# Find all numbers in a text with

**URL:** <https://discuss.elastic.co/t/find-all-numbers-in-a-text-with/339020>\
**Category:** Kibana\
**Created:** [July 23, 2023, 9:01pm UTC](https://discuss.elastic.co/t/find-all-numbers-in-a-text-with/339020 "2023-07-23T21:01:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kbfifi](https://avatars.discourse-cdn.com/v4/letter/k/d2c977/32.png) [@kbfifi](https://discuss.elastic.co/u/kbfifi)\
**Post date:** [July 23, 2023, 9:01pm UTC](https://discuss.elastic.co/t/find-all-numbers-in-a-text-with/339020/1 "2023-07-23T21:01:23Z")

</div>

I'm a newbe and trying to find all numbers in text with GROK. I'm using GROK debugger.  
My sample text: "Sample content with date 11 22 2022 and entity California and another date 1 1 1999 2-3-2024"

I hope to get an array like this ["11", "22", "2022", ""1", "1", "1999", "2", "3", "2024"]

I tried (with chatGPT, likely to be a newbe too ;-))  
%{NUMBER:numbers}  
%{NUMBER:num}(?:\s|%{SPACE})+  
and several other variants.

All result in just 1 number. Any suggestions?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 23, 2023, 11:28pm UTC](https://discuss.elastic.co/t/find-all-numbers-in-a-text-with/339020/2 "2023-07-23T23:28:22Z")

</div>

Theoretically regex is: `(?<digit>\d+)` but will return only the first match.

```auto
filter {
# 1st option:
	grok {
			break_on_match => false
			match => { "message" => ["date %{DATECUSTOM:[@metadata][date1]} %{DATA} date %{DATECUSTOM2:[@metadata][date2]}"] }
			pattern_definitions => { "DATECUSTOM" => "%{MONTHNUM} %{MONTHDAY} %{YEAR}" 
			"DATECUSTOM2" => "%{DATECUSTOM} %{DATE}" }
	}
	
	mutate {
          add_field => { "date" => "%{[@metadata][date1]}%{[@metadata][date2]}" }	  	
    }
    mutate{
	 gsub => ["date", "-", " "]
	 split => { "date" => " " }
	} 
# 2nd option:
   # replace nondigs with space, remove double spaces and split 
	  mutate {
        gsub => ["message", "\D", " ",
        "message", "\s\s", ""
        ]
		split => { "message" => " " }
      }
}

```

Result:

```auto
      "message" => [
        [0] "11",
        [1] "22",
        [2] "20221",
        [3] "1",
        [4] "1999",
        [5] "2",
        [6] "3",
        [7] "2024"
    ],
          "date" => [
        [0] "11",
        [1] "22",
        [2] "20221",
        [3] "1",
        [4] "1999",
        [5] "2",
        [6] "3",
        [7] "2024"
    ]
}

```

Note: This is made in Logstash

---

<div class="post-metadata">

**Author:** ![kbfifi](https://avatars.discourse-cdn.com/v4/letter/k/d2c977/32.png) [@kbfifi](https://discuss.elastic.co/u/kbfifi)\
**Post date:** [July 24, 2023, 8:39pm UTC](https://discuss.elastic.co/t/find-all-numbers-in-a-text-with/339020/3 "2023-07-24T20:39:33Z")

</div>

Thank you for your quick response! I give it a try soon!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2023, 8:40pm UTC](https://discuss.elastic.co/t/find-all-numbers-in-a-text-with/339020/4 "2023-08-21T20:40:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
