# Extract data with a Scripted Field - get domain name from URL string?

**URL:** <https://discuss.elastic.co/t/extract-data-with-a-scripted-field-get-domain-name-from-url-string/61746>\
**Category:** Kibana\
**Created:** [September 28, 2016, 9:45pm UTC](https://discuss.elastic.co/t/extract-data-with-a-scripted-field-get-domain-name-from-url-string/61746 "2016-09-28T21:45:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Grant\_Griffith](https://avatars.discourse-cdn.com/v4/letter/g/e9a140/32.png) [@Grant\_Griffith](https://discuss.elastic.co/u/Grant_Griffith)\
**Post date:** [September 28, 2016, 9:45pm UTC](https://discuss.elastic.co/t/extract-data-with-a-scripted-field-get-domain-name-from-url-string/61746/1 "2016-09-28T21:45:38Z")

</div>

Hey everyone, I'm using an ELK stack for our bind (DNS) query logs and would like to create a "Top Domains" visualization which I can almost do with the full 'dns\_dest' field. But, I don't want the full URL of the lookup, just the domain name.

Can I use a scripted field to create a new field with the domain? It's just for visualization purposes (I think) so a scripted field might do the trick.

Would it be more efficient to have Logstash do this with a filter?

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [September 30, 2016, 2:43am UTC](https://discuss.elastic.co/t/extract-data-with-a-scripted-field-get-domain-name-from-url-string/61746/2 "2016-09-30T02:43:27Z")

</div>

Hi Grant,

The flippant answer is yes, this would be more efficient with logstash.

The more considerate answer is the following. You can do that with scripted fields, but you'll want to use the painless or groovy language for that. In Kibana 4, you can only write numerical expressions, so that probably won't help you. In Kibana 5 beta, with painless or groovy, you can do string operations.

So I think it depends. If you can use logstash to parse it out, do that, it will have better performance. If not, Kibana 5 allows you to write scripted fields where you can parse text.

---

<div class="post-metadata">

**Author:** ![tbragin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tbragin/32/45166_2.png) [@tbragin](https://discuss.elastic.co/u/tbragin)\
**Post date:** [December 13, 2016, 8:14pm UTC](https://discuss.elastic.co/t/extract-data-with-a-scripted-field-get-domain-name-from-url-string/61746/3 "2016-12-13T20:14:48Z")

</div>

Btw, don't use Groovy, because it deprecated and will be removed in 6.0. Stick with Painless if you decide to do something advanced with scripted fields. If interested, here is a blog that walks you through what to do there: [https://www.elastic.co/blog/using-painless-kibana-scripted-fields](https://www.elastic.co/blog/using-painless-kibana-scripted-fields)

However, if you know you need a field ahead of time, just parse it with Logstash. I'd reserve scripted fields for experimentation when the fields you need _right now_ are simply not there, but once they are confirmed as useful, i'd go back to the datasource and index them directly to avoid on-search performance hit.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:33pm UTC](https://discuss.elastic.co/t/extract-data-with-a-scripted-field-get-domain-name-from-url-string/61746/4 "2017-07-06T13:33:45Z")

</div>


