# Further split logstash output for a particular field

**URL:** <https://discuss.elastic.co/t/further-split-logstash-output-for-a-particular-field/85996>\
**Category:** Logstash\
**Created:** [May 16, 2017, 6:01pm UTC](https://discuss.elastic.co/t/further-split-logstash-output-for-a-particular-field/85996 "2017-05-16T18:01:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![amit.karir](https://avatars.discourse-cdn.com/v4/letter/a/b2d939/32.png) [@amit.karir](https://discuss.elastic.co/u/amit.karir)\
**Post date:** [May 16, 2017, 6:01pm UTC](https://discuss.elastic.co/t/further-split-logstash-output-for-a-particular-field/85996/1 "2017-05-16T18:01:21Z")

</div>

Hi,

I have got my sql server data(from a table) sent to logstash and here is the stdout looks like:

{  
"exception" =\> "A exception with a null response was thrown sending an HTTP request to the remote WebDriver server",  
"process" =\> "Plan",  
**"variables" =\> "(407) 111-1111%Floor_1%Network_Telcom%ISEContactName_Tom smith%ContactEmail_[A.B@GMAIL.COM](mailto:A.B@GMAIL.COM)%EquipmentOption_Template%Procurement_Rental",**  
"profile" =\> "Plan",  
"stepcompleted" =\> "Started Processing",  
"datecreated" =\> 2017-05-16T11:32:28.300Z,  
"inputparam" =\> "ORDER11111,1111111",  
"transactionid" =\> "ORDER11111,1111111uewrutewurt",  
"ordercreationdetails" =\> nil,  
"@timestamp" =\> 2017-05-16T17:42:05.011Z,  
"enddatetime" =\> 2017-05-16T11:45:28.760Z,  
"@version" =\> "1",  
"username" =\> "assistedge.rpa",  
"startdatetime" =\> 2017-05-16T11:32:32.587Z,  
"status" =\> "Failed",  
"applicationwithexception" =\> "AppB"  
}

I need to further split the variables field into logstash fields. The field values are delimited by % and key-value by \*.

Can someone share pointers on how to achieve it?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 18, 2017, 5:31am UTC](https://discuss.elastic.co/t/further-split-logstash-output-for-a-particular-field/85996/2 "2017-05-18T05:31:16Z")

</div>

Look into the kv filter, possibly in conjunction with a grok filter if you want to separate the initial phone number (?) from the key/value pairs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2017, 5:31am UTC](https://discuss.elastic.co/t/further-split-logstash-output-for-a-particular-field/85996/3 "2017-06-15T05:31:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
