# Extract field from source

**URL:** <https://discuss.elastic.co/t/extract-field-from-source/126984>\
**Category:** Logstash\
**Created:** [April 5, 2018, 6:44pm UTC](https://discuss.elastic.co/t/extract-field-from-source/126984 "2018-04-05T18:44:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![las](https://avatars.discourse-cdn.com/v4/letter/l/5f9b8f/32.png) [@las](https://discuss.elastic.co/u/las)\
**Post date:** [April 5, 2018, 6:44pm UTC](https://discuss.elastic.co/t/extract-field-from-source/126984/1 "2018-04-05T18:44:44Z")

</div>

The event from filebeat contains the source field which contains the log filename. How do I use grok to extract some data from it?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 5, 2018, 7:35pm UTC](https://discuss.elastic.co/t/extract-field-from-source/126984/2 "2018-04-05T19:35:09Z")

</div>

Just use grok as you normally would, except that you configure it to parse the `source` field rather than the usual `message` field.

If you want a concrete example you'll have to tell us what "some data" is.

---

<div class="post-metadata">

**Author:** ![las](https://avatars.discourse-cdn.com/v4/letter/l/5f9b8f/32.png) [@las](https://discuss.elastic.co/u/las)\
**Post date:** [April 5, 2018, 7:56pm UTC](https://discuss.elastic.co/t/extract-field-from-source/126984/3 "2018-04-05T19:56:38Z")

</div>

I get grokparsefailure tags but I don't see any logs in console or in the file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 5, 2018, 8:06pm UTC](https://discuss.elastic.co/t/extract-field-from-source/126984/4 "2018-04-05T20:06:31Z")

</div>

Show us your config and what an event produced by Logstash looks like. Use a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

**Author:** ![las](https://avatars.discourse-cdn.com/v4/letter/l/5f9b8f/32.png) [@las](https://discuss.elastic.co/u/las)\
**Post date:** [April 5, 2018, 8:22pm UTC](https://discuss.elastic.co/t/extract-field-from-source/126984/5 "2018-04-05T20:22:06Z")

</div>

I see time in 20180101 12:34:56.1234 format. I tried pattern yyyyMMdd HH:mm:ss.SSSS and I am getting dateparsefailure. What pattern can I use?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 6, 2018, 6:12am UTC](https://discuss.elastic.co/t/extract-field-from-source/126984/6 "2018-04-06T06:12:11Z")

</div>

When the date filter fails it'll log details in the Logstash log.

---

<div class="post-metadata">

**Author:** ![las](https://avatars.discourse-cdn.com/v4/letter/l/5f9b8f/32.png) [@las](https://discuss.elastic.co/u/las)\
**Post date:** [April 6, 2018, 12:50pm UTC](https://discuss.elastic.co/t/extract-field-from-source/126984/7 "2018-04-06T12:50:03Z")

</div>

I'm not getting any error logs. I tried changing log4j properties also. Mine is a Windows installation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2018, 12:50pm UTC](https://discuss.elastic.co/t/extract-field-from-source/126984/8 "2018-05-04T12:50:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
