# Trailing Whitespaces in Message Field

**URL:** <https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574>\
**Category:** Logstash\
**Created:** [August 6, 2022, 1:38am UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574 "2022-08-06T01:38:56Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 6, 2022, 1:38am UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/1 "2022-08-06T01:38:56Z")

</div>

Here is my sample data:

```auto
EventQ 00001350 Fri 08/05 20:19:20.541 _00008_ 39765 990 HEARTBEAT SYSTEM=>MDETMGR i"SINGLETON" //beep// added to EventQueue for a new total of 1 Pending Event

```

This is one line and Elastic is identifying the end of each line properly. There is funky spacing in each line.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88349c02692d0556a62b2bc407117ae9cc4ce07e.png)

I have used the grok creator tools out there and can get each individual line working by using the \s\* or %{SPACE}\* pattern but once I put it into my .conf file and let the logs rip through it I just get grok parse failures. What am I doing wrong?

This was my latest sad attempt...

```auto
"%{WORD:event}%{SPACE}*%{WORD:code}%{SPACE}*%{DAY:day}%{SPACE}*%{MONTHNUM:month}/%{MONTHDAY:day}%{SPACE}*%{TIME:time}%{SPACE}*%{GREEDYDATA:msg}"

```

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 6, 2022, 1:42am UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/2 "2022-08-06T01:42:01Z")

</div>

When I do

```auto
"%{WORD:event}%{SPACE}*%{GREEDYDATA:msg}"

```

it gives me:

event: E  
msg: ventQ 00001350 Fri 08/05 20:19:20.541 _00008_ 39765 990 HEARTBEAT SYSTEM=\>MDETMGR i"SINGLETON" //beep// added to EventQueue for a new total of 1 Pending Event

---

<div class="post-metadata">

**Author:** ![sudhagar\_ramesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sudhagar_ramesh/32/105673_2.png) [@sudhagar\_ramesh](https://discuss.elastic.co/u/sudhagar_ramesh)\
**Post date:** [August 6, 2022, 2:29am UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/3 "2022-08-06T02:29:07Z")

</div>

Hello @Micah_Barsness

Could you try these below GROK pattern and let us know how it goes

```auto
%{WORD:event}\s*%{WORD:code}\s*%{DAY:day}\s*%{MONTHNUM:month}/%{MONTHDAY:day}\s*%{TIME:time}\s*%{GREEDYDATA:msg}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 6, 2022, 4:39am UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/4 "2022-08-06T04:39:20Z")

</div>

> [@Micah\_Barsness](#):
>
> What am I doing wrong?

SPACE is actually \s\*, no need for additional asterisk. Have a look [here](https://github.com/hpcugent/logstash-patterns/blob/master/files/grok-patterns) for patterns.

Log fields are usually separated by space. \s\* is 0 or more whitespaces, \s+ is one or more. Depend on case you use \* or + .

> The \s metacharacter matches whitespace character.  
> Whitespace characters can be:
> 
> - A space character
> - A tab character \t
> - A carriage return character \r
> - A new line character \n
> - A vertical tab character \v
> - A form feed character \f

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 6, 2022, 6:51pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/5 "2022-08-06T18:51:36Z")

</div>

> [@sudhagar\_ramesh](#):
>
> `%{WORD:event}\s*%{WORD:code}\s*%{DAY:day}\s*%{MONTHNUM:month}/%{MONTHDAY:day}\s*%{TIME:time}\s*%{GREEDYDATA:msg}`

When I use this it doesn't work, and it should - I can put it into the grok debugger and its working just fine. It makes me think there is something else going on... Here's my input /filter

```auto
input {
  beats {
   port => 5047
        }
      }

filter {
  grok {
  match => { "message" => [
"%{WORD:event}\s*%{WORD:code}\s*%{DAY:day}\s*%{MONTHNUM:month}/%{MONTHDAY:day}\s*%{TIME:time}\s*%{GREEDYDATA:msg}"
                          ]
           }
       }
       }

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 7, 2022, 7:46am UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/6 "2022-08-07T07:46:02Z")

