# Extract fields from kibana logs

**URL:** <https://discuss.elastic.co/t/extract-fields-from-kibana-logs/266511>\
**Category:** Kibana\
**Created:** [March 8, 2021, 6:19am UTC](https://discuss.elastic.co/t/extract-fields-from-kibana-logs/266511 "2021-03-08T06:19:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![aagarwal3](https://avatars.discourse-cdn.com/v4/letter/a/ee7513/32.png) [@aagarwal3](https://discuss.elastic.co/u/aagarwal3)\
**Post date:** [March 8, 2021, 6:19am UTC](https://discuss.elastic.co/t/extract-fields-from-kibana-logs/266511/1 "2021-03-08T06:19:20Z")

</div>

I have the Status Code in `log` field only on kibana logs which I want to extract.  
Is there any way in which we can parse the `log` field from Kibana itself?

```auto
"2021-03-08 06:16:16.631 INFO ; Status_Code=200; Response_Body={sometext};\n"

```

thanks

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [March 8, 2021, 3:21pm UTC](https://discuss.elastic.co/t/extract-fields-from-kibana-logs/266511/2 "2021-03-08T15:21:10Z")

</div>

@aagarwal3

Are you ingesting these logs with another tool, and index each log line as a document into Elasticsearch?

Reading out `Status_Code=XXX` should be possible with the grok filter from logstash [Grok filter plugin | Logstash Reference [7.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) . You would just look for the `Status_Code={code}` pattern.

---

<div class="post-metadata">

**Author:** ![aagarwal3](https://avatars.discourse-cdn.com/v4/letter/a/ee7513/32.png) [@aagarwal3](https://discuss.elastic.co/u/aagarwal3)\
**Post date:** [March 8, 2021, 5:35pm UTC](https://discuss.elastic.co/t/extract-fields-from-kibana-logs/266511/3 "2021-03-08T17:35:03Z")

</div>

Can this be done once the logs are already in kibana dev tools though?

---

<div class="post-metadata">

**Author:** ![thomasneirynck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thomasneirynck/32/23313_2.png) [@thomasneirynck](https://discuss.elastic.co/u/thomasneirynck)\
**Post date:** [March 8, 2021, 5:59pm UTC](https://discuss.elastic.co/t/extract-fields-from-kibana-logs/266511/4 "2021-03-08T17:59:10Z")

</div>

@aagarwal3 no, using grok is something you would do at ingest time. Apart from logstch, you could also use the grok-processor: [Grok processor | Elasticsearch Reference [master] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/grok-processor.html) This would be the preferred solution.

To do this at runtime, you can look to write a scripted-field, and use the Painless-programming language to parse out that status-code. [Scripted fields | Kibana Guide [7.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/scripted-fields.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2021, 5:59pm UTC](https://discuss.elastic.co/t/extract-fields-from-kibana-logs/266511/5 "2021-04-05T17:59:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
