# Extract field from message field with in logs

**URL:** <https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908>\
**Category:** Logstash\
**Created:** [February 11, 2019, 5:59pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908 "2019-02-11T17:59:20Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ray\_zuniga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ray_zuniga/32/35823_2.png) [@ray\_zuniga](https://discuss.elastic.co/u/ray_zuniga)\
**Post date:** [February 11, 2019, 5:59pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/1 "2019-02-11T17:59:20Z")

</div>

im working with an elk stack that I did not deploy. I have an "index" for dns logs. it gives me a few default fields. The message field is given, but I noticed that the "client" and "query" with in it are things I would like to get a separate field for because they contain pertinent info. how would I add this ?  
what file would I edit to not he Logstash server to add those two "fields" /etc/logstash/conf.d/\* ?

the client field has the # sign added to it can I separate that ?  
Im an elk noob sorry

`message:<30>Feb 11 09:48:11 x.x.x.x named[22083]: client x.x.x.x#56007 (z03resources.renlearnrp.com): query: z03resources.renlearnrp.com IN A +ED (x.x.x.x)`

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [February 11, 2019, 11:20pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/2 "2019-02-11T23:20:25Z")

</div>

You'll need to inform whatever tool you're using to ingest that data how to break out those values. You mentioned Logstash, which is perfectly capable of doing this... but I don't know that tool so I can't really give you any assistance there. The best I can do is point you at [the log parsing docs](https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html). You probably just need to update the grok pattern you're using.

---

<div class="post-metadata">

**Author:** ![ray\_zuniga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ray_zuniga/32/35823_2.png) [@ray\_zuniga](https://discuss.elastic.co/u/ray_zuniga)\
**Post date:** [February 12, 2019, 9:39pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/3 "2019-02-12T21:39:40Z")

</div>

sorry moved it to Logstash forum instead of Kibana. but that thanks for the input

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2019, 10:29pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/4 "2019-02-12T22:29:29Z")

</div>

> [@ray\_zuniga](#):
>
> \<30\>Feb 11 09:48:11 x.x.x.x named[22083]: client x.x.x.x#56007 ([z03resources.renlearnrp.com](http://z03resources.renlearnrp.com)): query: [z03resources.renlearnrp.com](http://z03resources.renlearnrp.com) IN A +ED (x.x.x.x)

I would start by picking apart the syslog header.

```
    grok { match => ["message", "^<%{NUMBER:level}>%{SYSLOGTIMESTAMP:ts} %{IPV4:ip1} %{WORD:program}\[%{NUMBER:pid}\]: %{GREEDYDATA:restOfLine}" ] }

```

I'm not sure what fields you want from that message, but this should get you started.

```
    grok { match => ["restOfLine", "^%{WORD:something1} %{IPV4:ip2}#%{NUMBER:port} \(%{HOSTNAME:host1}\): (?<query>[^(]+)\(%{IPV4:ip3}\)" ] }

```

That gets me

```
   "program" => "named",
     "query" => "query: z03resources.renlearnrp.com IN A +ED ",
       "ip1" => "1.2.3.4",
        "ts" => "Feb 11 09:48:11",
       "ip2" => "5.6.7.8",
       "pid" => "22083",
     "host1" => "z03resources.renlearnrp.com",
     "level" => "30",
      "port" => "56007",
"something1" => "client"
       "ip3" => "8.1.2.4"

```

---

<div class="post-metadata">

**Author:** ![ray\_zuniga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ray_zuniga/32/35823_2.png) [@ray\_zuniga](https://discuss.elastic.co/u/ray_zuniga)\
**Post date:** [February 12, 2019, 10:46pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/5 "2019-02-12T22:46:58Z")

</div>

Thank you for the info much appreciated. This is deff something for me to go through . This would go in the `/etc/logstash/conf.f/*.filter.conf` file in logstash correct ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2019, 10:57pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/6 "2019-02-12T22:57:50Z")

</div>

Typically you would create a configuration file in /etc/logstash/conf.d and point logstash to the file using -f

---

<div class="post-metadata">

**Author:** ![ray\_zuniga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ray_zuniga/32/35823_2.png) [@ray\_zuniga](https://discuss.elastic.co/u/ray_zuniga)\
**Post date:** [February 15, 2019, 2:28am UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/7 "2019-02-15T02:28:02Z")

</div>

I normally just edit the files in there and sysctl restart logstash. is that not normal ?  
do I have to start logstash with a specific conf file every time ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 15, 2019, 1:20pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/8 "2019-02-15T13:20:32Z")

</div>

You can point -f at a specific file, or at a directory, in which case it will concatenate all the files in the directory to create a configuration. Whatever works for you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2019, 1:26pm UTC](https://discuss.elastic.co/t/extract-field-from-message-field-with-in-logs/167908/9 "2019-03-15T13:26:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
