# Separate response time from message field

**URL:** <https://discuss.elastic.co/t/separate-response-time-from-message-field/101017>\
**Category:** Logstash\
**Created:** [September 19, 2017, 12:04pm UTC](https://discuss.elastic.co/t/separate-response-time-from-message-field/101017 "2017-09-19T12:04:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vivek\_Samaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_samaga/32/43285_2.png) [@Vivek\_Samaga](https://discuss.elastic.co/u/Vivek_Samaga)\
**Post date:** [September 19, 2017, 12:04pm UTC](https://discuss.elastic.co/t/separate-response-time-from-message-field/101017/1 "2017-09-19T12:04:41Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2f2c8899e3d6b5af18a07be0be95f68589e3f15.png)

Hi I need to separate the response time in the Screenshot which is "0" and create a new field for it how to do this?

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [September 19, 2017, 6:31pm UTC](https://discuss.elastic.co/t/separate-response-time-from-message-field/101017/2 "2017-09-19T18:31:25Z")

</div>

Is it some kind of web access log? You can use Grok, Dissect, or CSV (if the log is in csv format) to parse.

---

<div class="post-metadata">

**Author:** ![Vivek\_Samaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_samaga/32/43285_2.png) [@Vivek\_Samaga](https://discuss.elastic.co/u/Vivek_Samaga)\
**Post date:** [September 20, 2017, 7:24am UTC](https://discuss.elastic.co/t/separate-response-time-from-message-field/101017/3 "2017-09-20T07:24:07Z")

</div>

Yes those are access logs.  
Now am trying to dissect all the fields  
`10.160.7.4 - - [20/Sep/2017:05:03:19 -0500] 0 "GET /" 200 3493`

`%{IPORHOST:clientip} %{USER:ident} %{USER:ident} \[%{HTTPDATE:timestamp}\] %{NOTSPACE:request}`

This is what i had used for GROK filter what will be the dissect filter for the same logs.  
I used this

```
dissect => {
       mapping => {
        "message" => [
"%{IPORHOST:clientip} %{USER:ident} %{USER:ident} %{USER:auth} \[%{HTTPDATE:timestamp}\] %{NOTSPACE:request} \"(?:%{WORD:verb} \/%{WORD:application}%{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) (?:%{WORD:ServerHost}:%{WORD:ServerPort})"
]
}
}

```

This does not seem to work.

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [September 21, 2017, 3:39am UTC](https://discuss.elastic.co/t/separate-response-time-from-message-field/101017/4 "2017-09-21T03:39:17Z")

</div>

If it's a custom access log, you can play with Grok using [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/). Otherwises, just search in the forum for patterns for common access log types like Apache, nginx, or IIS.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2017, 3:39am UTC](https://discuss.elastic.co/t/separate-response-time-from-message-field/101017/5 "2017-10-19T03:39:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
