# Extract value from message field ( runtime fields)

**URL:** https://discuss.elastic.co/t/extract-value-from-message-field-runtime-fields/311679
**Category:** Elasticsearch
**Created:** [August 8, 2022, 10:57pm UTC](https://discuss.elastic.co/t/extract-value-from-message-field-runtime-fields/311679 "2022-08-08T22:57:14Z")
**Posts on this page:** 1
**Showing post:** 23

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [August 10, 2022, 1:57am UTC](https://discuss.elastic.co/t/extract-value-from-message-field-runtime-fields/311679/23 "2022-08-10T01:57:34Z")

</div>

@jplopezy Look

**OHHHHH i may have found a** way using the `_source`

> However, there are cases where retrieving fields from `_source` is necessary. For example, `text` fields do not have `doc_values` available by default, so you have to retrieve values from `_source` . In other instances, you might choose to disable `doc_values` on a specific field.

**it will not be efficient and I would not recommend at scale...**

Try this as the code in the runtime field

```auto
String username=grok('%{GREEDYDATA:leading_data}/CN=%{DATA:username}\'').extract(params._source.message)?.username;
if (username != null) emit(username); 

```

---

_[View the full topic](https://discuss.elastic.co/t/extract-value-from-message-field-runtime-fields/311679)._
