# Targeting Field Content

**URL:** <https://discuss.elastic.co/t/targeting-field-content/249543>\
**Category:** Logstash\
**Created:** [September 22, 2020, 3:07pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543 "2020-09-22T15:07:31Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [September 22, 2020, 3:07pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/1 "2020-09-22T15:07:31Z")

</div>

Hi,  
I am trying to get grok to target certain fields and extract the content that follows. For example:

`<c_port>3186</c_port>`

I want to find c\_port and extract the number that follows, in this case 3186. I have tried number of ways and cant seem to get this functionality. Thank you.

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [September 22, 2020, 3:38pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/2 "2020-09-22T15:38:38Z")

</div>

During my log onboarding, I have a similar situation.  
I use mutate gsub instead.

So for your situation, we can use a regex to specify what to capture.

```auto
    mutate {
          gsub => ["field_name", "[^\d]*(\d+)[^\>]*\>", "\1"]
        }

```

hope this can help you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 22, 2020, 3:52pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/3 "2020-09-22T15:52:25Z")

</div>

You could do that using grok or dissect. If the entire [message] is XML then you also have the option of using an xml filter.

---

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [September 22, 2020, 3:55pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/4 "2020-09-22T15:55:34Z")

</div>

Thank you Kavierkoo.  
As Badger suggested, I would prefer to use the XML filter or grok option but I can't seem to find how to make either of those two give me the value (3186) that follows that field (\<c\_port\>). Can I get a hint on how I may incorporate the XML filter or grok to accomplish this?

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [September 22, 2020, 3:59pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/5 "2020-09-22T15:59:31Z")

</div>

this is a good and better idea!

---

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [September 22, 2020, 4:06pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/6 "2020-09-22T16:06:21Z")

</div>

Thank you Kavierkoo.  
As Badger suggested, I would prefer to use the XML filter or grok option but I can't seem to find how to make either of those two give me the value (3186) that follows that field (\<c\_port\>). Can I get a hint on how I may incorporate the XML filter or grok to accomplish this?

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [September 22, 2020, 4:13pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/7 "2020-09-22T16:13:07Z")

</div>

Looks like this could help you.

#### `overwrite` [edit](https://github.com/logstash-plugins/logstash-filter-grok/edit/master/docs/index.asciidoc)

- Value type is [array](https://www.elastic.co/guide/en/logstash/master/configuration-file-structure.html#array)
- Default value is `[]`

The fields to overwrite.

This allows you to overwrite a value in a field that already exists.

For example, if you have a syslog line in the `message` field, you can overwrite the `message` field with part of the match like so:

```auto
    filter {
      grok {
        match => { "message" => "%{SYSLOGBASE} %{DATA:message}" }
        overwrite => ["message"]
      }
    }

```

In this case, a line like `May 29 16:37:11 sadness logger: hello world` will be parsed and `hello world` will overwrite the original message.

> **[Grok filter plugin | Logstash Reference \[master\] | Elastic](https://www.elastic.co/guide/en/logstash/master/plugins-filters-grok.html#plugins-filters-grok-overwrite)**

---

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [September 22, 2020, 4:50pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/8 "2020-09-22T16:50:36Z")

</div>

> [@teej](#):
>
> \<c\_port\>3186\</c\_port\>

Kavierkoo,  
Thank you for your kindness in taking the time to help me out. I apologize for beating the dead horse but what I am looking to do is not overwrite anything. I am trying to find a field title - in this case `<c_port>` and then extracting the the content that follows - in this case `3186` but ignoring the end closing portion - in this case` </c_port>`.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 22, 2020, 4:52pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/9 "2020-09-22T16:52:35Z")

</div>

> [@teej](#):
>
> I would prefer to use the XML filter

This configuration

```
input { generator { count => 1 lines => ['<a><c_port>3186</c_port></a>'] } }
filter {
    xml {
        source => "message"
        store_xml => false
        xpath => { "/a/c_port/text()" => "c_port" }
    }
    mutate { replace => { "c_port" => "%{[c_port][0]}" } }
    mutate { convert => { "c_port" => "integer" } }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

produces

```
    "c_port" => 3186,

```

Note that [message] must be a complete and valid XML document for this to work.

To give a better example of the filter configuration I would need to see the complete document, and yes, I realize that may not be possible for you to post.

---

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [September 22, 2020, 5:50pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/10 "2020-09-22T17:50:52Z")

</div>

😵 Wow Badger, did you use a tool for this or did that come out of your head that fast? That worked immediately (of course) but my input will read from a file such as what follows -which may be wrong for the intended work but still the input will come from a file:

