# Working with messages with string format and split the fields of them in logstash

**URL:** <https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645>\
**Category:** Logstash\
**Created:** [September 5, 2022, 4:45am UTC](https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645 "2022-09-05T04:45:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![f.haeri](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@f.haeri](https://discuss.elastic.co/u/f.haeri)\
**Post date:** [September 5, 2022, 4:45am UTC](https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645/1 "2022-09-05T04:45:08Z")

</div>

**I have this message:**

[ReadDockerQueue] [ReadMessageQueue] message: {"requestType":"PortfolioResponse","parametersJson":"{"algorithmAccessSpecifications":{"dockerName":"D1","xxx":"xxx","userName":"xxx","instanceGuid":"95519e30-d552-4171-bd17-9030ec6116ae"},"usersPortfolios":[{"userName":"0013538225","userPortfolios":}]}"} [Dir] ir.sanayco.library.Algorithm.AlgorithmCoreBase.AlgorithmCoreBase$ReadDockerQueue

**I want this output in json format:**  
{  
"Info": "[ReadDockerQueue] [ReadMessageQueue]"  
"message": {"requestType":"PortfolioResponse","parametersJson":"{"algorithmAccessSpecifications":{"dockerName":"D1","xxx":"xxx","userName":"xxx","instanceGuid":"95519e30-d552-4171-bd17-9030ec6116ae"},"usersPortfolios":[{"userName":"0013538225","userPortfolios":}]}"}  
"desc": "[Dir] ir.sanayco.library.Algorithm.AlgorithmCoreBase.AlgorithmCoreBase$ReadDockerQueue"  
}  
**How can I solve my problem?**

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [September 5, 2022, 9:07am UTC](https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645/2 "2022-09-05T09:07:52Z")

</div>

Easiest is to use grok:

```auto
filter {
	grok {
		match => { "message" => '%{DATA:info} message: %{DATA:message}\"\} %{GREEDYDATA:desc}' }
		overwrite => ["message"]
	}
	mutate{ update => { "message" => '%{message}"}' } }

}

```

---

<div class="post-metadata">

**Author:** ![f.haeri](https://avatars.discourse-cdn.com/v4/letter/f/7ba0ec/32.png) [@f.haeri](https://discuss.elastic.co/u/f.haeri)\
**Post date:** [September 5, 2022, 10:14am UTC](https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645/3 "2022-09-05T10:14:41Z")

</div>

Thank you. It's a great answer

I have another problem in Message field. When I run your code, I receive string format in Message field. I want the output of Message field be a Json. It would be like this:

{  
"info": "[ReadDockerQueue] [ReadMessageQueue]",  
"message": {  
"requestType": "PortfolioResponse",  
"parametersJson": {  
"algorithmAccessSpecifications ": {  
"dockerName ": "D1 ",  
"xxx ": "xxx ",  
"userName ": "xxx ",  
"instanceGuid ": "95519e30 - d552 - 4171 - bd17 - 9030 ec6116ae "  
},  
"usersPortfolios ": [{  
"userName ": "0013538225 ",  
"userPortfolios ":   
}]  
}  
},  
"desc": "[Dir] ir.sanayco.library.Algorithm.AlgorithmCoreBase.AlgorithmCoreBase$ReadDockerQueue"  
}

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [September 5, 2022, 10:33am UTC](https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645/4 "2022-09-05T10:33:05Z")

</div>

I have noticed that. What you copied or originally had received, the message is not valid JSON format. You can check and correct [here](https://jsonformatter.org/)  
Another option is to manually split by grok or just by ",

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2022, 10:33am UTC](https://discuss.elastic.co/t/working-with-messages-with-string-format-and-split-the-fields-of-them-in-logstash/313645/5 "2022-10-03T10:33:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
