# Extracting counts of given nos from message field

**URL:** <https://discuss.elastic.co/t/extracting-counts-of-given-nos-from-message-field/92251>\
**Category:** Elasticsearch\
**Created:** [July 7, 2017, 10:18am UTC](https://discuss.elastic.co/t/extracting-counts-of-given-nos-from-message-field/92251 "2017-07-07T10:18:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suman\_Saha](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@Suman\_Saha](https://discuss.elastic.co/u/Suman_Saha)\
**Post date:** [July 7, 2017, 10:18am UTC](https://discuss.elastic.co/t/extracting-counts-of-given-nos-from-message-field/92251/1 "2017-07-07T10:18:20Z")

</div>

Hi ,  
We are using kibana 4 as container on openshift , now we want to generate graph from below messages generated on messages field '### 1.460 seconds process time ' .We want pull out the numeric value( like 1.460 here ) only for this 'process time' content messages and from this message we want to make a graph hourly .

How to extract this numeric value from this message ?

---

<div class="post-metadata">

**Author:** ![jimczi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jimczi/32/47985_2.png) [@jimczi](https://discuss.elastic.co/u/jimczi)\
**Post date:** [July 7, 2017, 12:30pm UTC](https://discuss.elastic.co/t/extracting-counts-of-given-nos-from-message-field/92251/2 "2017-07-07T12:30:26Z")

</div>

You could use a script that tries to extract the number from the string but it will be slow. You should rather try to do that at indexing time by extracting the number from the string field and put it in a new field `duration`. Then in Kibana you can generate a graph for this field directly.

---

<div class="post-metadata">

**Author:** ![Suman\_Saha](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@Suman\_Saha](https://discuss.elastic.co/u/Suman_Saha)\
**Post date:** [July 10, 2017, 7:47am UTC](https://discuss.elastic.co/t/extracting-counts-of-given-nos-from-message-field/92251/3 "2017-07-10T07:47:57Z")

</div>

Hi,

Thanks for the reply , could you please let me know the scripts which need to be run and where its need to be run ?  
Also how to mange indexing in running container as fulentd ?

---

<div class="post-metadata">

**Author:** ![Suman\_Saha](https://avatars.discourse-cdn.com/v4/letter/s/58f4c7/32.png) [@Suman\_Saha](https://discuss.elastic.co/u/Suman_Saha)\
**Post date:** [July 12, 2017, 7:56am UTC](https://discuss.elastic.co/t/extracting-counts-of-given-nos-from-message-field/92251/4 "2017-07-12T07:56:30Z")

</div>

Is there anyway I can do this from kibana console itself rather modifying fluentd servers which is running as container ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2017, 7:56am UTC](https://discuss.elastic.co/t/extracting-counts-of-given-nos-from-message-field/92251/5 "2017-08-09T07:56:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
