# Can't parse field

**URL:** https://discuss.elastic.co/t/cant-parse-field/26557
**Category:** Logstash
**Created:** [July 30, 2015, 10:09am UTC](https://discuss.elastic.co/t/cant-parse-field/26557 "2015-07-30T10:09:02Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![Smasell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smasell/32/43483_2.png) [@Smasell](https://discuss.elastic.co/u/Smasell)
#### Post date: [July 30, 2015, 10:09am UTC](https://discuss.elastic.co/t/cant-parse-field/26557/1 "2015-07-30T10:09:02Z")

</div>

Hey,

I have message:  
"message": "[Fri Jul 24 23:34:09 2015] [error] [client 217.118.78.107] device-model=Fly+IQ4415+Quad&ram=456&build-type=etc1", All I want is to parse 3 fields:

"device\_model": "Fly IQ4415 Quad"  
"ram": "456"  
"build\_type": "etc1"

THX for helping me!!!

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 30, 2015, 1:27pm UTC](https://discuss.elastic.co/t/cant-parse-field/26557/2 "2015-07-30T13:27:44Z")

</div>

You can use grok to extract "device-model=Fly+IQ4415+Quad&ram=456&build-type=etc1" into a field and then use the [kv filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html) to extract the three fields you're interested in. Finally, use the [urldecode filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-urldecode.html) to turn "Fly+IQ4415+Quad" into "Fly IQ4415 Quad".

---

<div class="post-metadata">

### Author: ![Smasell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smasell/32/43483_2.png) [@Smasell](https://discuss.elastic.co/u/Smasell)
#### Post date: [August 11, 2015, 4:59pm UTC](https://discuss.elastic.co/t/cant-parse-field/26557/3 "2015-08-11T16:59:35Z")

</div>

@magnusbaeck

can you help me with urldecoder filter to turn "Fly+IQ4415+Quad" into "Fly IQ4415 Quad". I can't get it!

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 11, 2015, 5:26pm UTC](https://discuss.elastic.co/t/cant-parse-field/26557/4 "2015-08-11T17:26:38Z")

</div>

Hmm. It seems Ruby's URI module doesn't decode plus signs to spaces. My RFC-fu isn't strong enough to explain why this is the correct behavior (if indeed it is). I suggest you use a mutate filter to replace plus signs with spaces and use urldecode for other encoded characters that potentially could occur in the string.

```
mutate {
  gsub => ["device-model", "\+", " "]
}
```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:32am UTC](https://discuss.elastic.co/t/cant-parse-field/26557/5 "2017-07-06T05:32:18Z")

</div>


