# Unable to process joblogs coming from filebeat

**URL:** <https://discuss.elastic.co/t/unable-to-process-joblogs-coming-from-filebeat/172309>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 14, 2019, 10:36am UTC](https://discuss.elastic.co/t/unable-to-process-joblogs-coming-from-filebeat/172309 "2019-03-14T10:36:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sapna](https://avatars.discourse-cdn.com/v4/letter/s/ee59a6/32.png) [@Sapna](https://discuss.elastic.co/u/Sapna)\
**Post date:** [March 14, 2019, 10:36am UTC](https://discuss.elastic.co/t/unable-to-process-joblogs-coming-from-filebeat/172309/1 "2019-03-14T10:36:43Z")

</div>

Hello,  
I have a job logs for DB2 and they are coming from filebeat.  
I want to extract message, error code , table name, DB instance from logs to visualize them in kibana.

Logs are for DB instance : EXXXX  
2019/03/08 21:35:01 DB2 Runstats command returned (RC=4):  
connect to enablest

Database Connection Information

Database server = xxxx  
SQL authorization ID = SOXDB  
Local database alias = Exxxxx

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

Job los for PWXXX :

2019/03/08 21:35:05 Using TEMPFILE /tmp/sxxx  
2019/03/08 21:37:26 DB2 Runstats command returned (RC=4):  
connect to xxxxx

Database Connection Information

Database server = XXXX  
SQL authorization ID = xxx  
Local database alias = PXXXX

RUNSTATS ON TABLE SXXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

RUNSTATS ON TABLE SXXXX WITH DISTRIBUTION AND DETAILED INDEXES ALL ALLOW WRITE ACCESS  
DB20000I The RUNSTATS command completed successfully.

Both of the logs are in same job log.

Could you please help how we can paste timestamp and DB instance at each log and then extract error code using grok in logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 11, 2019, 10:36am UTC](https://discuss.elastic.co/t/unable-to-process-joblogs-coming-from-filebeat/172309/2 "2019-04-11T10:36:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
