# Extract substring of a log line

**URL:** <https://discuss.elastic.co/t/extract-substring-of-a-log-line/94788>\
**Category:** Logstash\
**Created:** [July 27, 2017, 12:39pm UTC](https://discuss.elastic.co/t/extract-substring-of-a-log-line/94788 "2017-07-27T12:39:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DFrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfrant/32/20512_2.png) [@DFrant](https://discuss.elastic.co/u/DFrant)\
**Post date:** [July 27, 2017, 12:39pm UTC](https://discuss.elastic.co/t/extract-substring-of-a-log-line/94788/1 "2017-07-27T12:39:37Z")

</div>

Hello,

I have some logs lines wich are only one string, for example :

> 01999918000170702135929%WS%00000000000070030819078820913135929050000080RRN0002W900500000000C0000000000000500024464063100100 03081907882 300 R00

I would know how it is possible to use a filter to extract field from this string using char index.  
For example:

ID = substring(0,11)  
date = substring(11, 17)  
etc...

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 28, 2017, 3:24am UTC](https://discuss.elastic.co/t/extract-substring-of-a-log-line/94788/2 "2017-07-28T03:24:23Z")

</div>

Maybe you can use the ruby filter to do that.

Should be something like this

```auto
filter {
    ruby {
        code => "
             event.set('ID', event.get('message')[0..11])
             event.set('date', event.get('message')[12..17])
        "
    }
} 

```

This way a field called ID will receive the substring for 0 to 11 from the source field message, which countains your log line, the same for the field date.

I was not able to test this yet, but in theory this should work.

You can read more of the ruby filter [here](https://www.elastic.co/guide/en/logstash/5.5/event-api.html)

---

<div class="post-metadata">

**Author:** ![DFrant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dfrant/32/20512_2.png) [@DFrant](https://discuss.elastic.co/u/DFrant)\
**Post date:** [July 28, 2017, 10:28am UTC](https://discuss.elastic.co/t/extract-substring-of-a-log-line/94788/3 "2017-07-28T10:28:24Z")

</div>

Thanks for your answer.

I proceed with pattern matching and regex to proceed:

I defined patterns that i want to match with my log line:

```
ID (^.{0}.{11})
TESTTIMESTAMP (.{12})
...

```

And in my pattern matcher I did:

```
 match => { "message" => "%{ID:id}%{DATE:date}..."}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2017, 10:28am UTC](https://discuss.elastic.co/t/extract-substring-of-a-log-line/94788/4 "2017-08-25T10:28:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
