# Trying to have dissect clean up after itself

**URL:** https://discuss.elastic.co/t/trying-to-have-dissect-clean-up-after-itself/134087
**Category:** Logstash
**Created:** [May 31, 2018, 5:09pm UTC](https://discuss.elastic.co/t/trying-to-have-dissect-clean-up-after-itself/134087 "2018-05-31T17:09:18Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 31, 2018, 5:09pm UTC](https://discuss.elastic.co/t/trying-to-have-dissect-clean-up-after-itself/134087/1 "2018-05-31T17:09:18Z")

</div>

I am using dissect to parse a field it has just parsed out of a message.

```auto
input { generator { message => 'aaa bbb/ccc ddd' count => 1 } }
output { stdout { codec => rubydebug } }
filter {
    dissect {
        mapping => {
            "message" => '%{a} %{bAndC} %{d}'
            "bAndC" => '%{b}/%{c}'
        }
    }
}

```

That gets this, which looks good. However I do not need the combined bAndC field

```
     "bAndC" => "bbb/ccc",
         "a" => "aaa",
         "b" => "bbb",
         "d" => "ddd",
         "c" => "ccc"

```

So I tried this

```auto
input { generator { message => 'aaa bbb/ccc ddd' count => 1 } }
output { stdout { codec => rubydebug } }
filter {
    dissect {
        mapping => {
            "message" => '%{a} %{bAndC} %{d}'
            "bAndC" => '%{b}/%{c}'
        }
        remove_field => ["bAndC"]
    }
}

```

Which gets me this. Is that a bug or a feature?

```
         "a" => "aaa",
         "d" => "ddd",

```

( "%{a} %{b}/%{c} %{d}" is not a solution to my problem 🙂 )

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [May 31, 2018, 5:14pm UTC](https://discuss.elastic.co/t/trying-to-have-dissect-clean-up-after-itself/134087/2 "2018-05-31T17:14:48Z")

</div>

Why is the last option not a solution? It would be easier to help if you actually showed some real data?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 31, 2018, 5:18pm UTC](https://discuss.elastic.co/t/trying-to-have-dissect-clean-up-after-itself/134087/3 "2018-05-31T17:18:31Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> Why is the last option not a solution?

Actually it is a solution. The subsequent parsing of ccc cannot be done using dissect, but combining the two things I am doing in that dissect works just fine.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 28, 2018, 5:18pm UTC](https://discuss.elastic.co/t/trying-to-have-dissect-clean-up-after-itself/134087/4 "2018-06-28T17:18:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
