# Parsing a Concatenated Field to Extract Sub-Fields

**URL:** <https://discuss.elastic.co/t/parsing-a-concatenated-field-to-extract-sub-fields/276523>\
**Category:** Logstash\
**Created:** [June 21, 2021, 10:31am UTC](https://discuss.elastic.co/t/parsing-a-concatenated-field-to-extract-sub-fields/276523 "2021-06-21T10:31:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fmaginga](https://avatars.discourse-cdn.com/v4/letter/f/bbce88/32.png) [@fmaginga](https://discuss.elastic.co/u/fmaginga)\
**Post date:** [June 21, 2021, 10:31am UTC](https://discuss.elastic.co/t/parsing-a-concatenated-field-to-extract-sub-fields/276523/1 "2021-06-21T10:31:14Z")

</div>

Hello,

I am trying to write a logstash filter to extract individual sub-fields from on concatenated field.

Example:

I have a field CGI = 640070003110080

```auto
CGI = 640070003110080

```

I want to split the CGI field in to four other fields as follows;

```auto
MCC = 640
MNC = 07
LAC = 00031
CellID = 10080

```

CGI is always 15 digits long, 1st to 3rd digits are MCC, 4th to 5th digits are MNC, 6th to 10th digits are LAC and 11th to 15th digits are CellID

Which filter plugin can I use? I tried to search I could not find any so far.

Best Regards,  
Frank

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [June 21, 2021, 11:05am UTC](https://discuss.elastic.co/t/parsing-a-concatenated-field-to-extract-sub-fields/276523/2 "2021-06-21T11:05:36Z")

</div>

Hi,

You can use grok like this on the CGI field

```auto
(?<MCC>[0-9]{3})(?<MNC>[0-9]{2})(?<LAC>[0-9]{5})(?<CellID>[0-9]{5})

```

`<MCC>` specify what is the name of the new field. The name is followed by a pattern `[0-9]{3}`.  
`[0-9]` specify what i search. Here i search digit between 0 and 9 include.  
`{3}` specify the number of digit i want to find. Here 3.

For each new field, i copy past the first configuration and change the name of the field and the number of digit i search.

The final grok filter looks like this:

```auto
grok {
  match => { "CGI" => "(?<MCC>[0-9]{3})(?<MNC>[0-9]{2})(?<LAC>[0-9]{5})(?<CellID>[0-9]{5})" }
}

```

Cad.

---

<div class="post-metadata">

**Author:** ![fmaginga](https://avatars.discourse-cdn.com/v4/letter/f/bbce88/32.png) [@fmaginga](https://discuss.elastic.co/u/fmaginga)\
**Post date:** [June 21, 2021, 11:29am UTC](https://discuss.elastic.co/t/parsing-a-concatenated-field-to-extract-sub-fields/276523/3 "2021-06-21T11:29:23Z")

</div>

Thanks @Cad, it worked!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2021, 11:29am UTC](https://discuss.elastic.co/t/parsing-a-concatenated-field-to-extract-sub-fields/276523/4 "2021-07-19T11:29:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
