# Migrating Splunk query to Elastic

**URL:** <https://discuss.elastic.co/t/migrating-splunk-query-to-elastic/174155>\
**Category:** Elasticsearch\
**Created:** [March 27, 2019, 3:06pm UTC](https://discuss.elastic.co/t/migrating-splunk-query-to-elastic/174155 "2019-03-27T15:06:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ravitandur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravitandur/32/4568_2.png) [@ravitandur](https://discuss.elastic.co/u/ravitandur)\
**Post date:** [March 27, 2019, 3:06pm UTC](https://discuss.elastic.co/t/migrating-splunk-query-to-elastic/174155/1 "2019-03-27T15:06:09Z")

</div>

Currently we are using Splunk and planning to migrate to Elastic. We are in the process of deciding how data needs to be ingested into Elastic Cluster.  
In this topic I will give provide

1. Sample log data.
2. Current Splunk Query we are using on that data.
3. How this data is indexed into Elastic cluster.
4. My questing is, with the current indexed data in Elastic cluster, is it possible to write the queries in DSL to get the information as done in Splunk? or do we need to change the way we are indexing the documents?

Sample data:  
2019-03-25 23:09:59 (973) worker.3 worker.3 txid=f0fe292fdb50 Completed: ASYNC: Discovery - Sensors in 0:03:31.246, next occurrence is null

Splunk Query to extract the jobname and form a table  
index=abc timeformat= "%Y-%m-%d %H:%M:%S" earliest="2019-03-25 23:00:00" searchtimespanminutes=10 instance=\* node=\* Completed: worker  
| rex field=\_raw "Completed: (?\<jobname\>.\*) in"  
| table \_time, node, jobname

When we ingested the data into Elastic cluster, we used the reg ex which converted the raw data into below fields:  
@timestamp:2019-03-25 23:09:59  
Threadname : worker.3  
message : txid=f0fe292fdb50 Completed: ASYNC: Discovery - Sensors in 0:03:31.246, next occurrence is null

My question is, from message, during query time can we extract jobname is Elastic?  
Also in this example, the jobname is string, but in some other cases the extracted value might be integer, so can we extract different type values in elastic during query time and apply required functions on top of extracted values?

Please suggest?  
In case any further information required please let me know.

Thanks,  
Ravi

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 28, 2019, 4:26am UTC](https://discuss.elastic.co/t/migrating-splunk-query-to-elastic/174155/2 "2019-03-28T04:26:46Z")

</div>

> [@ravitandur](#):
>
> My question is, from message, during query time can we extract jobname is Elastic?

Ideally you would do that during indexing, so it's another field.

You probably could do it with a funky query, but that's outside my scope of knowledge sorry.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 28, 2019, 6:22am UTC](https://discuss.elastic.co/t/migrating-splunk-query-to-elastic/174155/3 "2019-03-28T06:22:31Z")

</div>

When you work with Elasticsearch you generally parse out as much as possible as index time as doing this as query time tend to get slow. This approach and the benefits it brings is described in [this blog post](https://www.elastic.co/blog/schema-on-write-vs-schema-on-read).

---

<div class="post-metadata">

**Author:** ![ravitandur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravitandur/32/4568_2.png) [@ravitandur](https://discuss.elastic.co/u/ravitandur)\
**Post date:** [April 3, 2019, 10:27am UTC](https://discuss.elastic.co/t/migrating-splunk-query-to-elastic/174155/4 "2019-04-03T10:27:31Z")

</div>

Thank you. Followed the blog and able to create required scripted fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2019, 10:27am UTC](https://discuss.elastic.co/t/migrating-splunk-query-to-elastic/174155/5 "2019-05-01T10:27:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