```
  input {
    file {
      path => "/tmp/test2.xml"
      sincedb_path => "/dev/null"
      start_position => "beginning"
      codec => multiline {
        pattern => "^<name=*\>"
        auto_flush_interval => 1
        negate => "true"
        what => "previous"
        max_lines => 1000000000
        max_bytes => "500 MiB"
  }}

```

Whereas the line provided works beautifully but I am not sure how to incorporate it so that it does what it does after reading in the file:

`input { generator { count => 1 lines => ['<a><c_port>3186</c_port></a>'] } }`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 22, 2020, 7:11pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/11 "2020-09-22T19:11:34Z")

</div>

> [@teej](#):
>
> input { generator { count =\> 1 lines =\> ['\<c\_port\>3186\</c\_port\>'] } }

You would not use that, I was just using it to provide an event where the [message] field was valid XML. Provided your multiline codec consumes a single complete XML document you should be OK.

---

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [September 22, 2020, 10:37pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/12 "2020-09-22T22:37:50Z")

</div>

hummm. when I feed it a file it simply returns:  
`"c_port" => 0`

if I take the \<c\_port\>33186\</c\_port\> portion out of the input file, I still get:  
`"c_port" => 0`

My input file starts with:

```
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<ns2:bcLogEntry xmlns:ns2="http://www.yahoo.com/wcf/log/v1_0">
    <alert_id>AS01WCF0000000000000001894</alert_id>
    <c_ip>fee3:e1ad:e1ad:daba::3</c_ip>
    <c_port>3186</c_port>
    <cs_Accept_>*/*</cs_Accept_>
    <cs_Accept __length>3</cs_Accept__ length>
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 22, 2020, 10:56pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/13 "2020-09-22T22:56:40Z")

</div>

> [@teej](#):
>
> ```auto
> <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
> <ns2:bcLogEntry xmlns:ns2="http://www.yahoo.com/wcf/log/v1_0">
> <alert_id>AS01WCF0000000000000001894</alert_id>
> <c_ip>fee3:e1ad:e1ad:daba::3</c_ip>
> <c_port>3186</c_port>
> <cs_Accept_>*/*</cs_Accept_>
> <cs_Accept __length>3</cs_Accept__ length>
> 
> ```

Using xpath in logstash with namespaces is beyond my talents. You could try

```
    xml {
        source => "message"
        store_xml => true
        target => "theXML"
        force_array => false
    }
    mutate { replace => { "c_port" => "%{[theXML][c_port]}" } }
    mutate { convert => { "c_port" => "integer" } }

```

---

<div class="post-metadata">

**Author:** ![Puneeth\_S\_B\_Gowda1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/puneeth_s_b_gowda1/32/68544_2.png) [@Puneeth\_S\_B\_Gowda1](https://discuss.elastic.co/u/Puneeth_S_B_Gowda1)\
**Post date:** [September 23, 2020, 6:15am UTC](https://discuss.elastic.co/t/targeting-field-content/249543/14 "2020-09-23T06:15:54Z")

</div>

> [@teej](#):
>
> 3186

try xpath something like this

below one is my xpath you could try your one with below config  
xpath =\>[  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan/@id","ratePlanid" ]  
}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 23, 2020, 2:04pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/15 "2020-09-23T14:04:38Z")

</div>

I figured out how to get it done when there is a namespace...

```
    xml {
        source => "message"
        store_xml => false
        namespaces => { "ns2" => "http://www.yahoo.com/wcf/log/v1_0" }
        xpath => { "/ns2:bcLogEntry/c_port/text()" => "c_port" }
    }
    mutate { replace => { "c_port" => "%{[c_port][0]}" } }
    mutate { convert => { "c_port" => "integer" } }
```

---

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [September 24, 2020, 8:10pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/16 "2020-09-24T20:10:05Z")

</div>

Thank you Puneeth.

---

<div class="post-metadata">

**Author:** ![teej](https://avatars.discourse-cdn.com/v4/letter/t/b5a626/32.png) [@teej](https://discuss.elastic.co/u/teej)\
**Post date:** [September 24, 2020, 8:10pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/17 "2020-09-24T20:10:42Z")

</div>

Thank you Badger, this did the trick. Appreciate it very much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2020, 8:10pm UTC](https://discuss.elastic.co/t/targeting-field-content/249543/18 "2020-10-22T20:10:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
