# Extract string from message field kibana

**URL:** <https://discuss.elastic.co/t/extract-string-from-message-field-kibana/116549>\
**Category:** Kibana\
**Created:** [January 22, 2018, 10:52pm UTC](https://discuss.elastic.co/t/extract-string-from-message-field-kibana/116549 "2018-01-22T22:52:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![saikrishnagaddipati](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@saikrishnagaddipati](https://discuss.elastic.co/u/saikrishnagaddipati)\
**Post date:** [January 22, 2018, 10:52pm UTC](https://discuss.elastic.co/t/extract-string-from-message-field-kibana/116549/1 "2018-01-22T22:52:58Z")

</div>

I am using kibana-5.6.3  
I have messages populating in kibana. I have the message in kibana as bleow  
`1330207 Backup host-44 Done **0** 2 fit-dev host-44 01/11/2018 18:00:02 01/11/2018 18:03:28 000:03:26`

I want to extract number "0" located at 5th position in the message and add it as new field  
How to do this on kibana side?

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [January 24, 2018, 3:38pm UTC](https://discuss.elastic.co/t/extract-string-from-message-field-kibana/116549/2 "2018-01-24T15:38:22Z")

</div>

You would need to extract fields from `message` before storing the documents in Elastic Search. [Logstash](https://www.elastic.co/products/logstash) provides a rich feature set that is designed to read events from a data source(s), transform each event, and then send the transformed event to Elastic Search.

Nathan

---

<div class="post-metadata">

**Author:** ![saikrishnagaddipati](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@saikrishnagaddipati](https://discuss.elastic.co/u/saikrishnagaddipati)\
**Post date:** [January 24, 2018, 4:07pm UTC](https://discuss.elastic.co/t/extract-string-from-message-field-kibana/116549/3 "2018-01-24T16:07:23Z")

</div>

@Nathan_Reese  
I am using logstaah 5.6.4  
I am trying to parse the below message field in logstash and add a field "error\_code" but logstash adds all the fields(bytes, syslog\_hostname, method, method2). How to configure logstash to stop adding the unwanted fields?  
message: 1332414 Backup hgnmowi88-ben Done 0 16142082 idk-dev-db Prod-Differential host-ben

and my logstash confi is below

if [type] == "hostup" {  
grok {  
match =\> { "message" =\> "%{NUMBER:bytes}\s\*%{WORD:method}\s\*%{SYSLOGHOST:syslog\_hostname}\s\*%{WORD:method2}\s\*%{INT:number}\s\*%{INT:number2}\s\*%{USERNAME:user\_id}\s\*%{SYSLOGHOST:syslog\_hostname2}"}  
add\_field =\> { "error\_code" =\> "%{number}"}  
}  
}

---

<div class="post-metadata">

**Author:** ![Nathan\_Reese](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nathan_reese/32/84829_2.png) [@Nathan\_Reese](https://discuss.elastic.co/u/Nathan_Reese)\
**Post date:** [January 24, 2018, 4:29pm UTC](https://discuss.elastic.co/t/extract-string-from-message-field-kibana/116549/4 "2018-01-24T16:29:10Z")

</div>

In your logstash configuration `filter` section, add the following

```auto
  mutate {
    remove_field => ["bytes", "syslog_hostname", "method", "method2"]
  }

```

---

<div class="post-metadata">

**Author:** ![saikrishnagaddipati](https://avatars.discourse-cdn.com/v4/letter/s/7ea924/32.png) [@saikrishnagaddipati](https://discuss.elastic.co/u/saikrishnagaddipati)\
**Post date:** [January 24, 2018, 5:20pm UTC](https://discuss.elastic.co/t/extract-string-from-message-field-kibana/116549/5 "2018-01-24T17:20:13Z")

</div>

@Nathan_Reese how to parse a tab seperated message as below  
message: 1332414 Backup hgnmowi88-ben Done 0 16142082 idk-dev-db Prod-Differential hqidwinfmd03-ben

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2018, 5:20pm UTC](https://discuss.elastic.co/t/extract-string-from-message-field-kibana/116549/6 "2018-02-21T17:20:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
