# Breaking down a field

**URL:** <https://discuss.elastic.co/t/breaking-down-a-field/160023>\
**Category:** Logstash\
**Created:** [December 9, 2018, 1:22am UTC](https://discuss.elastic.co/t/breaking-down-a-field/160023 "2018-12-09T01:22:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexsamad](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Post date:** [December 9, 2018, 1:22am UTC](https://discuss.elastic.co/t/breaking-down-a-field/160023/1 "2018-12-09T01:22:03Z")

</div>

Hi

so i have a  
grok {  
match =\> ["message", " +"(?\<http\_ybid\>[^"]\*)" \*%{GREEDYDATA:msg}"]  
}

now this field could be  
"-"  
or  
"1234.999"

I would like to end up with if possible  
http\_ybid to equal "-" or "1234.999"

and  
http\_ybid.trans to equal "-" or "1234"  
http\_ybid.req to equal "-" or "999"

How can i do that ?

I'm guessing I can

if [http\_ybid] = "-"  
http\_ybid.trans = "-"  
http\_ybid.req = "-"  
else  
http\_ybid.trans = match up to "."  
http\_ybid.req = match after "."  
fi

but how do I do that ?

A

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [December 9, 2018, 4:43am UTC](https://discuss.elastic.co/t/breaking-down-a-field/160023/2 "2018-12-09T04:43:43Z")

</div>

Should be fairly easy using the mutate filter. First...is having a - a requirement for the fields? If not, I'd suggest using the mutate gsub option and convert the - to a 0 if that is what the value is when the doc arrives to Logstash. That way the mapping data type for the field could be an integer vs a string which is _typically_ preferred but not always. Second, I'd use the mutate split option to split the field if it is found not to be a - (or 0). Then you'd have an array object and you could then create new fields based on those values, i.e.  
If [http\_ybid] != "0" {  
mutate {  
add\_field =\> {  
"[http\_ybid][trans]" =\> "%{http\_ybid[0]}"  
"[http\_ybid][req]" =\> "%{http\_ybid[1]"}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![alexsamad](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Post date:** [December 9, 2018, 10:56pm UTC](https://discuss.elastic.co/t/breaking-down-a-field/160023/3 "2018-12-09T22:56:25Z")

</div>

Cool, that looks easy

A

---

<div class="post-metadata">

**Author:** ![alexsamad](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@alexsamad](https://discuss.elastic.co/u/alexsamad)\
**Post date:** [December 10, 2018, 1:14am UTC](https://discuss.elastic.co/t/breaking-down-a-field/160023/4 "2018-12-10T01:14:52Z")

</div>

Did it slightly different  
mutate {  
gsub =\> ["http\_ybid", "-", "0"]  
}

```
if [http_ybid] != "0" {
      grok {
        match => ["http_ybid", "(?<ybid.sess>[^.]*)\.(?<ybid.trans>.*)" ]
      }
}

```

no real reliance on on -. so the move to 0 works. guess I could just test for -

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2019, 1:15am UTC](https://discuss.elastic.co/t/breaking-down-a-field/160023/5 "2019-01-07T01:15:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
