# Auto Field Detection in Logs

**URL:** <https://discuss.elastic.co/t/auto-field-detection-in-logs/42543>\
**Category:** Logstash\
**Created:** [February 24, 2016, 1:13am UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543 "2016-02-24T01:13:24Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [February 24, 2016, 1:13am UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543/1 "2016-02-24T01:13:24Z")

</div>

Is there a way to write grok pattern such that it will automatically detect fields and parse it into elasticsearch. I am hoping to eliminate the need to constantly create grok patterns to recognize new log patterns

For example all the fields start with field\_name = fieldvalue  
src\_ip = 10.1.1.223 src\_port = 8080

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 24, 2016, 6:45am UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543/2 "2016-02-24T06:45:28Z")

</div>

Look at the kv filter.

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [February 24, 2016, 7:24am UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543/3 "2016-02-24T07:24:00Z")

</div>

I can see that within Logstash there is already predefined grok patterns for firewall like Juniper.

So under what kind of situation should we use customized grok pattern and what kind of situation should we use the KV filter?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 24, 2016, 8:44am UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543/4 "2016-02-24T08:44:57Z")

</div>

If it's key/value data I see no reason to use grok unless the keys are very static (in which case the maintenance burden is low).

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [February 25, 2016, 12:50am UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543/5 "2016-02-25T00:50:23Z")

</div>

So why would the Logstash contain a grok pattern for Juniper while the same can be achieved with kv filter? I am trying understand the rational of why it is there. 🙂

Is there a way to modify the KV filter such that its can process key/value in the form of "mykey:myvalue" instead of the existing form "mykey=myvalue"?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 25, 2016, 3:26pm UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543/6 "2016-02-25T15:26:38Z")

</div>

> So why would the Logstash contain a grok pattern for Juniper while the same can be achieved with kv filter?

I don't know.

> Is there a way to modify the KV filter such that its can process key/value in the form of "mykey:myvalue" instead of the existing form "mykey=myvalue"?

Yes. Please explore the various configuration options listed in the [kv filter documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html).

---

<div class="post-metadata">

**Author:** ![gringo](https://avatars.discourse-cdn.com/v4/letter/g/f19dbf/32.png) [@gringo](https://discuss.elastic.co/u/gringo)\
**Post date:** [March 1, 2016, 3:08am UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543/7 "2016-03-01T03:08:29Z")

</div>

Thank you for your help! I am now able to do what I need 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/auto-field-detection-in-logs/42543/8 "2017-07-06T05:09:14Z")

</div>


