Grab value from message field and add it to a new field

You can use grok to match the entire pattern, then you can use that field elsewhere - https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html