</div>

Try with

```auto
filter {

	grok {
		match => { "message" => "%{WORD:event}\s+%{WORD:code}\s+%{EXCHTIME:[@metadata][timestamp]}\s*%{DATA:code2}\s+%{NUMBER:code3}\s+%{NUMBER:code4}\s+%{GREEDYDATA:msg}" }
		pattern_definitions => { "EXCHTIME" => "%{DAY:day}\s*%{MONTHNUM:month}/%{MONTHDAY:daynum}\s*%{TIME:hours}" } 
	}

    date {
    match => ["[@metadata][timestamp]", "E MM/dd HH:mm:ss.SSS"]
    timezone => "Asia/Dubai"
	remove_field => ["day", "daynum","month", "hours"]
   }
   
}

```

Result:

```auto
{
         "code2" => "_00008_",
          "code" => "00001350",
         "code4" => "990",
    "@timestamp" => 2022-08-05T16:19:20.541Z,
           "msg" => "HEARTBEAT SYSTEM=>MDETMGR i\\\"SINGLETON\\\" //beep// added to EventQueue for a new total of 1 Pending Event",
       "message" => "EventQ 00001350 Fri 08/05 20:19:20.541 _00008_ 39765 990 HEARTBEAT SYSTEM=>MDETMGR i\\\"SINGLETON\\\" //beep// added to EventQueue for a new total of 1 Pending Event",
         "code3" => "39765",
      "@version" => "1"
}

```

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 8, 2022, 1:29pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/7 "2022-08-08T13:29:11Z")

</div>

I think I've figured out the issue, need assistance with the solution:

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/b/8b6843fc9f2a4cfa0fb83d1ca93e48253a008743.png)

There are trailing whitespaces in each event.

![image](https://us1.discourse-cdn.com/elastic/original/3X/c/0/c0cb20112b8535481f309fd41de113d73dff3581.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/a/d/adc2fe4f059c8dd0b0b120e14e12f82ea63e673f.png)

I did some research and saw that NOTSPACE might work better for this but haven't had any luck yet.

```auto
{NOTSPACE:event}%{NOTSPACE:code}%{DAY:day}%{MONTHNUM:month}/%{MONTHDAY:day}%{TIME:time}%{GREEDYDATA:msg}

```

Any suggestions on how to take care of these hidden characters?

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 8, 2022, 1:43pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/8 "2022-08-08T13:43:42Z")

</div>

Interesting..

A simple,

```auto
"%{NOTSPACE:event}%{GREEDYDATA:msg}"

```

produces the event with no trailing characters

![image](https://us1.discourse-cdn.com/elastic/original/3X/2/c/2c21c25cee58f10ce8427690ffd8b7bc86b27cd9.png)

but the characters are left on the "msg" field

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/a/daed7619f02df7c424be42e5dc30c7c4d5e7077b.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 8, 2022, 1:48pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/9 "2022-08-08T13:48:42Z")

</div>

To remove trailing or leading whitespaces in Logstash you can use the [`strip`](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-strip) option of the `mutate` filter.

```auto
    filter {
      mutate {
         strip => ["field1", "field2"]
      }
    }

```

This will remove any leading or trailing whitespaces from the fields specified.

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 8, 2022, 2:01pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/10 "2022-08-08T14:01:17Z")

</div>

The only problem is that I'm unable to grok to get those fields out. I get grokparsefailure every time I run

```auto
%{NOTSPACE:event}%{NOTSPACE:code}%{DAY:day}%{MONTHNUM:month}/%{MONTHDAY:day}%{TIME:time}%{GREEDYDATA:msg}

```

I believe its getting tripped up on these whitespaces during the grok.

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 8, 2022, 2:30pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/11 "2022-08-08T14:30:47Z")

</div>

Also tried:

```auto
{NOTSPACE:event}\S+%{NOTSPACE:code}\S+%{DAY:day}\S+%{MONTHNUM:month}/%{MONTHDAY:day}\S+%{TIME:time}\S+%{GREEDYDATA:msg}

```

no luck ☹

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 8, 2022, 2:54pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/12 "2022-08-08T14:54:17Z")

</div>

You should use `\s+` or `%{SPACE}`, not `\S+`.

