# Scripted field for Matching Substring

**URL:** <https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013>\
**Category:** Kibana\
**Created:** [September 3, 2018, 5:07am UTC](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013 "2018-09-03T05:07:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [September 3, 2018, 5:07am UTC](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013/1 "2018-09-03T05:07:47Z")

</div>

Hi,

My setup:  
Kibana 5.6.2  
ES 5.6.2

Need some help to extract the SIM number from the path field in a document  
The field value:

`C:/HWM/Apps/CAR/Export/971XXXXXX231_20180903.CSV`

I need to fetch only the value **971XXXXXX231** as a result for the below mentioned scripted field.

Here is my attempt using the examples mentioned in [scripted help](https://www.elastic.co/blog/using-painless-kibana-scripted-fields)

```
def logger= doc['path.keyword'].value;
if (logger!= null) {
    int lastSlashIndex = logger.lastIndexOf('/');
    if (lastSlashIndex > 0) {
    return logger.substring(lastSlashIndex+1);
    }
}
return "";

```

But the result is 971XXXXXX231\_20180903.CSV

---

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [September 3, 2018, 8:41am UTC](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013/2 "2018-09-03T08:41:12Z")

</div>

Fixed it myself.

```
def logger= doc['path.keyword'].value;
if (logger!= null) {
    int lastSlashIndex = logger.lastIndexOf('/');
    int lastUndrIndex = logger.lastIndexOf('_');
    if (lastSlashIndex > 0) {
    return logger.substring(lastSlashIndex+1,lastUndrIndex);
    }
}
return "";
```

---

<div class="post-metadata">

**Author:** ![Brandon\_Kobel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brandon_kobel/32/14829_2.png) [@Brandon\_Kobel](https://discuss.elastic.co/u/Brandon_Kobel)\
**Post date:** [September 4, 2018, 12:13pm UTC](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013/3 "2018-09-04T12:13:40Z")

</div>

Hey @karnamonkster, I'm glad to hear you were able to solve your issue, thanks for sharing your solution here for others!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2018, 12:13pm UTC](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013/4 "2018-10-02T12:13:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
