# Splitting message using Logstash mutate filter

**URL:** <https://discuss.elastic.co/t/splitting-message-using-logstash-mutate-filter/373011>\
**Category:** Logstash\
**Created:** [January 9, 2025, 3:49pm UTC](https://discuss.elastic.co/t/splitting-message-using-logstash-mutate-filter/373011 "2025-01-09T15:49:58Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [January 9, 2025, 3:49pm UTC](https://discuss.elastic.co/t/splitting-message-using-logstash-mutate-filter/373011/1 "2025-01-09T15:49:58Z")

</div>

Hi All,

The incoming feed (log) to Logstash has parameters which are delimited by `~|~`

These are being mutated and split in Logstash as follows. :

```auto
 if [type] == "tv_dmz_access" {
                mutate {
                        split => ["message", "~|~"]
                        add_field =>{
                          "timeReqRecd" => "%{[message][0]}"
                          "remoteHostIP" => "%{[message][1]}"
                          "xForwardedFor" => "%{[message][2]}"

```

Problem is that ` "xForwardedFor"` at times receives more than one IPs which are comma separted. For example `~|~109.1.07.12, 14.1.15.4, 3.3.8.13, 4.15.24.7, 9.15.34.74~|~`

Kibana tends to display `only` the first IP and disregards other 4.

How can I set Logstash so that Kibana displays all 5 IPs instead of only one (first)?

Thanks
