# Scripted field for Matching Substring

**URL:** <https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013>\
**Category:** Kibana\
**Created:** [September 3, 2018, 5:07am UTC](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013 "2018-09-03T05:07:47Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![karnamonkster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karnamonkster/32/67266_2.png) [@karnamonkster](https://discuss.elastic.co/u/karnamonkster)\
**Post date:** [September 3, 2018, 8:41am UTC](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013/2 "2018-09-03T08:41:12Z")

</div>

Fixed it myself.

```
def logger= doc['path.keyword'].value;
if (logger!= null) {
    int lastSlashIndex = logger.lastIndexOf('/');
    int lastUndrIndex = logger.lastIndexOf('_');
    if (lastSlashIndex > 0) {
    return logger.substring(lastSlashIndex+1,lastUndrIndex);
    }
}
return "";
```

---

_[View the full topic](https://discuss.elastic.co/t/scripted-field-for-matching-substring/147013)._
