# Fetch substring from a string in logstash filter

**URL:** <https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223>\
**Category:** Logstash\
**Created:** [August 7, 2023, 6:23am UTC](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223 "2023-08-07T06:23:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [August 7, 2023, 6:23am UTC](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223/1 "2023-08-07T06:23:11Z")

</div>

Hi, I have a field called url in elasticsearch document.  
The sample value for the field is /3dpassport/login  
I want to extract only the first string before / that is 3dpassport and store it in a field. Tried this

```auto
copy => {
          "url" => "service_name"
        }
        split => {
          "service_name" => "/"
        }
        add_field => { "service" => "%{service_name[1]}" }

```

In this case  
url =\> /3dpassport/login  
service\_name=\> /3dpassport/login

there is no separate field created for service  
After making changes in pipeline i have deleted and recreated data views

if i put it in this format  
add\_field =\> { "service" =\> "%{[service\_name][1]}" }  
i am getting service name as  
service=\> %{[service\_name][1]}

and if i put "%{url[1]}" there is no service field generated. looks like some syntax problem accessing the array

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 7, 2023, 5:36pm UTC](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223/2 "2023-08-07T17:36:04Z")

</div>

> [@Neelam\_Zanvar](#):
>
> ```auto
> copy => {
> "url" => "service_name"
> }
> split => {
> "service_name" => "/"
> }
> add_field => { "service" => "%{service_name[1]}" }
> 
> ```

A mutate filter does things in a [fixed order](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-proc_order), and copy happens after split. add\_field comes last. Use two mutate filters

```
    mutate { copy => { "url" => "service_name" } }
    mutate {
        split => { "service_name" => "/" }
        add_field => { "service" => "%{[service_name][1]}" }
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2023, 5:36pm UTC](https://discuss.elastic.co/t/fetch-substring-from-a-string-in-logstash-filter/340223/3 "2023-09-04T17:36:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
