# Splitting based on different lines and generating multiple events

**URL:** https://discuss.elastic.co/t/splitting-based-on-different-lines-and-generating-multiple-events/189439
**Category:** Logstash
**Created:** [July 8, 2019, 10:57pm UTC](https://discuss.elastic.co/t/splitting-based-on-different-lines-and-generating-multiple-events/189439 "2019-07-08T22:57:14Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Sous\_Lesquels](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sous_lesquels/32/41843_2.png) [@Sous\_Lesquels](https://discuss.elastic.co/u/Sous_Lesquels)
#### Post date: [July 8, 2019, 10:57pm UTC](https://discuss.elastic.co/t/splitting-based-on-different-lines-and-generating-multiple-events/189439/1 "2019-07-08T22:57:15Z")

</div>

Say I have a file of this format:

```
a11
a21 b22 c23
a31
a41
a51 b52 c53

```

I.e. lines can be either:

- `aX`
- `aX bY cZ`

I want to generate:

- A signle event for `aX` lines (emitting `{a: aX, c: 0}`)
- Two events for `aX bY cZ` lines (emitting `{a: aX, c: 0}` and `{a: bY, c: Z}`)

How do I approach this?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 8, 2019, 11:33pm UTC](https://discuss.elastic.co/t/splitting-based-on-different-lines-and-generating-multiple-events/189439/2 "2019-07-08T23:33:34Z")

</div>

I would start with

```
    if [message] !~ /[^]+ [^]+ [^]+/ {
        mutate { add_field => { "a" => "%{message}" "c" => "0" } }
        mutate { convert => { "c" => "integer" } }
    } else {
        grok { match => { "message" => "^%{WORD:[@metadata][first]} %{WORD:[@metadata][second]} %{WORD:[@metadata][third]}$" } }
        mutate { add_field => { "foo" => ["%{[@metadata][first]} 0", "%{[@metadata][second]} %{[@metadata][third]}" ] } }
        split { field => "foo" }
    }

```

That will create stuff that looks like this

```
{
         "a" => "a41",
         "c" => 0,
"@timestamp" => 2019-07-08T23:27:28.313Z,
   "message" => "a41"
}
{
       "foo" => "a21 0",
"@timestamp" => 2019-07-08T23:27:28.313Z,
   "message" => "a21 b22 c23"
}
{
       "foo" => "b22 c23",
"@timestamp" => 2019-07-08T23:27:28.313Z,
   "message" => "a21 b22 c23"
}

```

You just need to add the grok and mutate+add\_field to convert [foo] to the fields that you want. It's really ugly code, but I do not have time to write something prettier right now.

Where you write bN I hope you meant bY 🙂

---

<div class="post-metadata">

### Author: ![Sous\_Lesquels](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sous_lesquels/32/41843_2.png) [@Sous\_Lesquels](https://discuss.elastic.co/u/Sous_Lesquels)
#### Post date: [July 9, 2019, 1:38pm UTC](https://discuss.elastic.co/t/splitting-based-on-different-lines-and-generating-multiple-events/189439/3 "2019-07-09T13:38:43Z")

</div>

Thanks @Badger!

> Where you write bN I hope you meant bY 🙂

Ah, right, typo, I fixed in the q.

Let me look into what you suggested.

Is there a way to grok first for the relevant parts (i.e. have 3 separate groks for `aX`, `bY` and `cY`, where the last two should be optional), put everything in an event (i.e. have an event that has `aX`, `bY` and `cY` as fields) and then clone based on the resulting event?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 9, 2019, 1:56pm UTC](https://discuss.elastic.co/t/splitting-based-on-different-lines-and-generating-multiple-events/189439/4 "2019-07-09T13:56:15Z")

</div>

> [@Sous\_Lesquels](#):
>
> Is there a way to grok first for the relevant parts (i.e. have 3 separate groks for `aX` , `bY` and `cY` , where the last two should be optional), put everything in an event (i.e. have an event that has `aX` , `bY` and `cY` as fields) and then clone based on the resulting event?

I am sure there are many ways to do it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 6, 2019, 1:56pm UTC](https://discuss.elastic.co/t/splitting-based-on-different-lines-and-generating-multiple-events/189439/5 "2019-08-06T13:56:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
