# Space separated fields

**URL:** <https://discuss.elastic.co/t/space-separated-fields/61276>\
**Category:** Logstash\
**Created:** [September 22, 2016, 3:28pm UTC](https://discuss.elastic.co/t/space-separated-fields/61276 "2016-09-22T15:28:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![joshuaclark](https://avatars.discourse-cdn.com/v4/letter/j/5daacb/32.png) [@joshuaclark](https://discuss.elastic.co/u/joshuaclark)\
**Post date:** [September 22, 2016, 3:28pm UTC](https://discuss.elastic.co/t/space-separated-fields/61276/1 "2016-09-22T15:28:25Z")

</div>

Hi I'm having a problem with shipping a log to elasticsearch. I have the config setup to use (?.{64}) when the field has /carbon/admin/login.jsp it's separating every slash. How can I get it to keep the slashes in the same field?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 22, 2016, 4:47pm UTC](https://discuss.elastic.co/t/space-separated-fields/61276/2 "2016-09-22T16:47:58Z")

</div>

It's very hard to understand what you're asking. Please supply your configuration, an example of what your event looks like, and what you'd like it to look like instead.

---

<div class="post-metadata">

**Author:** ![joshuaclark](https://avatars.discourse-cdn.com/v4/letter/j/5daacb/32.png) [@joshuaclark](https://discuss.elastic.co/u/joshuaclark)\
**Post date:** [September 22, 2016, 6:11pm UTC](https://discuss.elastic.co/t/space-separated-fields/61276/3 "2016-09-22T18:11:21Z")

</div>

Sorry it looks like this issue that I'm having is related to the mappings. I have a field called name that looks like this in Discover "Name:GET /carbon/metrics-view" which is how it should be. However, when I try to visualize this field it breaks it up like "GET" "carbon" "metrics" "view". I tried switching to raw but there is no raw option for the field. I'm running logstash 2.3.4, Kibana 4.6.1. My logstash conf is

input {  
file {  
path =\> ["C:/Program Files (x86)/Jenkins/jobs/_/builds/_/log"]  
start\_position =\> "beginning"  
sincedb\_path =\> "nul"  
}  
}

filter {  
grok {  
match =\> ["message", "(?.{64})(?.{10})(?.{13})(?.{8})(?.{8})(?.{8})(?.{9})(?\<req\s\>.{5})"]  
}

```
mutate {
	strip => ["Name", "reqs", "fails", "Avg", "Min", "Max", "Median", "req\s"]
	convert => ["reqs", "integer"]
	convert => ["fails", "integer"]
	convert => ["Avg", "integer"]
	convert => ["Min", "integer"]
	convert => ["Max", "integer"]
	convert => ["Median", "integer"]
	convert => ["req\s", "integer"]
    }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 22, 2016, 7:31pm UTC](https://discuss.elastic.co/t/space-separated-fields/61276/4 "2016-09-22T19:31:27Z")

</div>

Yes, this is indeed mapping-related. The field in question in analyzed, but you don't want that when you're doing term aggregations. Use an index template to set the field in question to not\_analyzed.

A wild guess as to why you don't have a .raw subfield is because you're calling your indexes something else than logstash-_. The index template that Logstash installs by default only applies to logstash-_ indexes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:37am UTC](https://discuss.elastic.co/t/space-separated-fields/61276/5 "2017-07-06T04:37:17Z")

</div>