This works in Grok Debugger on Kibana.

```auto
%{NOTSPACE:event}\s+%{NOTSPACE:code}\s+%{DAY:day}\s+%{MONTHNUM:month}/%{MONTHDAY:day}\s+%{TIME:time}\s+%{GREEDYDATA:msg}

```

The response is:

```auto
{
  "msg": "_00008_ 39765 990 HEARTBEAT SYSTEM=>MDETMGR i\"SINGLETON\" //beep// added to EventQueue for a new total of 1 Pending Event",
  "code": "00001350",
  "month": "08",
  "time": "20:19:20.541",
  "event": "EventQ",
  "day": "05"
}

```

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 8, 2022, 3:16pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/13 "2022-08-08T15:16:00Z")

</div>

I understand, I've got it working in grok debuggers but grok is not processing my whitespaces properly.

Here's a view of the raw logs -

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fc3f23d8dfe356495028640629be35edcfb07ed6.png)

My current code (has to be simplified otherwise I just get grok failures and its impossible to troubleshoot so im going one field at a time trying to figure this out):

```auto
grok {
 match => { "message" => [
    "%{NOTSPACE:event}%{GREEDYDATA:msg}"
    ]
           } }

grok { match => { "msg" => "%{GREEDYDATA:code}%{GREEDYDATA:msg2}" }}            
       }

```

I can't even get this to work:

```auto
input {
  beats {
   port => 5047
        }
      }

filter {

mutate { 
    gsub => [
      # replace all whitespace characters or multiple adjacent whitespace characters with one space 
      "message", "\s+", " "
    ]
  }

}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e550fdb4cd26e057b8f3b169295f1249947d0c56.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 8, 2022, 3:33pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/14 "2022-08-08T15:33:37Z")

</div>

I'm not sure your gsub will do what you want to do, it will match one or more spaces an replace each match with another whitespace, so if you have 3 whitespaces, it will match each one of them and replace by another whitespace, in the end you will have the same 3 whitespaces.

Are you using this grok:

```auto
%{NOTSPACE:event}\s+%{NOTSPACE:code}\s+%{DAY:day}\s+%{MONTHNUM:month}/%{MONTHDAY:day}\s+%{TIME:time}\s+%{GREEDYDATA:msg}

```

This should work.

If you want to go field by field just change where you start using `GREEDYDATA`.

For example:

Start with:

```auto
%{NOTSPACE:event}\s+%{%{GREEDYDATA:msg}

```

If you cant the event and msg field, go to the next field:

```auto
%{NOTSPACE:event}\s+%{NOTSPACE:code}\s+%{GREEDYDATA:msg}

```

And proceed like this until you parse everything.

From what you shared I see no reason for this grok to not work.

Can you share a sample of your messages as plain text so people can try to replicate your pipeline?

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 8, 2022, 3:41pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/15 "2022-08-08T15:41:45Z")

</div>

> [@leandrojmp](#):
>
> Can you share a sample of your messages as plain text so people can try to replicate your pipeline?

