# How to extract response and key-values value from response time string of apache logs

**URL:** <https://discuss.elastic.co/t/how-to-extract-response-and-key-values-value-from-response-time-string-of-apache-logs/274991>\
**Category:** Logstash\
**Created:** [June 4, 2021, 2:08pm UTC](https://discuss.elastic.co/t/how-to-extract-response-and-key-values-value-from-response-time-string-of-apache-logs/274991 "2021-06-04T14:08:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![learningelk](https://avatars.discourse-cdn.com/v4/letter/l/3d9bf3/32.png) [@learningelk](https://discuss.elastic.co/u/learningelk)\
**Post date:** [June 4, 2021, 2:08pm UTC](https://discuss.elastic.co/t/how-to-extract-response-and-key-values-value-from-response-time-string-of-apache-logs/274991/1 "2021-06-04T14:08:09Z")

</div>

My logs are as follows :

`::ffff:10.67.0.179 - - [23/Feb/2021:13:55:18 +0000] "GET /files/77570035-bc7e-4be7-9554-e2164dd9397e.otf HTTP/1.1" 200 211 "-" "-" "c37004e0-75de-11eb-b6d4-cb790f9fe1ad" "40.324 ms" "serviceName=file-download-service"`

I have created a pipeline that works but the issue is that I am unable to get rid of "ms " and convert the response time to float , from response time field that is "40.324 ms". Also I am not able to separate "serviceName=file-download-service" field as key value name as I am getting complete value.

Here is the logstash pipeline :

```
input {
  file {
    path => "/Users/learnelk/Documents/logging/logstash/event-data/access.log"
  }
}

filter {

  grok {
    match => { "message" => "%{COMBINEDAPACHELOG} %{QS:coid} %{QS:responsetime} %{GREEDYDATA:sn}" }
  }
  mutate {
    remove_field => ["message", "referrer", "agent"]
    gsub => [
      "coid", '"', "",
      "responsetime", "ms", "",
      "responsetime", '"', "",
      "responsetime", ' ', "",
      "sn", '"', ""
    ]
    convert => {
      "response" => "integer"
      "bytes" => "integer"
    }
  }
}

output {
  stdout {
    codec => rubydebug
  }
}

```

Here is the output that I get :

```
{
              "sn" => "serviceName=file-download-service",
            "path" => "/Users/learnelk/Documents/logging/logstash/event-data/upload-access.log",
            "verb" => "GET",
           "bytes" => 211,
     "httpversion" => "1.1",
        "@version" => "1",
        "clientip" => "::ffff:10.67.0.179",
        "response" => 200,
    "responsetime" => "40.324",
            "coid" => "c37004e0-75de-11eb-b6d4-cb790f9fe1ad",
         "request" => "/files/77570035-bc7e-4be7-9554-e2164dd9397e.otf",
      "@timestamp" => 2021-06-04T12:15:08.604Z,
            "host" => "learnelk-mac.local",
            "auth" => "-",
           "ident" => "-",
       "timestamp" => "23/Feb/2021:13:55:18 +0000"
}

```

Kindly help .

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 4, 2021, 4:02pm UTC](https://discuss.elastic.co/t/how-to-extract-response-and-key-values-value-from-response-time-string-of-apache-logs/274991/2 "2021-06-04T16:02:19Z")

</div>

You can use mutate+convert to convert [responsetime] to a float, and you can use a kv filter to parse [sn].

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2021, 4:02pm UTC](https://discuss.elastic.co/t/how-to-extract-response-and-key-values-value-from-response-time-string-of-apache-logs/274991/3 "2021-07-02T16:02:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
