# Extract certain values from Url.Query field

**URL:** <https://discuss.elastic.co/t/extract-certain-values-from-url-query-field/265633>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 26, 2021, 4:24pm UTC](https://discuss.elastic.co/t/extract-certain-values-from-url-query-field/265633 "2021-02-26T16:24:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamesm1](https://avatars.discourse-cdn.com/v4/letter/j/ce7236/32.png) [@jamesm1](https://discuss.elastic.co/u/jamesm1)\
**Post date:** [February 26, 2021, 4:24pm UTC](https://discuss.elastic.co/t/extract-certain-values-from-url-query-field/265633/1 "2021-02-26T16:24:53Z")

</div>

I currently have a Fleet module set up to ingest IIS logs into Kibana.  
Within the logs they contain the filed URL.Query, which holds alot of information.  
What i would like to do is to turn all of the parameters inside the URL.Query into fields themselves. For instance  
gameId=759&gameSessionId=3358711541

I would like to be able to see "gameId" and "GameSessionId" as fields.

I can see a similar question posted on

> [@How to Parse url.query into Different Fields?](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920/2):
>
> Hello, thanks for the question about filebeat. In your configuration, is filebeat shipping directly to elasticsearch, or does filebeat first ship data to logstash for enrichment or filtering. If you're using logstash, this could be a possible good portion of the pipeline to split about the url.query string. If you're using logstash, I would recommend looking at the grok filter plugin: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)

However there is no answer on this. Could someone please provide some information or advice, thank you :).

Not sure if this is important, but the agent.type is "filebeats"

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [March 1, 2021, 9:49am UTC](https://discuss.elastic.co/t/extract-certain-values-from-url-query-field/265633/2 "2021-03-01T09:49:52Z")

</div>

I think you can open an enhancement request (issue) in the elastic/integrations repo. It would be a nice improvement.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2021, 11:50am UTC](https://discuss.elastic.co/t/extract-certain-values-from-url-query-field/265633/3 "2021-03-29T11:50:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
