# Is it possible to extract value of data within a field in Kibana?

**URL:** <https://discuss.elastic.co/t/is-it-possible-to-extract-value-of-data-within-a-field-in-kibana/304626>\
**Category:** Kibana\
**Created:** [May 13, 2022, 12:57am UTC](https://discuss.elastic.co/t/is-it-possible-to-extract-value-of-data-within-a-field-in-kibana/304626 "2022-05-13T00:57:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![thiton](https://avatars.discourse-cdn.com/v4/letter/t/b38774/32.png) [@thiton](https://discuss.elastic.co/u/thiton)\
**Post date:** [May 13, 2022, 12:57am UTC](https://discuss.elastic.co/t/is-it-possible-to-extract-value-of-data-within-a-field-in-kibana/304626/1 "2022-05-13T00:57:44Z")

</div>

Hi,

I am trying to extract value of data with a field, but no luck. Please help. Many thanks in advance.

For example,

1. I run below script to get the data

```auto
GET xx-prod-transaction-*/_search
 {
  "query": {
    "bool": {
      "must": [
        {
          "term": {
            "appName": "app1"
          }
        },
        {
          "term": {
            "Transaction-Category": "request"
          }
        }
      ]
    }
  }
}

```

1. Script returns

```auto
{
  "took" : 25328,
  "timed_out" : false,
  "_shards" : {
    "total" : 250,
    "successful" : 250,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 10000,
      "relation" : "gte"
    },
    "max_score" : 9.945171,
    "hits" : [
      {
        "_index" : "xx-prod-transaction-2022.04.25",
        "_type" : "_doc",
        "_id" : "B8QnY4AB6yZ61111",
        "_score" : 9.945111,
        "_ignored" : [
          "original_message.keyword"
        ],
        "_source" : {
          "Transaction-Id" : "e821e122-1314-415e-bff4-c92445",
          "Transaction-Category" : "request",
          "Transaction-Payload" : "0436R042022042518310200000000000000000000000000000017802100000000005700157 00055542100M3152018010120220425QD161.73 NA",
         "appName" : "app1",
          "tags" : [
            "FORMATTED",
            "TRANSACTION",
            "PROD"
          ],
          "@timestamp" : "2022-04-25T23:56:41.595Z",
          "App-Id" : "5d277dfddfd8e86e111"
        }
      }

```

1. I would like to extract a value = "_000555421_' which is in bold from one of returned fields 'Transaction-Payload'  
" **Transaction-Payload**" : "0436R042022042518310200000000000000000000000000000017802100000000005700157 00055542100M3152018010120220425QD161.73 NA"

Please help. Thanks.

Thi T.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [May 13, 2022, 7:47am UTC](https://discuss.elastic.co/t/is-it-possible-to-extract-value-of-data-within-a-field-in-kibana/304626/2 "2022-05-13T07:47:29Z")

</div>

Hi,

Have you tried runtime fields?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2022, 7:48am UTC](https://discuss.elastic.co/t/is-it-possible-to-extract-value-of-data-within-a-field-in-kibana/304626/3 "2022-06-10T07:48:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
