# Replace and Datatype conversion

**URL:** <https://discuss.elastic.co/t/replace-and-datatype-conversion/254491>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [November 6, 2020, 7:39am UTC](https://discuss.elastic.co/t/replace-and-datatype-conversion/254491 "2020-11-06T07:39:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesh\_Kannan\_K\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ganesh_kannan_k_s/32/50604_2.png) [@Ganesh\_Kannan\_K\_S](https://discuss.elastic.co/u/Ganesh_Kannan_K_S)\
**Post date:** [November 6, 2020, 7:39am UTC](https://discuss.elastic.co/t/replace-and-datatype-conversion/254491/1 "2020-11-06T07:39:00Z")

</div>

/Folder enumeration completed (6 s)/

This is a sample log. I need to get the number from this string Message. So I tried to split , replace and convert. That didn't work. I tried to create a scripted field first by splitting the token and then converting that field. Didn't work either. Can anyone tell me which is the best way to do this.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 6, 2020, 7:46am UTC](https://discuss.elastic.co/t/replace-and-datatype-conversion/254491/2 "2020-11-06T07:46:51Z")

</div>

Hi,

Welcome to this forum! 🥳

Do you really need to get the data from within Kibana or would it be possible to parse that while ingesting? While ingesting(either using [Elasticsearch ingest pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/master/grok-processor.html) or [LogStash pipeline](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)) you can use the following grok pattern: `/%{DATA:action} \(%{NUMBER:duration} %{DATA:unit}\)/`

This gives you the following result:

```auto
{
  "duration": "6",
  "unit": "s",
  "action": "Folder enumeration completed"
}

```

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Ganesh\_Kannan\_K\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ganesh_kannan_k_s/32/50604_2.png) [@Ganesh\_Kannan\_K\_S](https://discuss.elastic.co/u/Ganesh_Kannan_K_S)\
**Post date:** [November 6, 2020, 11:25am UTC](https://discuss.elastic.co/t/replace-and-datatype-conversion/254491/3 "2020-11-06T11:25:05Z")

</div>

Thank you so much Wolfram. I was able to change it during ingestion.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2020, 11:25am UTC](https://discuss.elastic.co/t/replace-and-datatype-conversion/254491/4 "2020-12-04T11:25:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
