# Dynamic field creation using regex and scripted fields

**URL:** <https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312>\
**Category:** Kibana\
**Created:** [May 6, 2015, 7:12pm UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312 "2015-05-06T19:12:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![esiegel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/esiegel/32/44911_2.png) [@esiegel](https://discuss.elastic.co/u/esiegel)\
**Post date:** [May 6, 2015, 7:12pm UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312/1 "2015-05-06T19:12:40Z")

</div>

I'm wondering if scripted fields could help me with dynamically generating kibana fields.

A small subset of my logs follows the format:  
message: "My awesome thing that I just did (10ms)"

I'd like to query for all logs where the message field begins with "My awesome thing", and then extract the duration and graph the results.

I could update logstash to add this magic field, but I'd much rather do this dynamically as the result set will be small and I don't think this is a typical use case.

---

<div class="post-metadata">

**Author:** ![rashid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashid/32/12566_2.png) [@rashid](https://discuss.elastic.co/u/rashid)\
**Post date:** [May 7, 2015, 4:45pm UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312/2 "2015-05-07T16:45:30Z")

</div>

Query time field extraction is unfortunately not currently possible in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![kmrdiscuss](https://avatars.discourse-cdn.com/v4/letter/k/db5fbb/32.png) [@kmrdiscuss](https://discuss.elastic.co/u/kmrdiscuss)\
**Post date:** [May 13, 2015, 6:32pm UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312/3 "2015-05-13T18:32:08Z")

</div>

Could this be done using a function\_score block and script\_field?

---

<div class="post-metadata">

**Author:** ![rashid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashid/32/12566_2.png) [@rashid](https://discuss.elastic.co/u/rashid)\
**Post date:** [May 13, 2015, 6:43pm UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312/4 "2015-05-13T18:43:56Z")

</div>

Currently kibana only supports lucene expressions in script fields, for security reasons. Lucene expressions unfortunately only support numbers, we're working to bring string support to them

---

<div class="post-metadata">

**Author:** ![Cesar\_Augusto\_Ribeir](https://avatars.discourse-cdn.com/v4/letter/c/bc8723/32.png) [@Cesar\_Augusto\_Ribeir](https://discuss.elastic.co/u/Cesar_Augusto_Ribeir)\
**Post date:** [October 15, 2015, 6:59pm UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312/5 "2015-10-15T18:59:53Z")

</div>

I'm totally new to this but found this [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok) stuff. Seems that it can extract "new fields" like you want.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [October 19, 2015, 4:03am UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312/6 "2015-10-19T04:03:49Z")

</div>

It does, but it needs to happen in Logstash, which is a step you do prior to indexing in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![tanbamboo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tanbamboo/32/11158_2.png) [@tanbamboo](https://discuss.elastic.co/u/tanbamboo)\
**Post date:** [August 2, 2016, 9:42am UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312/7 "2016-08-02T09:42:44Z")

</div>

Does Elasticsearch 5.0 support this feature?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:42pm UTC](https://discuss.elastic.co/t/dynamic-field-creation-using-regex-and-scripted-fields/312/8 "2017-07-06T13:42:26Z")

</div>


