# Grok patterns : creating new field

**URL:** <https://discuss.elastic.co/t/grok-patterns-creating-new-field/83576>\
**Category:** Logstash\
**Created:** [April 25, 2017, 1:52pm UTC](https://discuss.elastic.co/t/grok-patterns-creating-new-field/83576 "2017-04-25T13:52:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sylfaen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylfaen/32/17653_2.png) [@Sylfaen](https://discuss.elastic.co/u/Sylfaen)\
**Post date:** [April 25, 2017, 1:52pm UTC](https://discuss.elastic.co/t/grok-patterns-creating-new-field/83576/1 "2017-04-25T13:52:43Z")

</div>

Hello !

I was wondering if it is possible to embed the content of a field to a new "structured field" ?

For example, from a JDBC entry, I've got a column named message which contains informations with the following format:  
CONFIRM;userId:58428;status:DONE;...

With a grok match, I succeeded to split the message column into several new document fields :

> "\_index": "demo",  
> "\_type": "demologs",  
> "\_id": "AVulVdwqUVyhaHL536Vw",  
> "\_score": 1,  
> "\_source": {  
> "date": "2015-09-27T12:21:58.000Z",  
> "amount": "58.2",  
> "type": "CONFIRM",  
> "userId": "58428",  
> "status": "DONE",  
> } ...

Date/Amount come from other column of the table.  
But is it possible to create a field that encapsulate all message informations without manually use the add\_field feature ?

> "\_index": "demo",  
> "\_type": "demologs",  
> "\_id": "AVulVdwqUVyhaHL536Vw",  
> "\_score": 1,  
> "\_source": {  
> "date": "2015-09-27T12:21:58.000Z",  
> "amount": "58.2",  
> "message" : {  
> "type": "CONFIRM",  
> "userId": "58428",  
> "status": "DONE",  
> },  
> } ...

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 25, 2017, 2:01pm UTC](https://discuss.elastic.co/t/grok-patterns-creating-new-field/83576/2 "2017-04-25T14:01:54Z")

</div>

In your grok expression, use (for example) `[message][type]` instead of `type`.

---

<div class="post-metadata">

**Author:** ![Sylfaen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylfaen/32/17653_2.png) [@Sylfaen](https://discuss.elastic.co/u/Sylfaen)\
**Post date:** [April 25, 2017, 2:05pm UTC](https://discuss.elastic.co/t/grok-patterns-creating-new-field/83576/3 "2017-04-25T14:05:17Z")

</div>

Hey,

Thanks for your quick answer!

What you mean is to specify the type above the match expression ?  
My grok expression looks like this :

grok {  
match =\> { "message" =\> "^%{DATA:type}?;userId:%{DATA:userId}?;status:%{WORD:status}?" }  
}

Thanks again! 😅

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 25, 2017, 2:06pm UTC](https://discuss.elastic.co/t/grok-patterns-creating-new-field/83576/4 "2017-04-25T14:06:05Z")

</div>

I mean: In your grok expression, replace `type` with `[message][type]`.

---

<div class="post-metadata">

**Author:** ![Sylfaen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylfaen/32/17653_2.png) [@Sylfaen](https://discuss.elastic.co/u/Sylfaen)\
**Post date:** [April 25, 2017, 2:58pm UTC](https://discuss.elastic.co/t/grok-patterns-creating-new-field/83576/5 "2017-04-25T14:58:57Z")

</div>

I replace [message] with a new field's name and it's working very well.

Thanks Magnus 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2017, 3:00pm UTC](https://discuss.elastic.co/t/grok-patterns-creating-new-field/83576/6 "2017-05-23T15:00:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
