# Field from logs

**URL:** <https://discuss.elastic.co/t/field-from-logs/322476>\
**Category:** Elasticsearch\
**Created:** [January 4, 2023, 2:41pm UTC](https://discuss.elastic.co/t/field-from-logs/322476 "2023-01-04T14:41:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![MrMartin1](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@MrMartin1](https://discuss.elastic.co/u/MrMartin1)\
**Post date:** [January 4, 2023, 2:41pm UTC](https://discuss.elastic.co/t/field-from-logs/322476/1 "2023-01-04T14:41:53Z")

</div>

Hi!

I'm new to elasticsearch and have recently setup elastic, kibana and filebeat and manage to receive logs from a Cisco device.  
Now i have a question if it's possible to parse specific value from the message, like "PeerAddress", "ConnectTime" (see picture) and have that added to a column in a table.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd04e953d47e8a34302270e9efd026944c3d0477.png)

Thanks in advance !

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 5, 2023, 11:32pm UTC](https://discuss.elastic.co/t/field-from-logs/322476/2 "2023-01-05T23:32:55Z")

</div>

Can you copy 2-3 lines as text?(use formating \</\>) Do you need full line parsed or just "PeerAddress" and "ConnectTime"?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2023, 11:33pm UTC](https://discuss.elastic.co/t/field-from-logs/322476/3 "2023-02-02T23:33:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
