# Filter an existing field to generate a new field

**URL:** <https://discuss.elastic.co/t/filter-an-existing-field-to-generate-a-new-field/193427>\
**Category:** Elasticsearch\
**Created:** [August 2, 2019, 1:05am UTC](https://discuss.elastic.co/t/filter-an-existing-field-to-generate-a-new-field/193427 "2019-08-02T01:05:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [August 2, 2019, 1:05am UTC](https://discuss.elastic.co/t/filter-an-existing-field-to-generate-a-new-field/193427/1 "2019-08-02T01:05:37Z")

</div>

Given the following event input inside Kibana Discover Page:

```
cloudwatch_logs.log_group: /aws/lambda/b2_raw_processor
@version: 1
message: 2019-08-01 15:30:19,207 - INFO - RAWPROC - PROCESS - SUCCESS - file_type:video - machine_id:93843ed258d1c8469a80c6d3672b033f - upload_date:2019-07-31 - tag_id:0548207774505533 - rsid:1564607297562 - timestamp:20190731 - extra_info:down - file:0548207774505533-1564607297562-20190731-down-000000.tar.bz2 : File processed successfully 
@timestamp: Aug 1, 2019 @ 08:30:19.207
cloudwatch_logs.event_id: 34893383240648998145054626322427042217296655004557574166
cloudwatch_logs.ingestion_time: Aug 1, 2019 @ 08:30:32.524
cloudwatch_logs.log_stream: 2019/08/01/[$LATEST]c72de767a67b4919ae5f57f872b7b0ab
type: Cloudwatch
_id: 4_rOTWwBFuDxKtYSDOBz
_type: _doc
_index: stage-cloudwatch
_score: -

```

Is there any way to filter out `machine_id:93843ed258d1c8469a80c6d3672b033f` from the message field, and generated a new field out of it using Elasticsearch query?

For example:

```
cloudwatch_logs.log_group: /aws/lambda/b2_raw_processor
@version: 1
message: 2019-08-01 15:30:19,207 - INFO - RAWPROC - PROCESS - SUCCESS - file_type:video - machine_id:93843ed258d1c8469a80c6d3672b033f - upload_date:2019-07-31 - tag_id:0548207774505533 - rsid:1564607297562 - timestamp:20190731 - extra_info:down - file:0548207774505533-1564607297562-20190731-down-000000.tar.bz2 : File processed successfully 
machine_id:93843ed258d1c8469a80c6d3672b033f 
@timestamp: Aug 1, 2019 @ 08:30:19.207
cloudwatch_logs.event_id: 34893383240648998145054626322427042217296655004557574166
cloudwatch_logs.ingestion_time: Aug 1, 2019 @ 08:30:32.524
cloudwatch_logs.log_stream: 2019/08/01/[$LATEST]c72de767a67b4919ae5f57f872b7b0ab
type: Cloudwatch
_id: 4_rOTWwBFuDxKtYSDOBz
_type: _doc
_index: stage-cloudwatch
_score: -
```

---

<div class="post-metadata">

**Author:** ![EZprogramming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ezprogramming/32/57291_2.png) [@EZprogramming](https://discuss.elastic.co/u/EZprogramming)\
**Post date:** [August 2, 2019, 1:07am UTC](https://discuss.elastic.co/t/filter-an-existing-field-to-generate-a-new-field/193427/2 "2019-08-02T01:07:20Z")

</div>

I tried using [Regexp queryedit](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-regexp-query.html#query-dsl-regexp-query), but it would return the whole json events that match the criteria, and not actually generating a new field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 30, 2019, 1:07am UTC](https://discuss.elastic.co/t/filter-an-existing-field-to-generate-a-new-field/193427/3 "2019-08-30T01:07:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
