# Quick question, Scripted Field hostname + url

**URL:** <https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195>\
**Category:** Kibana\
**Created:** [July 22, 2016, 3:25pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195 "2016-07-22T15:25:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [July 22, 2016, 3:25pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/1 "2016-07-22T15:25:55Z")

</div>

How would someone do to get a "complete hostname with url" field

using : hostname.raw and url.raw

hostname is shown in log as : hostname="[cm.g.doubleclick.net](http://cm.g.doubleclick.net)"  
url is shown as : url="/pixel?google\_nid=eyereturn&g=fde2328d-182e-49fa-a232-8d182ef9fafe&google\_hm=_eIyjRguSfqiMo0YLvn6\_g&google_"

so at the end, I would like to get :

[cm.g.doubleclick.net/pixel?google\_nid=eyereturn&g=fde2328d-182e-49fa-a232-8d182ef9fafe&google\_hm=](http://cm.g.doubleclick.net/pixel?google_nid=eyereturn&g=fde2328d-182e-49fa-a232-8d182ef9fafe&google_hm=)_eIyjRguSfqiMo0YLvn6\_g&google_ as a field.

I assume I can do it in Scripted Field, but I dont see much information about that... anyone already succeed in doing it ?

Thank you !

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [July 22, 2016, 3:49pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/2 "2016-07-22T15:49:53Z")

</div>

What version of Kibana and Elasticsearch are you using?

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [July 22, 2016, 4:02pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/3 "2016-07-22T16:02:35Z")

</div>

latest

kibana 4.4 latest stable build, same for elasticsearch latest build avail on repo

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [July 22, 2016, 4:04pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/4 "2016-07-22T16:04:41Z")

</div>

curl -XGET 'localhost:9200'  
{  
"name" : "Beyonder",  
"cluster\_name" : "elasticsearch",  
"version" : {  
"number" : "2.3.4",  
"build\_hash" : "e455fd0c13dceca8dbbdbb1665d068ae55dabe3f",  
"build\_timestamp" : "2016-06-30T11:24:31Z",  
"build\_snapshot" : false,  
"lucene\_version" : "5.5.0"  
},  
"tagline" : "You Know, for Search"

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [July 22, 2016, 4:21pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/5 "2016-07-22T16:21:02Z")

</div>

So, there currently a limitation with scripted fields that does not allow string manipulation. It's a limitation of Lucene expressions.  
My suggestion would be to do the string concatenation when you index the documents so you have three fields. `hostname`, `url` and `full_url`

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [July 22, 2016, 4:22pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/6 "2016-07-22T16:22:30Z")

</div>

> [@BigFunger](#):
>
> My suggestion would be to do the string concatenation when you index the documents so you have three fields. hostname, url and full\_url

sorry to ask .. but im sort of a newbie limit script kiddy in term of ELK stack, would you mind giving me an exemple ?

plus I assume, I would then have to re-index the whole thing ? or start from scratch ..

right ?

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [July 22, 2016, 5:30pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/7 "2016-07-22T17:30:03Z")

</div>

What are you using to index your documents?

---

<div class="post-metadata">

**Author:** ![gh0stid](https://avatars.discourse-cdn.com/v4/letter/g/f9ae1b/32.png) [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Post date:** [July 22, 2016, 5:34pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/8 "2016-07-22T17:34:33Z")

</div>

I'm not sure I understand ?

I use a logstash input file 10-network.conf that fetch logs from /var/log/network.log using kv filter and some mutate. then output using 50-output.conf

to my elasticsearch..

---

<div class="post-metadata">

**Author:** ![BigFunger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bigfunger/32/7323_2.png) [@BigFunger](https://discuss.elastic.co/u/BigFunger)\
**Post date:** [July 22, 2016, 5:44pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/9 "2016-07-22T17:44:26Z")

</div>

My logstash ability is almost non-existent... but a quick google search turned [this](https://groups.google.com/forum/#!topic/logstash-users/BlZCWDIhcHw) up:

```auto
filter {
  mutate {
    add_field => ["field3", "%{field1} %{field2}"]
  }
}

```

You'll also want to make sure that the field that you're adding is not-analyzed.  
[Elasticsearch mapping-intro Link](https://www.elastic.co/guide/en/elasticsearch/guide/current/mapping-intro.html#_index_2)

And AFAIK, you will have to re-index your data.

I've also been told that when 5.0 launches, you'll be able to create a scripted field that concatenates strings, but that doesn't help you right now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/quick-question-scripted-field-hostname-url/56195/10 "2017-07-06T13:44:44Z")

</div>


