# Extract a specific field from a string

**URL:** <https://discuss.elastic.co/t/extract-a-specific-field-from-a-string/377618>\
**Category:** Logstash\
**Created:** [April 29, 2025, 12:25pm UTC](https://discuss.elastic.co/t/extract-a-specific-field-from-a-string/377618 "2025-04-29T12:25:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stanislavcik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stanislavcik/32/142875_2.png) [@stanislavcik](https://discuss.elastic.co/u/stanislavcik)\
**Post date:** [April 29, 2025, 12:25pm UTC](https://discuss.elastic.co/t/extract-a-specific-field-from-a-string/377618/1 "2025-04-29T12:25:26Z")

</div>

How to extract a specific field from a string if the string length varies?

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [April 29, 2025, 12:27pm UTC](https://discuss.elastic.co/t/extract-a-specific-field-from-a-string/377618/2 "2025-04-29T12:27:39Z")

</div>

Welcome @stanislavcik!

Does your field have a particular pattern or separator? If so it should be possible using a [grok filter](https://www.elastic.co/docs/reference/logstash/plugins/plugins-filters-grok).

If you have an example that you're trying to parse it would be useful to see to help further.

Let us know!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 29, 2025, 1:19pm UTC](https://discuss.elastic.co/t/extract-a-specific-field-from-a-string/377618/3 "2025-04-29T13:19:58Z")

</div>

Also you can use mutate-gsub. In both case, grok or gsub, you should use a regex pattern.
