# New to ELK - help required on this kibana query

**URL:** <https://discuss.elastic.co/t/new-to-elk-help-required-on-this-kibana-query/152458>\
**Category:** Kibana\
**Created:** [October 15, 2018, 9:26am UTC](https://discuss.elastic.co/t/new-to-elk-help-required-on-this-kibana-query/152458 "2018-10-15T09:26:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![roopeshetty](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@roopeshetty](https://discuss.elastic.co/u/roopeshetty)\
**Post date:** [October 15, 2018, 9:26am UTC](https://discuss.elastic.co/t/new-to-elk-help-required-on-this-kibana-query/152458/1 "2018-10-15T09:26:14Z")

</div>

Hi ,

We are running a powershell script to monitor the expiry dates of around 200 certificates which will write the script output on the system event logs of one of our windows servers as below;

**_[Origin=SERVER001.co.net](http://Origin=SERVER001.co.net), SSLExperationDate=5/16/2020 7:59:59 PM, Days Remaining: 580 days ,Issuer=GeoTrust SSL CA - G3_**

**_Origin= [SERVER002.co.net](http://SERVER002.co.net), SSLExperationDate=8/26/2019 4:20:31 AM, Days Remaining: 315 days ,Issuer=GeoTrust SSL CA - G3_**

**_Origin= [SERVER003.co.net](http://SERVER003.co.net), SSLExperationDate=12/11/2020 3:07:44 PM, Days Remaining: 789 days ,Issuer=GeoTrust SSL CA - G3_**

Now our management wants to setup a dashboard on these certificates as per their expiry dates in a descending order in a table format which should consist 2 columns (Origin and Days Remaining)

“Origin” columns should contain certificate server names like [SERVER001.co.net](http://SERVER001.co.net), [SERVER002.co.net](http://SERVER002.co.net), [SERVER003.co.net](http://SERVER003.co.net), [SERVER004.co.net](http://SERVER004.co.net) etc…

“Days Remaining” column should contain number of days remaining for certificate expiry like 580, 315, 789 etc…

Now can some body please provide us the kibana search query so that we can accomplish this. Actually in splunk there is something called “rex” - a search-time field extractor which would help us in creating the new fields out of any event log sentence. As we are very new to ELK stack we could not find any query command which is alternative to this rex command. Can some please help on this?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 15, 2018, 9:44am UTC](https://discuss.elastic.co/t/new-to-elk-help-required-on-this-kibana-query/152458/2 "2018-10-15T09:44:45Z")

</div>

When working with the Elastic Stack it is recommended to extract relevant fields at indexing time and not on read.

The best way to do this would therefore be to extract the field at indexing time, e.g. using [an ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/current/pipeline.html) with a [KV processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/kv-processor.html) or a [KV filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html) in Logstash.

If you want to extract data for already indexed data you can use the [reindex API](https://www.elastic.co/guide/en/elasticsearch/reference/6.4/docs-reindex.html) together with an ingest pipeline.

---

<div class="post-metadata">

**Author:** ![roopeshetty](https://avatars.discourse-cdn.com/v4/letter/r/b9bd4f/32.png) [@roopeshetty](https://discuss.elastic.co/u/roopeshetty)\
**Post date:** [October 15, 2018, 10:31am UTC](https://discuss.elastic.co/t/new-to-elk-help-required-on-this-kibana-query/152458/3 "2018-10-15T10:31:53Z")

</div>

Thanks for the response Christian, As i am very new to this ELK, i may need to understand from the scratch it seems. Thanks for the clue, i will go through this logstash config first and test it. Thanks again for providing me the clue for this.

regard

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2018, 10:31am UTC](https://discuss.elastic.co/t/new-to-elk-help-required-on-this-kibana-query/152458/4 "2018-11-12T10:31:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