```auto
Events 00001350 Mon 08/08 05:56:08.779 <Tx> [Ready] SysHeartbeat 000 7725 990 HEARTBEAT SYSTEM=>OFFMGR i"SINGLETON" //beep// NOW 9 of 13 258 Offlines _00004_ OFFMGR Ready
OfflinesH 00001350 Mon 08/08 05:56:08.779 _00004_ OFFMGR RUN001 SleepWalk DispatchEvent
Worker18 000013B4 Mon 08/08 05:56:08.779 [W18] _00010_ SECURITYMGR Security Ready worker.processmessage BEGINS 001 @1337
Offlines 00001350 Mon 08/08 05:56:08.779 _00004_ OFFMGR RUN001 4443 Posting SLEEPWALK
EventQ 000013B4 Mon 08/08 05:56:08.779 _00010_ 7724 990 HEARTBEAT SYSTEM=>SECURITYMGR i"SINGLETON" //beep// removed from EventQueue leaving a new total of No Pending Events
EventQ 00001350 Mon 08/08 05:56:08.779 _00007_ 7726 990 HEARTBEAT SYSTEM=>MTOKMGR i"SINGLETON" //beep// added to EventQueue for a new total of 1 Pending Event
Security 000013B4 Mon 08/08 05:56:08.779 _00010_ SECURITYMGR RUN001 4975 <Rx> [Ready] SysHeartbeat 7724 990 HEARTBEAT SYSTEM=>SECURITYMGR i"SINGLETON" //beep//
Events 00001350 Mon 08/08 05:56:08.779 <Tx> [Ready] SysHeartbeat 000 7726 990 HEARTBEAT SYSTEM=>MTOKMGR i"SINGLETON" //beep// NOW 8 of 13 258 MulTokAdd _00007_ MTOKMGR Ready
MulTokAddH 00001350 Mon 08/08 05:56:08.779 _00007_ MTOKMGR RUN001 SleepWalk DispatchEvent
Worker18 000013B4 Mon 08/08 05:56:08.779 [W18] _00010_ SECURITYMGR Security Ready worker.processmessage ENDS 000 (+ 1) @1337
MulTokAdd 00001350 Mon 08/08 05:56:08.779 _00007_ MTOKMGR RUN001 4442 Posting SLEEPWALK
Worker16 000013AC Mon 08/08 05:56:08.779 [W16] _00004_ OFFMGR Offlines Ready worker.processmessage BEGINS 001 @1337
Worker18 000013B4 Mon 08/08 05:56:08.779 [W18] _00007_ MTOKMGR MulTokAdd Ready worker.processmessage BEGINS 001 @1337
EventQ 000013AC Mon 08/08 05:56:08.779 _00004_ 7725 990 HEARTBEAT SYSTEM=>OFFMGR i"SINGLETON" //beep// removed from EventQueue leaving a new total of No Pending Events
EventQ 00001350 Mon 08/08 05:56:08.779 _00008_ 7727 990 HEARTBEAT SYSTEM=>MDETMGR i"SINGLETON" //beep// added to EventQueue for a new total of 1 Pending Event
EventQ 000013B4 Mon 08/08 05:56:08.779 _00007_ 7726 990 HEARTBEAT SYSTEM=>MTOKMGR i"SINGLETON" //beep// removed from EventQueue leaving a new total of No Pending Events
Events 00001350 Mon 08/08 05:56:08.779 <Tx> [Ready] SysHeartbeat 000 7727 990 HEARTBEAT SYSTEM=>MDETMGR i"SINGLETON" //beep// NOW 7 of 13 258 MulTokLkup _00008_ MDETMGR Ready
MulTokAdd 000013B4 Mon 08/08 05:56:08.779 _00007_ MTOKMGR RUN001 4443 <Rx> [Ready] SysHeartbeat 7726 990 HEARTBEAT SYSTEM=>MTOKMGR i"SINGLETON" //beep//
Offlines 000013AC Mon 08/08 05:56:08.779 _00004_ OFFMGR RUN001 4444 <Rx> [Ready] SysHeartbeat 7725 990 HEARTBEAT SYSTEM=>OFFMGR i"SINGLETON" //beep//
Worker18 000013B4 Mon 08/08 05:56:08.779 [W18] _00007_ MTOKMGR MulTokAdd Ready worker.processmessage ENDS 000 (+ 1) @1337
MulTokLkup 00001350 Mon 08/08 05:56:08.779 _00008_ MDETMGR RUN001 SleepWalk DispatchEvent
Worker16 000013AC Mon 08/08 05:56:08.779 [W16] _00004_ OFFMGR Offlines Ready worker.processmessage ENDS 000 (+ 1) @1337
MulTokLkup 00001350 Mon 08/08 05:56:08.779 _00008_ MDETMGR RUN001 4443 Posting SLEEPWALK

```

these are stored in .trc files which i'm using filebeat to send to logstash. if you double click on "events" at the top left for example its like the spaces are tied to the word Events

---

<div class="post-metadata">

**Author:** ![Micah\_Barsness](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/micah_barsness/32/83318_2.png) [@Micah\_Barsness](https://discuss.elastic.co/u/Micah_Barsness)\
**Post date:** [August 8, 2022, 3:43pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/16 "2022-08-08T15:43:48Z")

</div>

> [@leandrojmp](#):
>
> This should work.

I can confirm that it does not. I just get grok parse failure.

As soon as I insert the \s+ the grok fails.

Here is the code you are suggesting:

