [SitemapGenerator] Error while exporting the the facet '/ -\> Trio (brand) -\> Series 3401 (collection)'.  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | de.hybris.platform.servicelayer.exceptions.UnknownIdentifierException: No ProductCollectionInfo found with collectionValue [Series 3401] and brandValue [Trio]  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.foo.dao.impl.DefaultCollectionDao.getCollectionBySolrValue(DefaultCollectionDao.java:77)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.foo.services.impl.DefaultfooCollectionService.getCollectionBySolrValue(DefaultfooCollectionService.java:46)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.solr.services.impl.DefaultFilterPageUrlService.generateUrl(DefaultFilterPageUrlService.java:242)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.solr.services.impl.DefaultFilterPageUrlService.fabricateUrl(DefaultFilterPageUrlService.java:122)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.services.SitemapUrlService$7.apply(SitemapUrlService.java:117)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.services.SitemapUrlService$7.apply(SitemapUrlService.java:1)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.converters.LanguageTranslator.getAllTranslations(LanguageTranslator.java:41)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.converters.LanguageTranslator.getAllTranslations(LanguageTranslator.java:27)  
INFO | jvm 1 | main | 2016/03/01 04:03:03.503 | at com.test.sitemap.services.SitemapUrlService.generateFacetUrls(SitemapUrlService.java:114)

**While i actually want this:**  
[SitemapGeneratorCronjob::com.test.foo.types.job.SitemapGeneratorJob] ERROR [SitemapGenerator] Error while exporting the the facet '/ -\> Trio (brand) -\> Series 3401 (collection)'.  
de.hybris.platform.servicelayer.exceptions.UnknownIdentifierException: No ProductCollectionInfo found with collectionValue [Series 3401] and brandValue [Trio]  
at com.test.foo.dao.impl.DefaultCollectionDao.getCollectionBySolrValue(DefaultCollectionDao.java:77)  
at com.test.foo.services.impl.DefaultfooCollectionService.getCollectionBySolrValue(DefaultfooCollectionService.java:46)  
at com.test.solr.services.impl.DefaultFilterPageUrlService.generateUrl(DefaultFilterPageUrlService.java:242)  
at com.test.solr.services.impl.DefaultFilterPageUrlService.fabricateUrl(DefaultFilterPageUrlService.java:122)  
at com.test.sitemap.services.SitemapUrlService$7.apply(SitemapUrlService.java:117)  
at com.test.sitemap.services.SitemapUrlService$7.apply(SitemapUrlService.java:1)  
at com.test.sitemap.converters.LanguageTranslator.getAllTranslations(LanguageTranslator.java:41)  
at com.test.sitemap.converters.LanguageTranslator.getAllTranslations(LanguageTranslator.java:27)  
at com.test.sitemap.services.SitemapUrlService.generateFacetUrls(SitemapUrlService.java:114)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2016, 8:45pm UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874/6 "2016-03-09T20:45:59Z")

</div>

I'd look into the mutate filter's gsub option.

---

<div class="post-metadata">

**Author:** ![jervdv](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@jervdv](https://discuss.elastic.co/u/jervdv)\
**Post date:** [March 15, 2016, 9:52am UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874/7 "2016-03-15T09:52:19Z")

</div>

Indeed with gsub i was able to fix it. Thanks for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:06am UTC](https://discuss.elastic.co/t/removing-a-part-of-every-line-on-a-multiple-codec/43874/8 "2017-07-06T05:06:57Z")

</div>


