# Exec command Linux and extract specific field

**URL:** <https://discuss.elastic.co/t/exec-command-linux-and-extract-specific-field/283254>\
**Category:** Logstash\
**Created:** [September 3, 2021, 7:37am UTC](https://discuss.elastic.co/t/exec-command-linux-and-extract-specific-field/283254 "2021-09-03T07:37:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mira\_9](https://avatars.discourse-cdn.com/v4/letter/m/cdc98d/32.png) [@Mira\_9](https://discuss.elastic.co/u/Mira_9)\
**Post date:** [September 3, 2021, 7:37am UTC](https://discuss.elastic.co/t/exec-command-linux-and-extract-specific-field/283254/1 "2021-09-03T07:37:21Z")

</div>

Hi Community, i'm executing several linux commands in Logstash. and i want to extract specific fields to build some graphs in Kibana. for Example this is the result of an executed command

```auto
[2021-02-13 19:28:49.200] chan dur ibss obss interf time
[2021-02-13 19:28:49.216] 36 1599 13 0% Low 4 0% Low 0 0% Low 311143

```

How can i use the field " interf" and its value " 0 0% Low" to build a chart with timestamp axe?  
Thank you!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 3, 2021, 4:30pm UTC](https://discuss.elastic.co/t/exec-command-linux-and-extract-specific-field/283254/2 "2021-09-03T16:30:25Z")

</div>

My understanding is that the channel is printed left-adjusted (%-3u), so there will always be a space in front of it. You will need a grok specific to the line format. In this case

```
    if [message] =~ /obss/ { drop {} }
    grok { match => { "message" => "^\[%{TIMESTAMP_ISO8601:[@metadata][timestamp]}\] %{NUMBER:chanspec:int}\s+%{NUMBER:duration:int}\s+%{NUMBER}\s+%{NUMBER}%\s+%{WORD}\s+%{NUMBER:obssCongest:int}\s+%{NUMBER:obssPercent:int}%\s+%{WORD:obssLevel}\s+%{NUMBER:f9:int}\s+%{NUMBER:f10:int}%\s+%{WORD:f11}\s+%{NUMBER:f12:int}" } }
    date { match => ["[@metadata][timestamp]", ISO8601 ] }

```

will produce

```
"obssPercent" => 0,
  "obssLevel" => "Low",
        "f10" => 0,
        "f12" => 311143,
   "chanspec" => 36,
   "duration" => 1599,
        "f11" => "Low",
 "@timestamp" => 2021-02-14T00:28:49.216Z,
         "f9" => 0,
"obssCongest" => 4,
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 6, 2021, 2:13pm UTC](https://discuss.elastic.co/t/exec-command-linux-and-extract-specific-field/283254/4 "2021-09-06T14:13:17Z")

</div>

Your [message] field has leading spaces so you would need to replace the ^ in the grok pattern with ^\s+

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2021, 2:47pm UTC](https://discuss.elastic.co/t/exec-command-linux-and-extract-specific-field/283254/6 "2021-10-04T14:47:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
