# Split message field into multiple fields in kibana

**URL:** <https://discuss.elastic.co/t/split-message-field-into-multiple-fields-in-kibana/249262>\
**Category:** Kibana\
**Created:** [September 20, 2020, 4:02pm UTC](https://discuss.elastic.co/t/split-message-field-into-multiple-fields-in-kibana/249262 "2020-09-20T16:02:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chand/32/69706_2.png) [@chand](https://discuss.elastic.co/u/chand)\
**Post date:** [September 20, 2020, 4:02pm UTC](https://discuss.elastic.co/t/split-message-field-into-multiple-fields-in-kibana/249262/1 "2020-09-20T16:02:42Z")

</div>

I've the following data for the `message` field which is being shipped by filebeat to elasticseatch. I am not using Logstash here

```auto
2020-09-20 15:44:23 ::1 get / - 80 - ::1 mozilla/5.0+(windows+nt+10.0;+win64;+x64)+windows/537.36+(khtml,+like+gecko)+chrome/85.0.4183.102+chrome/537.36 - 200 0 0 10

```

I want to split the above data at every space and assign them to different fields and the new fields should get reflect in the kibana discovery portal.

How can we do that?

I've tried to use scripted field in kibana, but I am unable to achieve it as I am not aware of scripted field querying.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 20, 2020, 9:52pm UTC](https://discuss.elastic.co/t/split-message-field-into-multiple-fields-in-kibana/249262/2 "2020-09-20T21:52:04Z")

</div>

Welcome to our community! 😃

The best path is to do the processing before it is indexed. Those logs look like HTTP access logs, what is the source of them?

---

<div class="post-metadata">

**Author:** ![chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chand/32/69706_2.png) [@chand](https://discuss.elastic.co/u/chand)\
**Post date:** [September 21, 2020, 2:04am UTC](https://discuss.elastic.co/t/split-message-field-into-multiple-fields-in-kibana/249262/3 "2020-09-21T02:04:01Z")

</div>

@warkolm These are IIS logs getting shipped by Filebeat. The last field '10' is time-taken is somehow the not getting shipped. So I decided to split and assign the last value to a new field so that it gets showed in Kibana discovery portal.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 21, 2020, 2:30am UTC](https://discuss.elastic.co/t/split-message-field-into-multiple-fields-in-kibana/249262/4 "2020-09-21T02:30:43Z")

</div>

Are you using the IIS module? [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-iis.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-iis.html)

---

<div class="post-metadata">

**Author:** ![chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chand/32/69706_2.png) [@chand](https://discuss.elastic.co/u/chand)\
**Post date:** [September 21, 2020, 5:39am UTC](https://discuss.elastic.co/t/split-message-field-into-multiple-fields-in-kibana/249262/5 "2020-09-21T05:39:05Z")

</div>

@warkolm Yes, I am using IIS module but it is not shipping time-taken field.

FYI: Below are my filebeat and IIS module config files

filebeat.yml

```
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - c:\inetpub\logs\Logfiles\*\*

filebeat.config.modules:
  path: C:\Program Files\filebeat\modules.d\*.yml
  reload.enabled: true
  reload.period: 10s

setup.template.settings:
  index.number_of_shards: 1
setup.kibana:
  host: "<Kibana_IP>:5601"

output.elasticsearch:
  hosts: ["<Elasticsearch Master IP>:9200"]

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - add_kubernetes_metadata: ~

```

iis.yml

```
- module: iis
 access:
   enabled: true
   #var.paths:

 error:
   enabled: true
   #var.paths:

```

I've also specified the logs path in `iis.yml` config file at `var.paths` but it is also not exporting the time-taken field

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2020, 5:39am UTC](https://discuss.elastic.co/t/split-message-field-into-multiple-fields-in-kibana/249262/6 "2020-10-19T05:39:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
