# Split field in elastic

**URL:** <https://discuss.elastic.co/t/split-field-in-elastic/276069>\
**Category:** Logstash\
**Created:** [June 16, 2021, 1:59am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069 "2021-06-16T01:59:07Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [June 16, 2021, 1:59am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069/1 "2021-06-16T01:59:07Z")

</div>

Hi all,  
I have a little problems that needed solving.  
I have a field dns domain dns.question.name has value like this: `a.b.c.d`

Now i want to split this domain into many other domain like tld, sld ..... dynamically without having to use grok since the domain field can be vary with many has only 2 level domain and other has more.

I have check out kv filter but i seem to only work with field that has key:value type and since domain has no key so that a no go for me.

Can any one propose a solution for me.  
Thanks for your time.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 16, 2021, 2:52am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069/2 "2021-06-16T02:52:25Z")

</div>

Are you saying that you want 4 fields, each of which contains a single part of the domain name (i.e. "a", "b", "c", "d") or do you want "a.b.c.d", "b.c.d", "c.d", "d". I assume you also want "a.b.c.d.e.f" handled.

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [June 16, 2021, 3:14am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069/3 "2021-06-16T03:14:41Z")

</div>

> [@Badger](#):
>
> Are you saying that you want 4 fields, each of which contains a single part of the domain name (i.e. "a", "b", "c", "d") or do you want "a.b.c.d", "b.c.d", "c.d", "d"

i want each value in the . to be in a separate field (i.e. "a", "b", "c", "d")

> [@Badger](#):
>
> I assume you also want "a.b.c.d.e.f" handled.

Yes i want that as well

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 16, 2021, 3:33am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069/4 "2021-06-16T03:33:26Z")

</div>

I would use a ruby filter to do that. I am done for the day, so will not post a solution for about 12 hours

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 16, 2021, 5:02pm UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069/5 "2021-06-16T17:02:16Z")

</div>

Try

```
    ruby {
        code => '
            m = event.get("message")
            if m
                m = m.split(".")
                m.each_index { |x|
                    event.set("part#{x+1}", m[x])
                }
            end
        '
    }
```

---

<div class="post-metadata">

**Author:** ![lusynda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lusynda/32/53557_2.png) [@lusynda](https://discuss.elastic.co/u/lusynda)\
**Post date:** [June 17, 2021, 1:37am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069/6 "2021-06-17T01:37:17Z")

</div>

Thanks for the answer.  
But dont mind if i ask what would be the expected output field of this filter.  
I assume to be

```auto
part1:1
part2:2

```

and since this is domain stuff we do care about it from the bottom domain so is there a way to reverse this to the first field to be the last one with the dot.  
eg: [google.com](http://google.com) then i want the part1 to be com and the part2 the google.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 17, 2021, 1:46am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069/7 "2021-06-17T01:46:50Z")

</div>

I wondered if you would ask that 😃 You can try

```
    ruby {
        code => '
            m = event.get("message")
            if m
                m = m.split(".")
                len = m.length
                m.each_index { |x|
                    event.set("part#{len-x}", m[x])
                }
            end
        '
    }

```

which will produce

```
     "part2" => "google",
     "part1" => "com",
   "message" => "google.com"
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2021, 1:47am UTC](https://discuss.elastic.co/t/split-field-in-elastic/276069/8 "2021-07-15T01:47:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
