# Field contains CSV want to extract to array of strings

**URL:** <https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 7, 2021, 3:02pm UTC](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494 "2021-04-07T15:02:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ian351c](https://avatars.discourse-cdn.com/v4/letter/i/dfb087/32.png) [@ian351c](https://discuss.elastic.co/u/ian351c)\
**Post date:** [April 7, 2021, 3:02pm UTC](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494/1 "2021-04-07T15:02:22Z")

</div>

Hello all,

I am working on migrating from Splunk to ELK for my Palo Alto Networks firewall logs using the pre-built processor in Filebeat. The pipeline is Syslog \> Filebeat \> Elastic. The PANW logs contain two separate fields for URL Category: one with just a single value (which is extracted in the stock Filebeat input.yml as a string) and another one which contains a quoted string which is a list of comma separated categories (e.g. "music, streaming-services,low-risk"). I would like to extract this list into a field with multiple values (similar to how the Tags field can have multiple values). Is it possible to do this in Filebeat?

Thanks!

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 7, 2021, 3:27pm UTC](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494/2 "2021-04-07T15:27:04Z")

</div>

Hi ian 351c

This is done using the ingest processor in Elasticsearch that receives the data from filebeat.

> **[Split processor | Elasticsearch Guide \[master\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/master/split-processor.html)**

If you migrating from splunk I would recommend to get in touch with us using the contact form. You will receive a lot of help that way:

> **[Have questions? Contact Elastic](https://www.elastic.co/contact)**
>
> Have a question? Need help? Need to contact Elastic? We've got people worldwide to help you find the answers and information you're looking for.

---

<div class="post-metadata">

**Author:** ![ian351c](https://avatars.discourse-cdn.com/v4/letter/i/dfb087/32.png) [@ian351c](https://discuss.elastic.co/u/ian351c)\
**Post date:** [April 7, 2021, 4:47pm UTC](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494/3 "2021-04-07T16:47:42Z")

</div>

That works perfectly, thanks! Now the trick is to get my visualizations to not show super common values for this field. For instance, from my example above: "music, streaming-services,low-risk". I now get all three values in my field, but I want to exclude "low-risk" from my visualizations, since that's about 90% of my events, but not very useful information. I tried using a filter, but of course, that excludes the entire event rather than just removing "low-risk" from the visualization (a Lens in this case). How do I go about excluding a single value for a field from a visualization without discarding the entire event?

Thanks!

Edit: It looks like I can use a "classic" aggregation based visualization to do this, as it includes the ability to exclude a value from the visualization rather than the underlying query. I'd rather do this with a lens, but it doesn't appear to have that ability...

---

<div class="post-metadata">

**Author:** ![Felix\_Roessel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/felix_roessel/32/41623_2.png) [@Felix\_Roessel](https://discuss.elastic.co/u/Felix_Roessel)\
**Post date:** [April 7, 2021, 6:07pm UTC](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494/4 "2021-04-07T18:07:45Z")

</div>

I forwarded your feedback to the lens team. They will take care to implement it.  
Thanks for raising it.

---

<div class="post-metadata">

**Author:** ![ian351c](https://avatars.discourse-cdn.com/v4/letter/i/dfb087/32.png) [@ian351c](https://discuss.elastic.co/u/ian351c)\
**Post date:** [April 8, 2021, 3:00pm UTC](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494/5 "2021-04-08T15:00:36Z")

</div>

Thanks Felix. I appreciate that!

Ian

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2021, 5:01pm UTC](https://discuss.elastic.co/t/field-contains-csv-want-to-extract-to-array-of-strings/269494/6 "2021-05-06T17:01:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
