# Find values inside parenthesees and put it into an array

**URL:** <https://discuss.elastic.co/t/find-values-inside-parenthesees-and-put-it-into-an-array/268935>\
**Category:** Logstash\
**Created:** [March 31, 2021, 3:55pm UTC](https://discuss.elastic.co/t/find-values-inside-parenthesees-and-put-it-into-an-array/268935 "2021-03-31T15:55:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [March 31, 2021, 3:55pm UTC](https://discuss.elastic.co/t/find-values-inside-parenthesees-and-put-it-into-an-array/268935/1 "2021-03-31T15:55:24Z")

</div>

Hi all,

i have this problem , i have this kind of value into a field:

`Update for Windows Server 2012 R2 (KB3013410)"", Update for Windows Server 2012 R2 (KB3033446), Update for Windows Server 2012 R2 (KB3024751), Update for Windows Server 2012 R2 (KB3123245), Update for Windows Server 2012 R2 (KB3134815), Update for Windows Server 2012 R2 (KB3084905), Update for Windows Server 2012 R2 (KB3134179), Update for Windows Server 2012 R2 (KB3036612), Update for Windows Server 2012 R2 (KB3091297), Update for Windows Server 2012 R2 (KB3030947), Update for Windows Server 2012 R2 (KB3044673), Update for Windows Server 2012 R2 (KB3012702), Update for Windows Server 2012 R2 (KB3140219), Update for Windows Server 2012 R2 (KB3054169)`

I need to insert in an array only the code into the paratheses , obviously the field haven't the same pattern . Maybe i have to use regex?!

A coffee to the first good advice!

Roberto

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 31, 2021, 5:02pm UTC](https://discuss.elastic.co/t/find-values-inside-parenthesees-and-put-it-into-an-array/268935/2 "2021-03-31T17:02:02Z")

</div>

```
input { generator { count => 1 lines => ['Update for Windows Server 2012 R2 (KB3013410)"", Update for Windows Server 2012 R2 (KB3033446), Update for Windows Server 2012 R2 (KB3024751), Update for Windows Server 2012 R2 (KB3123245), Update for Windows Server 2012 R2 (KB3134815), Update for Windows Server 2012 R2 (KB3084905), Update for Windows Server 2012 R2 (KB3134179), Update for Windows Server 2012 R2 (KB3036612), Update for Windows Server 2012 R2 (KB3091297), Update for Windows Server 2012 R2 (KB3030947), Update for Windows Server 2012 R2 (KB3044673), Update for Windows Server 2012 R2 (KB3012702), Update for Windows Server 2012 R2 (KB3140219), Update for Windows Server 2012 R2 (KB3054169)'] } }
filter {
    ruby { code => 'event.set("patches", event.get("message").scan(/\(\w+\)/))' }
}

```

will produce

```
   "patches" => [
    [0] "(KB3013410)",
    [1] "(KB3033446)",
    [2] "(KB3024751)",
    [3] "(KB3123245)",
    [4] "(KB3134815)",
    [5] "(KB3084905)",
    [6] "(KB3134179)",
    [7] "(KB3036612)",
    [8] "(KB3091297)",
    [9] "(KB3030947)",
    [10] "(KB3044673)",
    [11] "(KB3012702)",
    [12] "(KB3140219)",
    [13] "(KB3054169)"
],
```

---

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [April 1, 2021, 8:26am UTC](https://discuss.elastic.co/t/find-values-inside-parenthesees-and-put-it-into-an-array/268935/3 "2021-04-01T08:26:06Z")

</div>

> [@Badger](#):
>
> ```auto
> filter {
> ruby { code => 'event.set("patches", event.get("message").scan(/\(\w+\)/))' }
> }
> 
> ```

IT WORKS !!!!

Another thing, sometime i have in input []  
(an empty list) in order to avoid Invalid Reference '[]' error I use:

```auto
filter{
	ruby {
  code => "
	if event.get('Patches available').nil?
		event.remove('[Patches available]')
	end
  "
	}
}

```

is it right?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2021, 8:26am UTC](https://discuss.elastic.co/t/find-values-inside-parenthesees-and-put-it-into-an-array/268935/4 "2021-04-29T08:26:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
