# How to split a field value into separated fields in elasticsearch

**URL:** <https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [July 13, 2020, 9:50am UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938 "2020-07-13T09:50:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hung\_M\_Le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hung_m_le/32/54995_2.png) [@Hung\_M\_Le](https://discuss.elastic.co/u/Hung_M_Le)\
**Post date:** [July 13, 2020, 9:50am UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938/1 "2020-07-13T09:50:20Z")

</div>

Hi

I have the following issue that I hope to get some help to resolve

background:

. I ingest a log file using filebeat  
. I defined inside elasticsearch grok and kv statements to split incoming data into separated fields

Question:  
. If I have field that II want to further split down to different field, how can I do it?  
. Is there a way to apply a regular expression to a field to determine a match and split this field into different values?  
. Can I assign the new split values different fields?

example:

I have a field --  
navlog.context.filename : [https://xxx.yyy.com/NA/GEN4/LANDMARK/version.properties](https://xxx.yyy.com/NA/GEN4/LANDMARK/version.properties)

I want to split the above field into:

navlog.context.region: NA  
navlog.context.product:GEN4  
navlog.context.layer:LANDMARK  
navlog.context.filename:version.properties

Thank you in advance for your help.

Best Regards

Hung Le

---

<div class="post-metadata">

**Author:** ![S0ul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0ul/32/46431_2.png) [@S0ul](https://discuss.elastic.co/u/S0ul)\
**Post date:** [July 16, 2020, 2:34pm UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938/2 "2020-07-16T14:34:07Z")

</div>

Hi Hung\_M\_Le,

Have you considered using grok again on your newly generated fields ? You could also split by "/", rename fields you want to keep and drop the others but I don't see why you would do this if grok is usable.

Regards,  
S0ul

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [July 17, 2020, 4:13am UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938/3 "2020-07-17T04:13:03Z")

</div>

@Hung_M_Le  
I would use script processor to avoid running regex multiple times. For ex.

```auto
PUT _ingest/pipeline/filename_splitter
{
  "processors": [
    {
      "script": {
        "lang": "painless", 
        "source": """
          String fn = ctx['navlog.context.filename'];
          int loc = fn.indexOf('/', 'https://'.length()); 
          int loc2 = fn.indexOf('/', loc+1);
          if (loc2 > -1) {
            ctx['navlog.context.region'] = fn.substring(loc+1, loc2);
            loc = loc2;
            loc2 = fn.indexOf('/', loc+1);
              if (loc2 > -1) {
                ctx['navlog.context.product'] = fn.substring(loc+1, loc2);
              }
          }
          """
      }
    }
  ]
}

POST navlog/_doc?pipeline=filename_splitter
{
  "navlog.context.filename" : "https://xxx.yyy.com/NA/GEN4/LANDMARK/version.properties"
}

```

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 23, 2020, 8:45am UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938/4 "2020-07-23T08:45:16Z")

</div>

The [split processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/split-processor.html) might be another way to go.

---

<div class="post-metadata">

**Author:** ![Vinayak\_Sapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vinayak_sapre/32/45939_2.png) [@Vinayak\_Sapre](https://discuss.elastic.co/u/Vinayak_Sapre)\
**Post date:** [July 23, 2020, 9:00am UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938/5 "2020-07-23T09:00:27Z")

</div>

Split processor generates array. We need a dictionary. String parts are set to different fields.

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [July 23, 2020, 9:21am UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938/6 "2020-07-23T09:21:49Z")

</div>

you can just pick the array elements then and set them to fields manually using a script processor

---

<div class="post-metadata">

**Author:** ![Hung\_M\_Le](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hung_m_le/32/54995_2.png) [@Hung\_M\_Le](https://discuss.elastic.co/u/Hung_M_Le)\
**Post date:** [August 6, 2020, 8:51am UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938/7 "2020-08-06T08:51:22Z")

</div>

THank you Vinayak and Alexander for your recommendation. I have tried both "script" and "split" and I found some issues when the format of a field change; however, I found a way to parse the field using grok. Here is a grok syntax that I used and it works pretty good. I also like the fact the I can use the grok debugger to test out the grok pattern.

{  
"grok": {  
"if": "ctx.navlog?.message != null && ctx.navlog?.message =~ /^T\|/",  
"field": "navlog.context.filename",  
"patterns":["https://%{DATA:navlog.context.web\_server}/%{DATA:navlog.context.region}/%{DATA:navlog.context.project}/%{DATA:navlog.context.layer}/%{DATA:navlog.context.map\_level}/%{DATA:navlog.context.map\_sublevel}/%{DATA:navlog.context.tiles}/%{DATA:navlog.context.tile\_id}/%{DATA:navlog.context.filename}","https://%{DATA:navlog.context.web\_server}/%{DATA:navlog.context.region}/%{DATA:navlog.context.project}/%{DATA:navlog.context.layer}/%{DATA:navlog.context.filename}"]  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 3, 2020, 8:51am UTC](https://discuss.elastic.co/t/how-to-split-a-field-value-into-separated-fields-in-elasticsearch/240938/8 "2020-09-03T08:51:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
