# Can we format message that we received in Graylog?

**URL:** <https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403>\
**Category:** Graylog Central (peer support)\
**Created:** [July 30, 2019, 11:57am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403 "2019-07-30T11:57:06Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sagar](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@Sagar](https://community.graylog.org/u/Sagar)\
**Post date:** [July 30, 2019, 11:57am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/1 "2019-07-30T11:57:06Z")

</div>

Hi I have a requirement where I am sending a output of single script to graylog which have many lines of code and new line is saperated by special charater and I want to replace that special character with new line while displaying that message. Is there any way to do it?

For e.g. My message string is following

line 1;line 2;line 3;line 4 and when display that message I want to replace that “;” with new line “\n” while displaying it in Graylog. Is there a way to do it?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [July 30, 2019, 3:24pm UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/2 "2019-07-30T15:24:48Z")

</div>

such is not possible with Graylog vanilla - you need to work around that.

---

<div class="post-metadata">

**Author:** ![Sagar](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@Sagar](https://community.graylog.org/u/Sagar)\
**Post date:** [July 31, 2019, 7:59am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/3 "2019-07-31T07:59:52Z")

</div>

Hi Jan,

Any suggestion from you to have any kind of work around?

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [July 31, 2019, 8:20am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/4 "2019-07-31T08:20:55Z")

</div>

only hacky solutions that I do not want to share … cause that include writing your own daemon that is working with the data before it is ingested into Graylog.

---

<div class="post-metadata">

**Author:** ![Sagar](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@Sagar](https://community.graylog.org/u/Sagar)\
**Post date:** [July 31, 2019, 8:25am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/5 "2019-07-31T08:25:20Z")

</div>

So does that mean that I have choose wrong tool for such type of requirements? Because this is really common requirement when we will talk about any log system to have that log in readable format.

Because when I also puting \n in message it doesn’ taking it into account and just treating it as string.

Also when we are passing muliline string then it is considerign it as a saperate messages for each line.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [July 31, 2019, 9:47am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/6 "2019-07-31T09:47:48Z")

</div>

I do not know your requirements at all.

You asked how to make a specific operation - It might be that [regex-replace](http://docs.graylog.org/en/3.0/pages/pipelines/functions.html#regex-replace) can do this - but I’m not sure. If you just want to have that during display time, the processing pipeline can be used in a decorator.

You do not share what you have done, just mention in a half sentence what is not working for you, leaving out the details about how you ingest.

* * *

Interpret `\n` as new line might be useful in your specific use, but did you think that every `\n` should be a new line? Might it be possible that another person does not want that and ask how to disable?  
Why not take all ingested as a string and make the user responsible to parse as he likes to have the message?

* * *

Regarding Multline messages - how you Graylog know if you are sending a new message line or parts or a part of the old message? Ingest multline messages as such an event and it works (read - ingest all together and not line by line).

---

<div class="post-metadata">

**Author:** ![Sagar](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@Sagar](https://community.graylog.org/u/Sagar)\
**Post date:** [July 31, 2019, 9:58am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/7 "2019-07-31T09:58:38Z")

</div>

Hi Jan,

Sorry If I haven’t explined it properly let me provide you in detail.

I have following example message as a string and I also tried using pipeline rule in following way.

The message string is output of my shell script with muliline message that I have combine with “NEWLINE” separator to send it as a single string to graylog.

```auto
This is line1 NEWLINE This is line 2 NEWLINE This is line 3

```

```auto
rule "process_when_message_contains_newline_text"
when
  has_field("message") AND contains(to_string($message.message), "NEWLINE")
then
  let temp = replace(to_string($message.message), "NEWLINE", "\n");
  set_field("message", to_string(temp));
end

```

So “NEWLINE” is my saperator which we have replaced with actual line break while displaying message but it didn’t work.

I want to display given message in following way

This is line1  
This is line 2  
This is line 3

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [July 31, 2019, 10:53am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/8 "2019-07-31T10:53:09Z")

</div>

is the string `NEWLINE` replaced by `\n`? But `\n` is not displayed as newline?

---

<div class="post-metadata">

**Author:** ![Sagar](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@Sagar](https://community.graylog.org/u/Sagar)\
**Post date:** [July 31, 2019, 10:57am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/9 "2019-07-31T10:57:15Z")

</div>

Yes Jan,

Exactly.

Replaced work but \n isn’t displayed as newline.

---

<div class="post-metadata">

**Author:** ![Ponet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/ponet/32/2131_2.png) [@Ponet](https://community.graylog.org/u/Ponet)\
**Post date:** [July 31, 2019, 11:05am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/10 "2019-07-31T11:05:30Z")

</div>

Hi @Sagar,

That is to be expected. The replace function only deals with strings so, when you say you want “\n” it will give you “\n”.

You could try using the regex\_replace function and make your rule similar to the below:

```auto
rule "process_when_message_contains_newline_text"
when
  has_field("message") AND contains(to_string($message.message), "NEWLINE")
then
  let temp = regex_replace("^.*(NEWLINE).*$", to_string($message.message), "\n", true);
  set_field("message", to_string(temp));
end

```

I haven’t tested the above so, I have no idea if it will work and provide a newline or whether it will also just output “\n”.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 14, 2019, 11:05am UTC](https://community.graylog.org/t/can-we-format-message-that-we-received-in-graylog/11403/11 "2019-08-14T11:05:31Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
