# Create fields when a word followed by ':'

**URL:** <https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164>\
**Category:** Logstash\
**Created:** [August 1, 2021, 8:23pm UTC](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164 "2021-08-01T20:23:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arkapravo\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arkapravo_das/32/78953_2.png) [@Arkapravo\_Das](https://discuss.elastic.co/u/Arkapravo_Das)\
**Post date:** [August 1, 2021, 8:23pm UTC](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164/1 "2021-08-01T20:23:27Z")

</div>

Hi,  
What I am trying to do is , if the unformatted text is like

`updating demand record with key:202107231924440412212356|current demand quantity:1|quantity getting reduced:1|shipmentno:170801380`

then I want to create field like key,quantity, shipmentno. I don't want to predefine the fields. This will help me to run stats on some unformatted logs for a specific field, lets say 'shipmentno'

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 1, 2021, 10:02pm UTC](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164/2 "2021-08-01T22:02:42Z")

</div>

You could try something like

```
dissect { mapping => { "message" => "updating demand record with %{[@metadata][restOfLine]" } }
kv { field_split => "|" value_split => ":" }
```

---

<div class="post-metadata">

**Author:** ![Arkapravo\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arkapravo_das/32/78953_2.png) [@Arkapravo\_Das](https://discuss.elastic.co/u/Arkapravo_Das)\
**Post date:** [August 1, 2021, 10:21pm UTC](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164/3 "2021-08-01T22:21:00Z")

</div>

Actually the string might change. As an example lets say,

1st String is: Creating ShipmentNo:1234  
2nd string is: Processing ShipmentNo:1234  
3rd string can be : Reducing demand for ShipmentNo:1234 and reduced Quantity:2

In all the above cases, I want a ShipmentNo field getting populated. I can't predefine what will be the format of the string or what are the fields expected. All I want to declare is, if logstash finds a ':' operator, then the word appears before ':' needs to be the field name and word follows the ':' needs to be the value.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 1, 2021, 11:15pm UTC](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164/4 "2021-08-01T23:15:11Z")

</div>

OK, I would use ruby for that. Something like [this](https://discuss.elastic.co/t/how-to-split-the-one-field-into-multiple-fields-using-kv-plugins/172067/4). You would not need to grok, just the ruby filter and

```
m = event.get("message").scan(/(\w+):(\w+)/)
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2021, 11:15pm UTC](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164/5 "2021-08-29T23:15:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
