# How to handle '=' in values, splitting on | but KV takes over all '=' not only the first

**URL:** <https://discuss.elastic.co/t/how-to-handle-in-values-splitting-on-but-kv-takes-over-all-not-only-the-first/97851>\
**Category:** Logstash\
**Created:** [August 22, 2017, 5:50am UTC](https://discuss.elastic.co/t/how-to-handle-in-values-splitting-on-but-kv-takes-over-all-not-only-the-first/97851 "2017-08-22T05:50:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [August 22, 2017, 5:50am UTC](https://discuss.elastic.co/t/how-to-handle-in-values-splitting-on-but-kv-takes-over-all-not-only-the-first/97851/1 "2017-08-22T05:50:58Z")

</div>

I'm parsing custom logs. Here's a snippet:  
18.7.2012 9:05:57\t|C3|date=18.07.2012 09:05:57|acronym=BS|... |firstsignUpDate=30.07.2007|bibl001c=m|biblUDK675s=(038)33=111=163.6|....

My second (first one ist just mutate/gsub just to change C3 =\> cir=C3) filter applied is KV

```auto
kv {
	field_split => "|"
}

```

This works fine, until my field containts multiples '=', for example `biblUDK675s=(038)33=111=163.6`.  
I've thought that after splitting with '|' only the part before first = should be taken as key.  
Is there any option to tell KV that `biblUDK675s` is the key and `(038)33=111=163.6` is the value?

---

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [August 23, 2017, 1:34pm UTC](https://discuss.elastic.co/t/how-to-handle-in-values-splitting-on-but-kv-takes-over-all-not-only-the-first/97851/2 "2017-08-23T13:34:10Z")

</div>

This one is solved, if I apply:

```auto
include_brackets => false

```

But if I use a diffrent string:  
18.7.2012 9:05:57\t|C3|date=18.07.2012 09:05:57|acronym=BS|… |firstsignUpDate=30.07.2007|bibl001c=m|biblUDK675s=test AU =fgdgd|…

Then it returns:  
biblUDK675s=test  
AU=fgdgd

But I explicitly applied that field split is "|", why does he uses a fall back?  
In first example, after including brackets, it returned correct, because there was no space.

---

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [August 25, 2017, 6:25am UTC](https://discuss.elastic.co/t/how-to-handle-in-values-splitting-on-but-kv-takes-over-all-not-only-the-first/97851/3 "2017-08-25T06:25:09Z")

</div>

Got no answer here and nothing on KV Github.

I've fixed this using ruby code, and wrote my own filter.  
If it helps somebody:

```auto
ruby {
		code => "
			a = event.get('message').split('|').delete_if{|x| !x.match(/=/)}
			a.each {|y| b = y.split('=', 2)
				event.set(b[0].strip, b[1])
			}"
	}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2017, 6:25am UTC](https://discuss.elastic.co/t/how-to-handle-in-values-splitting-on-but-kv-takes-over-all-not-only-the-first/97851/4 "2017-09-22T06:25:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
