# Query time field extraction and pattern capture token filter

**URL:** <https://discuss.elastic.co/t/query-time-field-extraction-and-pattern-capture-token-filter/43790>\
**Category:** Elasticsearch\
**Created:** [March 8, 2016, 3:05pm UTC](https://discuss.elastic.co/t/query-time-field-extraction-and-pattern-capture-token-filter/43790 "2016-03-08T15:05:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![michelecappelletti](https://avatars.discourse-cdn.com/v4/letter/m/e0b2c6/32.png) [@michelecappelletti](https://discuss.elastic.co/u/michelecappelletti)\
**Post date:** [March 8, 2016, 3:05pm UTC](https://discuss.elastic.co/t/query-time-field-extraction-and-pattern-capture-token-filter/43790/1 "2016-03-08T15:05:41Z")

</div>

Hi,  
I've found that elasticsearch doesn't support query time field extraction, like splunk for example..:  
`sourcetype=* POST| rex field=_raw "\"POST (?<url>.*) HTTP\/1\.1\" (?<status_code>[0-9]+) (?<body_size>[0-9]+) (?<response_time>[0-9]+)" | timechart span=1d avg(response_time) by url`

and im trying to achieve a workaround: the only thing that i've found in the doc that seems to treat this argument is pattern capture token filter..

[https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pattern-capture-tokenfilter.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/analysis-pattern-capture-tokenfilter.html)

but i can't really understand how to use it and even if it's really something that can help me in my intent.

So, every suggest is welcome

regards,  
Michele

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [March 8, 2016, 3:23pm UTC](https://discuss.elastic.co/t/query-time-field-extraction-and-pattern-capture-token-filter/43790/2 "2016-03-08T15:23:54Z")

</div>

> [@michelecappelletti](#):
>
> but i can't really understand how to use it and even if it's really something that can help me in my intent.

It's an index time thing, not a query time thing.

I don't know splunk but I presume you are looking for some way to extract fields at query time. Elasticsearch's thing for this is [script fields](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-script-fields.html) particularly the bit about `_source`. It doesn't support the kind of named regex thing you are using.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:10pm UTC](https://discuss.elastic.co/t/query-time-field-extraction-and-pattern-capture-token-filter/43790/3 "2017-07-05T23:10:19Z")

</div>


