# How to Parse url.query into Different Fields?

**URL:** <https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 24, 2019, 5:49pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920 "2019-09-24T17:49:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![antonio84](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@antonio84](https://discuss.elastic.co/u/antonio84)\
**Post date:** [September 24, 2019, 5:49pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920/1 "2019-09-24T17:49:16Z")

</div>

ELK 7.3 and Filebeat 7.3

I'm using the IIS module currently, and everything is parsing great. I would like to further parse the url.query section of this line, indicated in bold:

> 2019-09-24 17:14:04 10.202.225.10 GET /Sso/Internal/SignOn.aspx **fi=10\_2084e051-0184-4746-a017-558fdf9a99a1&customer=3** 443 - 10.202.225.254

I would like to separate it into 3 sections:

1. fi=10 the underscore following this would be the delimiter. Title would be "Client"
2. the middle section of stuff, the ampsersand being the delimiter. Title being "Widget"
3. customer=3 would be the last section. Title being "Customer"

Since I'm using the built in IIS module, I don't know where to put this additional parsing language, or frankly how to make it happen at all.

---

<div class="post-metadata">

**Author:** ![Michael\_Madden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_madden/32/46640_2.png) [@Michael\_Madden](https://discuss.elastic.co/u/Michael_Madden)\
**Post date:** [September 25, 2019, 7:36pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920/2 "2019-09-25T19:36:06Z")

</div>

Hello, thanks for the question about filebeat. In your configuration, is filebeat shipping directly to elasticsearch, or does filebeat first ship data to logstash for enrichment or filtering. If you're using logstash, this could be a possible good portion of the pipeline to split about the `url.query` string.

If you're using logstash, I would recommend looking at the grok filter plugin:  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)

---

<div class="post-metadata">

**Author:** ![antonio84](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@antonio84](https://discuss.elastic.co/u/antonio84)\
**Post date:** [September 26, 2019, 1:43pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920/3 "2019-09-26T13:43:12Z")

</div>

I am shipping directly to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![antonio84](https://avatars.discourse-cdn.com/v4/letter/a/90ced4/32.png) [@antonio84](https://discuss.elastic.co/u/antonio84)\
**Post date:** [October 1, 2019, 2:36pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920/4 "2019-10-01T14:36:16Z")

</div>

Hi, thanks for the response. I am shipping directly to Elasticsearch, is shipping to logstash the best way to split url.query or can it be achieved using the ingest pipeline in filebeat?

Any advice is appreciated, I'm still a newbie.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2019, 2:36pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920/5 "2019-10-29T14:36:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
