# Painless search

**URL:** <https://discuss.elastic.co/t/painless-search/236696>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [June 11, 2020, 12:13pm UTC](https://discuss.elastic.co/t/painless-search/236696 "2020-06-11T12:13:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jaume\_Puigserver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaume_puigserver/32/70143_2.png) [@Jaume\_Puigserver](https://discuss.elastic.co/u/Jaume_Puigserver)\
**Post date:** [June 11, 2020, 12:13pm UTC](https://discuss.elastic.co/t/painless-search/236696/1 "2020-06-11T12:13:51Z")

</div>

Hi,

I'm trying to use painless script for extracting data from a cisco message. I know that you will tell me that better indexing from start with a new asa patter but for now I need urgently extract data

The message string is

```auto
Mar 31 22:57:07 fortinet.xxx.com %ASA-4-113019: Group = XXXX_Users, Username = XXXXXX, IP = 000.000.000.000, Session disconnected. Session Type: SSL, Duration: 4h:05m:16s, Bytes xmt: 7035523, Bytes rcv: 4277273, Reason: Idle Timeout, Session Type: SSL, Duration: 4h:05m:16s, Bytes xmt: 7035523, Bytes rcv: 4277273, Reason: Idle Timeout

```

And I will extract Duration in seconds

I've tried

```auto
def t = /^.*Duration\\: ([0-9]+)h\\:([0-9]+)m\\:([0-9]+)s/.matcher(doc['message.keyword'].value);
if ( t != null ) {
   return (Integer.parseInt((t.group(1)) * 60 * 60) + (Integer.parseInt(t.group(2)) * 60) + Integer.parseInt(t.group(3)))
} else {
   return 0
}

```

But always get 0. Also if I only put one \ before : I get error

Any idea?

Rgds,  
Jaume.

---

<div class="post-metadata">

**Author:** ![markov00](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markov00/32/33316_2.png) [@markov00](https://discuss.elastic.co/u/markov00)\
**Post date:** [June 12, 2020, 4:09pm UTC](https://discuss.elastic.co/t/painless-search/236696/2 "2020-06-12T16:09:16Z")

</div>

Hi, I've checked the syntax and rewriting it like that should work: (try with both message or message.keyword

```auto
def t = /^.*Duration\: ([0-9]+)h\:([0-9]+)m\:([0-9]+)s/.matcher(doc['message'].value);
if (t.find()) {
   return Integer.parseInt(t.group(1))* 60 * 60 + Integer.parseInt(t.group(2)) * 60 + Integer.parseInt(t.group(3))
} else {
   return 0
}

```

---

<div class="post-metadata">

**Author:** ![Jaume\_Puigserver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaume_puigserver/32/70143_2.png) [@Jaume\_Puigserver](https://discuss.elastic.co/u/Jaume_Puigserver)\
**Post date:** [June 16, 2020, 8:20am UTC](https://discuss.elastic.co/t/painless-search/236696/3 "2020-06-16T08:20:37Z")

</div>

Hi,

Thanks for your reply, finally I got working with the following syntax on dev tools

```auto
GET filebeat-*/_search
{
  "query": {
    "bool": {
      "must": [
        {
          "query_string": {
            "query": "event.action: disconnected AND (message: User Requested OR message : timeout)"
          }
        },
        {
          "range": {
            "@timestamp": {
              "gte": "now-100d",
			        "lte": "now"
            }
          }
        }
      ]
    }
  },
 "script_fields": {
   "sc-duration": {
     "script": {
       "lang": "painless",
       "source": "def t = /^.*Duration\\: ([0-9]+)h\\:([0-9]+)m\\:([0-9]+)s/.matcher(doc['message.keyword'].value); if (t.find()) { return Integer.parseInt(t.group(1))* 60 * 60 + Integer.parseInt(t.group(2)) * 60 + Integer.parseInt(t.group(3)) } else { return 0 }"
     }
   }
 }
}

```

But when I go to create the index pattern I only get blank results.  
What I put on the script index is

```auto
def t = /^.*Duration\\: ([0-9]+)h\\:([0-9]+)m\\:([0-9]+)s/.matcher(doc['message.keyword'].value);
if (t.find()) {
   return Integer.parseInt(t.group(1))* 60 * 60 + Integer.parseInt(t.group(2)) * 60 + Integer.parseInt(t.group(3))
} else {
   return 0
}

```

Any idea why it's working on devtools but it could not generate the script field?

thks in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2020, 8:20am UTC](https://discuss.elastic.co/t/painless-search/236696/4 "2020-07-14T08:20:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
