# Doubts about extract field

**URL:** https://discuss.elastic.co/t/doubts-about-extract-field/252558
**Category:** Logstash
**Created:** [October 19, 2020, 2:02pm UTC](https://discuss.elastic.co/t/doubts-about-extract-field/252558 "2020-10-19T14:02:15Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![rildo](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@rildo](https://discuss.elastic.co/u/rildo)
#### Post date: [October 19, 2020, 2:02pm UTC](https://discuss.elastic.co/t/doubts-about-extract-field/252558/1 "2020-10-19T14:02:15Z")

</div>

Hello People ,

I have this code

´ ´ ´  
input {  
stdin { }  
}

output { stdout { codec =\> rubydebug } }

filter {  
json {  
source =\> "message"  
}

# mutate {

# gsub =\> ["message" , "\n", ","] }

mutate {  
gsub =\> ["message" , "[\]", "" ]  
gsub =\> ["other\_logs" , "[\\n]", "," ]  
split =\> ["other\_logs" , ","]  
add\_field =\> { "Client SSH" =\> "%{[other\_logs][2]}" }  
add\_field =\> { "User" =\> "%{[other\_logs][3]}" }  
add\_field =\> { "Password" =\> "%{[other\_logs][4]}" }  
}  
}

´ ´ ´  
My output is something like that

´ ´ ´  
"aka\_vulnerability" =\> false,  
"Password" =\> "Password:packet",  
"Client SSH" =\> "Client SSH:SSH-2.0-libssh-0.6.3",  
"service" =\> "ssh",  
"timestamp" =\> "2020-07-02 08:00:10",  
"host" =\> "xyz",  
"@version" =\> "1",  
"target\_ips" =\> {  
"1.1.1.1" =\> {  
"port" =\> "22"  
}  
},  
"message" =\> "{"aka\_vulnerability": false, "service": "ssh", "timestamp": "2020-07-02 08:00:10", "target\_ips": {"1.1.1.1": {"port": "22"}}, "source\_ip": "2.2.2.2", "other\_logs": "Start Attack:"2020-07-02 08:00:10"nEnd Attack:"2020-07-02 08:00:10"nClient SSH:SSH-2.0-libssh-0.6.3nUser:packetnPassword:packet", "source\_hostname": "-", "source\_port": "11818", "subject": "Brute Force"}",  
"subject" =\> "Brute Force",  
"User" =\> "User:packet",  
"source\_hostname" =\> "-",  
"other\_logs" =\> [  
[0] "Start Attack:"2020-07-02 08:00:10"",  
[1] "End Attack:"2020-07-02 08:00:10"",  
[2] "Client SSH:SSH-2.0-libssh-0.6.3",  
[3] "User:packet",  
[4] "Password:packet"  
],

´ ´ ´  
I would like that my fields "User" and "Password" were printed as follows

"User" =\> "packet"  
"Password" =\> "packet"

It is, without the name of field as below

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [October 19, 2020, 5:36pm UTC](https://discuss.elastic.co/t/doubts-about-extract-field/252558/2 "2020-10-19T17:36:19Z")

</div>

In a separate gsub, after the gsub that adds the fields, remove the prefix.

```
mutate { gsub => ["User", "User:", "", "Password", "Password:", ""] }
```

---

<div class="post-metadata">

### Author: ![rildo](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@rildo](https://discuss.elastic.co/u/rildo)
#### Post date: [October 19, 2020, 6:31pm UTC](https://discuss.elastic.co/t/doubts-about-extract-field/252558/3 "2020-10-19T18:31:34Z")

</div>

Thank you Badger for your answer

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 16, 2020, 6:31pm UTC](https://discuss.elastic.co/t/doubts-about-extract-field/252558/4 "2020-11-16T18:31:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
