# Create fields when a word followed by ':'

**URL:** <https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164>\
**Category:** Logstash\
**Created:** [August 1, 2021, 8:23pm UTC](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164 "2021-08-01T20:23:27Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 1, 2021, 11:15pm UTC](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164/4 "2021-08-01T23:15:11Z")

</div>

OK, I would use ruby for that. Something like [this](https://discuss.elastic.co/t/how-to-split-the-one-field-into-multiple-fields-using-kv-plugins/172067/4). You would not need to grok, just the ruby filter and

```
m = event.get("message").scan(/(\w+):(\w+)/)
```

---

_[View the full topic](https://discuss.elastic.co/t/create-fields-when-a-word-followed-by/280164)._
