# Transform -\> Field Extraction Example to GroupBy

**URL:** <https://discuss.elastic.co/t/transform-field-extraction-example-to-groupby/304155>\
**Category:** Elasticsearch\
**Tags:** transforms\
**Created:** [May 6, 2022, 7:46pm UTC](https://discuss.elastic.co/t/transform-field-extraction-example-to-groupby/304155 "2022-05-06T19:46:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lupolo](https://avatars.discourse-cdn.com/v4/letter/l/5fc32e/32.png) [@lupolo](https://discuss.elastic.co/u/lupolo)\
**Post date:** [May 6, 2022, 7:46pm UTC](https://discuss.elastic.co/t/transform-field-extraction-example-to-groupby/304155/1 "2022-05-06T19:46:01Z")

</div>

Under a transform query one of the results I get is this key value pair

`:"request_User-Agent": "idType=drwet; rmtSVer=2.2.2.4; wqHVer=2.3.2.0; idName=swawsw; idRolt=2.85T",`

I would like to "group\_by" `stbName` .

Could someone show an example about how to extract the key:value of `idName ` . So I can group by `idName ` ?

Thanks in advance!  
Lp

---

<div class="post-metadata">

**Author:** ![przemekwitek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/przemekwitek/32/79526_2.png) [@przemekwitek](https://discuss.elastic.co/u/przemekwitek)\
**Post date:** [May 9, 2022, 8:25am UTC](https://discuss.elastic.co/t/transform-field-extraction-example-to-groupby/304155/2 "2022-05-09T08:25:11Z")

</div>

Hi,  
Is `request_User-Agent` one of the fields in your source index (i.e. the index you provide as an input to the transform)?  
If so, then you can configure a runtime field `idName` which will be computed with a script. The script will extract the `swawsw` string from the `request_User-Agent` field.

Here is the relevant portion of the transform's config:

```auto
PUT _transform/transform-by-id
{
  "source": {
    "index": ["source-index"],
    "runtime_mappings": {
      "idName": {
        "type": "keyword",
        "script": "PLEASE DEVELOP YOUR ID-EXTRACTING SCRIPT HERE"
      }
    }
  },
  ...
}

```

---

<div class="post-metadata">

**Author:** ![lupolo](https://avatars.discourse-cdn.com/v4/letter/l/5fc32e/32.png) [@lupolo](https://discuss.elastic.co/u/lupolo)\
**Post date:** [May 9, 2022, 11:50am UTC](https://discuss.elastic.co/t/transform-field-extraction-example-to-groupby/304155/3 "2022-05-09T11:50:32Z")

</div>

Thanks for the example. It works as intended.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2022, 11:50am UTC](https://discuss.elastic.co/t/transform-field-extraction-example-to-groupby/304155/4 "2022-06-06T11:50:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
