# Create a new filed from a string field in painless script/ Substing in painless

**URL:** <https://discuss.elastic.co/t/create-a-new-filed-from-a-string-field-in-painless-script-substing-in-painless/159871>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 7, 2018, 7:49am UTC](https://discuss.elastic.co/t/create-a-new-filed-from-a-string-field-in-painless-script-substing-in-painless/159871 "2018-12-07T07:49:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sid\_nikhil](https://avatars.discourse-cdn.com/v4/letter/s/f9ae1b/32.png) [@sid\_nikhil](https://discuss.elastic.co/u/sid_nikhil)\
**Post date:** [December 7, 2018, 7:49am UTC](https://discuss.elastic.co/t/create-a-new-filed-from-a-string-field-in-painless-script-substing-in-painless/159871/1 "2018-12-07T07:49:31Z")

</div>

I have a string field **message** in filebeats index

message : "2018-12-07 00:42:57,797;INFO ;ATDSDSFCMTWB03.6612.38.0.0a7eec05-287d-462e-b2b5-bab666ee33e6;1;0;;GetSiteDetailsHandler;2;"

I need to split the string & extract the last integer(which is 2 here) and assign it to a new field .

I know we need to use scripted field(painless script) for this case .

Can someone please suggest painless script query to do this.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 11, 2018, 1:43am UTC](https://discuss.elastic.co/t/create-a-new-filed-from-a-string-field-in-painless-script-substing-in-painless/159871/2 "2018-12-11T01:43:38Z")

</div>

I would suggest you split up the message while ingesting events using Filebeat into Elasticsearch. To do this, you will first want to define an Elasticsearch Ingest Node pipeline with the right sequence of processors to perform the splitting of the `message` field and extraction of the last field from the resulting array. Then you will want to reference this pipeline in your `filebeat.yml` via the `output.elasticsearch.pipeline` setting.

To learn more, start with these docs: [https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ingest-node.html](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-ingest-node.html) and [https://www.elastic.co/guide/en/elasticsearch/reference/current/split-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/split-processor.html).

---

<div class="post-metadata">

**Author:** ![sid\_nikhil](https://avatars.discourse-cdn.com/v4/letter/s/f9ae1b/32.png) [@sid\_nikhil](https://discuss.elastic.co/u/sid_nikhil)\
**Post date:** [December 11, 2018, 4:51am UTC](https://discuss.elastic.co/t/create-a-new-filed-from-a-string-field-in-painless-script-substing-in-painless/159871/3 "2018-12-11T04:51:12Z")

</div>

Thanks I will try this .  
Could you please answer this question  
[https://discuss.elastic.co/t/automatically-delete-1-month-old-documents-without-deleting-index-in-elastic-search-kibana/160041/2](https://discuss.elastic.co/t/automatically-delete-1-month-old-documents-without-deleting-index-in-elastic-search-kibana/160041/2)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2019, 4:51am UTC](https://discuss.elastic.co/t/create-a-new-filed-from-a-string-field-in-painless-script-substing-in-painless/159871/4 "2019-01-08T04:51:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
