# Extract logs from the message field and create new separate runtime fields

**URL:** <https://discuss.elastic.co/t/extract-logs-from-the-message-field-and-create-new-separate-runtime-fields/320670>\
**Category:** Kibana\
**Tags:** runtime-fields\
**Created:** [December 7, 2022, 10:24am UTC](https://discuss.elastic.co/t/extract-logs-from-the-message-field-and-create-new-separate-runtime-fields/320670 "2022-12-07T10:24:20Z")\
**Posts on this page:** 1\
**Showing post:** 14

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [December 8, 2022, 12:14pm UTC](https://discuss.elastic.co/t/extract-logs-from-the-message-field-and-create-new-separate-runtime-fields/320670/14 "2022-12-08T12:14:53Z")

</div>

2 things we can do here:

- expand the time range via the time picker in the top right corner to see more results,
- check details of the shards failure via the button in the bottom right corner.

If the message field can be missing, then the script should be wrapped into an additional check:

```auto
if (doc["message.keyword"].size() > 0) {
  // ... the rest
  return;
}
emit("");

```

---

_[View the full topic](https://discuss.elastic.co/t/extract-logs-from-the-message-field-and-create-new-separate-runtime-fields/320670)._
