# Replace content of host field with part from message field

**URL:** <https://discuss.elastic.co/t/replace-content-of-host-field-with-part-from-message-field/53636>\
**Category:** Logstash\
**Created:** [June 22, 2016, 9:33am UTC](https://discuss.elastic.co/t/replace-content-of-host-field-with-part-from-message-field/53636 "2016-06-22T09:33:05Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![himbeere](https://avatars.discourse-cdn.com/v4/letter/h/db5fbb/32.png) [@himbeere](https://discuss.elastic.co/u/himbeere)\
**Post date:** [June 22, 2016, 9:33am UTC](https://discuss.elastic.co/t/replace-content-of-host-field-with-part-from-message-field/53636/1 "2016-06-22T09:33:05Z")

</div>

Hello.

I'm trying to replace the content of the host field with part from message field. My message field contains something like that:

message:\<85\>Jun 22 11:24:33 [backup02.bla.domain.de](http://backup02.bla.domain.de) sudo: .....

Now i wanna take "[backup02.bla.domain.de](http://backup02.bla.domain.de)" and put it in the "host" field. My filter currently is looking like this:

filter {  
if [type] == "general" {  
grok {  
match =\> ["message", "^(([a-zA-Z]|[a-zA-Z][a-zA-Z0-9-]_[a-zA-Z0-9]).)_([A-Za-z]|[A-Za-z][A-Za-z0-9-]\*[A-Za-z0-9])$" ]  
overwrite =\> ["host"]  
}  
}  
}

But this does not seem t o have any effect. Can someone please point me to the right direction?

thanks and cheers

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 22, 2016, 11:23am UTC](https://discuss.elastic.co/t/replace-content-of-host-field-with-part-from-message-field/53636/2 "2016-06-22T11:23:22Z")

</div>

I think you're misunderstanding how grok filters work. The grok expression in `match` needs to include information about which fields that should be extracted, typically via the grok-specific `%{PATTERN:destination-field}`. The `overwrite` option only indicates which fields in the original event that are allowed to be overwritten from the filter.

It looks like you're trying to parse a syslog message. Have you looked at the example in the Logstash documentation that covers that?

---

<div class="post-metadata">

**Author:** ![himbeere](https://avatars.discourse-cdn.com/v4/letter/h/db5fbb/32.png) [@himbeere](https://discuss.elastic.co/u/himbeere)\
**Post date:** [June 22, 2016, 12:54pm UTC](https://discuss.elastic.co/t/replace-content-of-host-field-with-part-from-message-field/53636/3 "2016-06-22T12:54:26Z")

</div>

Hello Magnus.

Thanks for taking the time to answer.

So you are saying i cannot take information from one field and add it to another overwriting the original content?  
Is there a way of doing so?

cheers

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 22, 2016, 1:59pm UTC](https://discuss.elastic.co/t/replace-content-of-host-field-with-part-from-message-field/53636/4 "2016-06-22T13:59:48Z")

</div>

> So you are saying i cannot take information from one field and add it to another overwriting the original content?

Sure you can, it's just that you're using the wrong syntax. Please have a look at the grok filter examples in the documentation and make sure you understand what they do.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:51am UTC](https://discuss.elastic.co/t/replace-content-of-host-field-with-part-from-message-field/53636/5 "2017-07-06T04:51:10Z")

</div>


