# Extract strings from one field

**URL:** <https://discuss.elastic.co/t/extract-strings-from-one-field/24637>\
**Category:** Logstash\
**Created:** [June 30, 2015, 3:29pm UTC](https://discuss.elastic.co/t/extract-strings-from-one-field/24637 "2015-06-30T15:29:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [June 30, 2015, 3:29pm UTC](https://discuss.elastic.co/t/extract-strings-from-one-field/24637/1 "2015-06-30T15:29:54Z")

</div>

After successfully parsing out this field from my log files, I want to extract information from this field and store it as a separate field, I looked through lots of the filters and didn't find one that serves this purpose, the field looks like this:

/content/folder[@name='\***_', Inc (t0030427da5p)']/reportView[@name='_** \*\*\*\* \*\* \*\*\*\* \*\* \*\*\* \*\*\*\*\*\*\*']

It should be like a path(text replaced by stars for company's sake), I want information between the bracket, or even better the two names(represented by stars). Any hints would be really appreciated \<:

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 30, 2015, 8:30pm UTC](https://discuss.elastic.co/t/extract-strings-from-one-field/24637/2 "2015-06-30T20:30:03Z")

</div>

Use the grok filter. I'm not 100% sure what result you expect from the example input string, but if you want the text inside the two single-quoted strings the following should work:

```
grok {
  match => [
    "name-of-field",
    "@name='(?<name1>[^']+)'.*@name='(?<name2>[^']+)'"
  ]
]

```

If the single-quoted strings themselves can contain single quotes that are escaped somehow it'll take some more care.

---

<div class="post-metadata">

**Author:** ![DavidL](https://avatars.discourse-cdn.com/v4/letter/d/ecc23a/32.png) [@DavidL](https://discuss.elastic.co/u/DavidL)\
**Post date:** [June 30, 2015, 10:08pm UTC](https://discuss.elastic.co/t/extract-strings-from-one-field/24637/3 "2015-06-30T22:08:45Z")

</div>

Thank you magnus, you are great. I did came up with my own grok but yours is much prettier.

David

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/extract-strings-from-one-field/24637/4 "2017-07-06T05:35:54Z")

</div>