```auto
input {
  beats {
   port => 5047
        }

      }

filter {
grok {
  match => { "message" => ["%{NOTSPACE:event}\s+%{GREEDYDATA:msg}"] }
     }
       }

```

here are the results:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd259f8b310ab59e6f4c9419f99dbf132515ef11.png)

and here is the next phase of the test:

```auto
input {
  beats {
   port => 5047
        }

      }

filter {
grok {
  match => { "message" => ["%{NOTSPACE:event}\s+%{NOTSPACE:code}\s+%{GREEDYDATA:msg}"] }
     }
       }

```

and the result:

![image](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8e8b6747cabbb5567fdfb85c2b8cf3b619b38862.png)

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/5/b557b9db93cd0339adb9dfc1b73da7d577ebcdb6.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/757093d2e1f0cec009308b5e594d4acb4354a684.png)

It's like its not seeing these spaces as spaces...

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 8, 2022, 4:31pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/17 "2022-08-08T16:31:36Z")

</div>

I can't replicate, the grok works fine for me:

Using this grok:

```auto
filter {
    grok {
        match => {
            "message" => "%{NOTSPACE:event}\s+%{NOTSPACE:code}\s+%{DAY:day}\s+%{MONTHNUM:month}/%{MONTHDAY:day}\s+%{TIME:time}\s+%{GREEDYDATA:msg}"
        }
    }
}

```

These are some samples of the output from Logstash:

```auto
{
          "code" => "00001350",
    "@timestamp" => 2022-08-08T16:27:28.359Z,
           "day" => [
        [0] "Mon",
        [1] "08"
    ],
         "event" => "Events",
      "@version" => "1",
          "host" => "elk-lab",
         "month" => "08",
       "message" => "Events 00001350 Mon 08/08 05:56:08.779 <Tx> [Ready] SysHeartbeat 000 7725 990 HEARTBEAT SYSTEM=>OFFMGR i\"SINGLETON\" //beep// NOW 9 of 13 258 Offlines _00004_ OFFMGR Ready",
          "time" => "05:56:08.779",
           "msg" => "<Tx> [Ready] SysHeartbeat 000 7725 990 HEARTBEAT SYSTEM=>OFFMGR i\"SINGLETON\" //beep// NOW 9 of 13 258 Offlines _00004_ OFFMGR Ready"
}
{
          "code" => "00001350",
    "@timestamp" => 2022-08-08T16:27:28.437Z,
           "day" => [
        [0] "Mon",
        [1] "08"
    ],
         "event" => "OfflinesH",
      "@version" => "1",
          "host" => "elk-lab",
         "month" => "08",
       "message" => "OfflinesH 00001350 Mon 08/08 05:56:08.779 _00004_ OFFMGR RUN001 SleepWalk DispatchEvent",
          "time" => "05:56:08.779",
           "msg" => "_00004_ OFFMGR RUN001 SleepWalk DispatchEvent"
}
{
          "code" => "000013B4",
    "@timestamp" => 2022-08-08T16:27:28.438Z,
           "day" => [
        [0] "Mon",
        [1] "08"
    ],
         "event" => "Worker18",
      "@version" => "1",
          "host" => "elk-lab",
         "month" => "08",
       "message" => "Worker18 000013B4 Mon 08/08 05:56:08.779 [W18] _00010_ SECURITYMGR Security Ready worker.processmessage BEGINS 001 @1337",
          "time" => "05:56:08.779",
           "msg" => "[W18] _00010_ SECURITYMGR Security Ready worker.processmessage BEGINS 001 @1337"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2022, 4:31pm UTC](https://discuss.elastic.co/t/trailing-whitespaces-in-message-field/311574/18 "2022-09-05T16:31:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
