# How to Parse url.query into Different Fields?

**URL:** <https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 24, 2019, 5:49pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920 "2019-09-24T17:49:16Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Michael\_Madden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/michael_madden/32/46640_2.png) [@Michael\_Madden](https://discuss.elastic.co/u/Michael_Madden)\
**Post date:** [September 25, 2019, 7:36pm UTC](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920/2 "2019-09-25T19:36:06Z")

</div>

Hello, thanks for the question about filebeat. In your configuration, is filebeat shipping directly to elasticsearch, or does filebeat first ship data to logstash for enrichment or filtering. If you're using logstash, this could be a possible good portion of the pipeline to split about the `url.query` string.

If you're using logstash, I would recommend looking at the grok filter plugin:  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)

---

_[View the full topic](https://discuss.elastic.co/t/how-to-parse-url-query-into-different-fields/200920)._
