# Trying to create a scripted field in Kibana

**URL:** <https://discuss.elastic.co/t/trying-to-create-a-scripted-field-in-kibana/182471>\
**Category:** Kibana\
**Created:** [May 23, 2019, 2:46pm UTC](https://discuss.elastic.co/t/trying-to-create-a-scripted-field-in-kibana/182471 "2019-05-23T14:46:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![nicks1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicks1993/32/84627_2.png) [@nicks1993](https://discuss.elastic.co/u/nicks1993)\
**Post date:** [May 23, 2019, 2:46pm UTC](https://discuss.elastic.co/t/trying-to-create-a-scripted-field-in-kibana/182471/1 "2019-05-23T14:46:41Z")

</div>

I have a log with a message field that I want to parse a "time" field out of.

for example:  
message: words::words::words (time=517, words)  
is an example of my message field. I want to create a field called time containing the value 517. How can I go about this in Kibana. I read a few tutorials but the resources seem limited

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [May 23, 2019, 3:09pm UTC](https://discuss.elastic.co/t/trying-to-create-a-scripted-field-in-kibana/182471/2 "2019-05-23T15:09:11Z")

</div>

You can use Java string operations to find the index of `time=` and the first index of `,` after the time and finally return a substring between those values.  
But, I highly recommend against this solutions, string operations are costly to do in scripted fields and they will run for every document in your search. The best time to parse that string is at ingest time, with a Logstash filter.

---

<div class="post-metadata">

**Author:** ![nicks1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicks1993/32/84627_2.png) [@nicks1993](https://discuss.elastic.co/u/nicks1993)\
**Post date:** [May 23, 2019, 3:16pm UTC](https://discuss.elastic.co/t/trying-to-create-a-scripted-field-in-kibana/182471/3 "2019-05-23T15:16:16Z")

</div>

Sweet, nice. It may end up moving into fluentd or logstash someday, but for now the company I'm at just wants to see the field and if it is useful we can parse it at ingest time.  
Thanks.

So could I do something like this.

```
def msg = doc['message'].value;
def index1 = msg.indexOf("=");
def index2 = msg.indexOf(",");
msg=msg.subString(index1+1,index2);
int num = Integer.parseInt(msg);
return num;

```

I'm just a bit confused about how to get the message string from the fields.

---

<div class="post-metadata">

**Author:** ![nicks1993](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nicks1993/32/84627_2.png) [@nicks1993](https://discuss.elastic.co/u/nicks1993)\
**Post date:** [May 23, 2019, 4:26pm UTC](https://discuss.elastic.co/t/trying-to-create-a-scripted-field-in-kibana/182471/4 "2019-05-23T16:26:12Z")

</div>

I am unable to do anything with my message field. Is this because the field in not aggregatable?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2019, 4:26pm UTC](https://discuss.elastic.co/t/trying-to-create-a-scripted-field-in-kibana/182471/5 "2019-06-20T16:26:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
