# Removing specific text from a log mesg

**URL:** <https://discuss.elastic.co/t/removing-specific-text-from-a-log-mesg/89023>\
**Category:** Logstash\
**Created:** [June 12, 2017, 11:13am UTC](https://discuss.elastic.co/t/removing-specific-text-from-a-log-mesg/89023 "2017-06-12T11:13:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raghu19](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@Raghu19](https://discuss.elastic.co/u/Raghu19)\
**Post date:** [June 12, 2017, 11:13am UTC](https://discuss.elastic.co/t/removing-specific-text-from-a-log-mesg/89023/1 "2017-06-12T11:13:11Z")

</div>

Is there a way to parse the log message and search for a particular string and if that is present, then to ignore/remove that string from that message?

Every log message in the log file that i am trying to parse using logstash is followed by a line (in a new line) in the below format  
**xxxxx (some string) : TraceLog message some\_number**

such messages need be ignored.  
I am using the multiline codec to identify the log messages as the ones that start with |. If any message does not start with | it should get appended to previous message.  
And hence the messages in the above format are getting appended to previous messages.  
Is there a way that they can be removed?  
. need to search the log text for the format  
. if present, log text = log text minus that string.

Kindly suggest. Thank you

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2017, 8:04pm UTC](https://discuss.elastic.co/t/removing-specific-text-from-a-log-mesg/89023/2 "2017-06-12T20:04:28Z")

</div>

To remove parts of a string, use a mutate filter and its gsub option. To completely ignore whole events, use a drop filter that you run conditionally via an `if ... { ... }` block.

---

<div class="post-metadata">

**Author:** ![Raghu19](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@Raghu19](https://discuss.elastic.co/u/Raghu19)\
**Post date:** [June 14, 2017, 11:55am UTC](https://discuss.elastic.co/t/removing-specific-text-from-a-log-mesg/89023/3 "2017-06-14T11:55:54Z")

</div>

thanks Magnus,  
i read about the gsub and able to achieve it partially.

The last line of my multilline log message is something like below  
xxxxx (some string) : TraceLog message some\_number

(some string in the beginning containing a-z A-Z 0-9 .-\_: followed by a fixed string ': TraceLog message' followed by a random number)

Is there a way i can ignore this entire last line? i tried the below,

mutate {  
gsub =\> ["Log\_Text", ": TraceLog message", ""]  
}  
mutate {  
gsub =\> ["Log\_Text", "[0-9]\*$", ""]  
}

The first mutate will remove the fixed string : TraceLog message and the next one will remove the number in the end.  
Even if there was no substring 'TraceLog message"in side the logtext, it is removing any string in the end!

can you plz suggest how can the reg expression be defined for this entire line, which can be used in gsub..

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 14, 2017, 12:25pm UTC](https://discuss.elastic.co/t/removing-specific-text-from-a-log-mesg/89023/4 "2017-06-14T12:25:10Z")

</div>

As I said, use a drop filter to completely ignore whole events.

```nohighlight
if [message] =~ /: TraceLog message \d+/ {
  drop { }
}

```

---

<div class="post-metadata">

**Author:** ![Raghu19](https://avatars.discourse-cdn.com/v4/letter/r/5f8ce5/32.png) [@Raghu19](https://discuss.elastic.co/u/Raghu19)\
**Post date:** [June 14, 2017, 12:52pm UTC](https://discuss.elastic.co/t/removing-specific-text-from-a-log-mesg/89023/5 "2017-06-14T12:52:15Z")

</div>

ya, but i need to have the rest of the log\_text.  
im extracting the log\_text using a multi-line codec and i need all the lines except the last line (in the above format)

codec =\> multiline {  
pattern =\> "^|"  
negate =\> true  
what =\> "previous"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2017, 12:52pm UTC](https://discuss.elastic.co/t/removing-specific-text-from-a-log-mesg/89023/6 "2017-07-12T12:52:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
