# I want to extract logs with more than a certain number of specific values in a message

**URL:** <https://discuss.elastic.co/t/i-want-to-extract-logs-with-more-than-a-certain-number-of-specific-values-in-a-message/307018>\
**Category:** Kibana\
**Created:** [June 13, 2022, 10:59am UTC](https://discuss.elastic.co/t/i-want-to-extract-logs-with-more-than-a-certain-number-of-specific-values-in-a-message/307018 "2022-06-13T10:59:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![its-ogawa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/its-ogawa/32/120829_2.png) [@its-ogawa](https://discuss.elastic.co/u/its-ogawa)\
**Post date:** [June 13, 2022, 10:59am UTC](https://discuss.elastic.co/t/i-want-to-extract-logs-with-more-than-a-certain-number-of-specific-values-in-a-message/307018/1 "2022-06-13T10:59:24Z")

</div>

I am using filebeat to get the logs for each server.  
Some of the logs are outputting the processing times of various methods, which are commonly formatted as "elaps:\*\*\*\*".

In Kibana, the elapsed time is displayed by using the keyword "elapses", but we would like to filter out only the elapsed time that is more than a certain number.  
Is it possible to express this in KQL?

ex)

[YYYYY-MM-DD hh:mm:ss] ... snip ... elaps:13 ... snip ...  
[YYYYY-MM-DD hh:mm:ss] ... snip ... elaps:20 ... snip ...  
[YYYYY-MM-DD hh:mm:ss] ... snip ... elaps:121 ... snip ...  
[YYYYY-MM-DD hh:mm:ss] ... snip ... elaps:614 ... snip ...  
[YYYYY-MM-DD hh:mm:ss] ... snip ... elaps:35 ... snip ...  
[YYYYY-MM-DD hh:mm:ss] ... snip ... elaps:518 ... snip ...  
... snip ...

For example, to extract elapses greater than 500

[YYYYY-MM-DD hh:mm:ss] ... snip ... elaps:614 ... snip ...  
[YYYYY-MM-DD hh:mm:ss] ... snip ... elaps:518 ... snip ...  
... snip ...

---

<div class="post-metadata">

**Author:** ![jughosta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jughosta/32/107160_2.png) [@jughosta](https://discuss.elastic.co/u/jughosta)\
**Post date:** [June 21, 2022, 7:48am UTC](https://discuss.elastic.co/t/i-want-to-extract-logs-with-more-than-a-certain-number-of-specific-values-in-a-message/307018/2 "2022-06-21T07:48:23Z")

</div>

Hi @its-ogawa !  
There is an option to create a runtime field with a number type. Then you would be able to filter with KQL.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2022, 7:48am UTC](https://discuss.elastic.co/t/i-want-to-extract-logs-with-more-than-a-certain-number-of-specific-values-in-a-message/307018/3 "2022-07-19T07:48:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
