# Filter from message field

**URL:** <https://discuss.elastic.co/t/filter-from-message-field/159167>\
**Category:** Elasticsearch\
**Created:** [December 3, 2018, 12:08pm UTC](https://discuss.elastic.co/t/filter-from-message-field/159167 "2018-12-03T12:08:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [December 3, 2018, 12:08pm UTC](https://discuss.elastic.co/t/filter-from-message-field/159167/1 "2018-12-03T12:08:56Z")

</div>

I have data from Jenkins console and I am using Logstash Plugin to ship logs to ES .  
Now the problem is that I want to extract data from the "message" field and create a custom field. I understand that logstash gork is a good option , but the logstash config files are not available as I am using the logstash-jenkins plugin to ship console logs from Jenkins.

Please let me know if there is way to filter data from the message field in my situation.Will I have to create a new mapping or is there any other way ?

I also understand that I can use painless and create a field. But I am using Logtrail and even if I create this custom field using painless, I wont be able to use it in Logtrail. So the field needs to be created at the source level.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2018, 12:08pm UTC](https://discuss.elastic.co/t/filter-from-message-field/159167/2 "2018-12-31T12:08:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
