# How can I make iteration & loop in logstash?

**URL:** <https://discuss.elastic.co/t/how-can-i-make-iteration-loop-in-logstash/891>\
**Category:** Logstash\
**Created:** [May 19, 2015, 10:16am UTC](https://discuss.elastic.co/t/how-can-i-make-iteration-loop-in-logstash/891 "2015-05-19T10:16:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kimjmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimjmin/32/15223_2.png) [@kimjmin](https://discuss.elastic.co/u/kimjmin)\
**Post date:** [May 19, 2015, 10:16am UTC](https://discuss.elastic.co/t/how-can-i-make-iteration-loop-in-logstash/891/1 "2015-05-19T10:16:40Z")

</div>

Hi, I have string data looks like next.

```
"detail":"B01=10,B02=10,BANK02=10,BANK01=50,F04=10"

```

I want parse the value of "detail" field.  
First I split with character ","

```
"detail":["B01=10","B02=10","BANK02=10","BANK01=50","F04=10"]

```

and for finally I want get field look like next.

```
"detal_new" : { "B01" : 10, "B02" : 10, "BANK02": 10, "BANK01" : 50, "F04" : 10 }

```

Now, I need make a loop with "detail" field, and have to split each value with "=".  
Then I guess make another object type field with %{value[0]} =\> %{value[1]}.  
I heard that if I want make loop in Logstash, I have to use ruby filter. Unfortunately I'm not familiar with ruby.  
Can anyone help me how this can be figured out?

Thank you, for reading and helping me.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 19, 2015, 11:12am UTC](https://discuss.elastic.co/t/how-can-i-make-iteration-loop-in-logstash/891/2 "2015-05-19T11:12:53Z")

</div>

Just use the [kv filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html).

```
filter {
  kv {
    source => "detail"
    target => "detail_new"
    field_split => ","
  }
}

```

The values will be strings instead of numbers, but you can use a [mutate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html) for the type conversion. If you don't know which fields you've got you'll indeed probably have to use a [ruby filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html).

---

<div class="post-metadata">

**Author:** ![kimjmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimjmin/32/15223_2.png) [@kimjmin](https://discuss.elastic.co/u/kimjmin)\
**Post date:** [May 19, 2015, 12:12pm UTC](https://discuss.elastic.co/t/how-can-i-make-iteration-loop-in-logstash/891/3 "2015-05-19T12:12:40Z")

</div>

I didn't tried kv filter before.  
I tryed and it works perfectly. I got exact data I wanted. Thanks a lot 😄

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/how-can-i-make-iteration-loop-in-logstash/891/4 "2017-07-06T05:39:41Z")

</div>


