# Simple Split filter

**URL:** <https://discuss.elastic.co/t/simple-split-filter/175362>\
**Category:** Logstash\
**Created:** [April 4, 2019, 9:29am UTC](https://discuss.elastic.co/t/simple-split-filter/175362 "2019-04-04T09:29:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lebedev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lebedev/32/53579_2.png) [@Lebedev](https://discuss.elastic.co/u/Lebedev)\
**Post date:** [April 4, 2019, 9:29am UTC](https://discuss.elastic.co/t/simple-split-filter/175362/1 "2019-04-04T09:29:08Z")

</div>

Hello! Dear collegues, need your help!  
I have the input log

09:00:00.023|SMSG|\*\*\*|ROUTING begin  
FLD\_029 \*\*  
VALIDITY\_FLAG T  
TIME\_STAT |POS\_ISO

09:00:00.024|DEBG|\*\*\*|proc\_new\_msg()  
FLD\_029 \*\*  
VALIDITY\_FLAG F  
TIME\_STAT |POS\_ISO\_IN\_E-21600.06876

09:00:00.070|DEBG|1\*\*\*|acq()  
FLD\_029 \*\*\*  
VALIDITY F  
TIME\_STAT |POS\_ISO\_-21600.05620|

Every paragraph i want write to the one event, well i see that every paragraph separate "\n\n"

I right the folowing conf:

beats {

```
port => 5055
host => " **.**. **.**"
tags => ["gateway_ssl"]
}

```

filter {

if "gateway\_ssl" in [tags] {

```
    mutate {"message", \n, " ; "}
split {
terminator => "\n\n"
add_tag => ["mutated"]	
}
 }

```

}

if "gateway\_ssl" in [tags] {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "gateway\_ssl-%{+YYYY.MM.dd}"  
}}

What am i do wrong? Could you help me correct my config?  
Thank you a lot!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 4, 2019, 12:00pm UTC](https://discuss.elastic.co/t/simple-split-filter/175362/2 "2019-04-04T12:00:39Z")

</div>

Are you consuming the entire file as a single event?

---

<div class="post-metadata">

**Author:** ![Lebedev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lebedev/32/53579_2.png) [@Lebedev](https://discuss.elastic.co/u/Lebedev)\
**Post date:** [April 4, 2019, 12:34pm UTC](https://discuss.elastic.co/t/simple-split-filter/175362/3 "2019-04-04T12:34:22Z")

</div>

Hi, Badger! Glad to hear you)  
No, not all file as single event. Just paragraph betwee two \n\n

Exm:  
1 event:  
09:00:00.023|SMSG|\*\*\*|ROUTING begin  
FLD\_029 \*\*  
VALIDITY\_FLAG T  
TIME\_STAT |POS\_ISO

2 event:  
09:00:00.024|DEBG|\*\*\*|proc\_new\_msg()  
FLD\_029 \*\*  
VALIDITY\_FLAG F  
TIME\_STAT |POS\_ISO\_IN\_E-21600.06876

3 event:  
09:00:00.070|DEBG|1\*\*\*|acq()  
FLD\_029 \*\*\*  
VALIDITY F  
TIME\_STAT |POS\_ISO\_-21600.05620|

After i will to need grok every event, i have prepered config

grok {  
match =\> {  
"message" =\> [  
"%{TIME:time\_transaction}|%{DATA:INFO}|%{NUMBER:number}|%{GREEDYDATA:type\_transaction}",  
"FLD\_029: %{NUMBER:FLD\_029\_value}",  
"VALIDITY\_FLAG: %{WORD:VALIDITY\_FLAG\_value}",  
"LOCALITY\_FLAG: %{WORD:LOCALITY\_FLAG\_value}",  
"RSW\_CAPTURE\_FLAG: %{WORD:RSW\_CAPTURE\_FLAG\_value}"]}

```
   add_tag => ["grokked"]}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 4, 2019, 12:47pm UTC](https://discuss.elastic.co/t/simple-split-filter/175362/4 "2019-04-04T12:47:19Z")

</div>

If you completely remove the filter {} section and use stdout { codec =\> rubydebug } as the output then what does a single event look like?

---

<div class="post-metadata">

**Author:** ![Lebedev](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lebedev/32/53579_2.png) [@Lebedev](https://discuss.elastic.co/u/Lebedev)\
**Post date:** [April 12, 2019, 2:10pm UTC](https://discuss.elastic.co/t/simple-split-filter/175362/5 "2019-04-12T14:10:08Z")

</div>

Well, i tried to delete all filter configuration.  
And added stdout rubydebuger, now i see that every line its the single event. Its not i need((  
But every event have the tag: beats\_input\_codec\_plain\_applied  
Is it Ok?  
Maybe i have another solutions to this task?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2019, 2:10pm UTC](https://discuss.elastic.co/t/simple-split-filter/175362/6 "2019-05-10T14:10:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
