# How to Handle Metadata in File Headers

**URL:** <https://discuss.elastic.co/t/how-to-handle-metadata-in-file-headers/167544>\
**Category:** Logstash\
**Created:** [February 7, 2019, 10:16pm UTC](https://discuss.elastic.co/t/how-to-handle-metadata-in-file-headers/167544 "2019-02-07T22:16:25Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 8, 2019, 1:02am UTC](https://discuss.elastic.co/t/how-to-handle-metadata-in-file-headers/167544/2 "2019-02-08T01:02:33Z")

</div>

Try something like

```
    if [message] == "[Metadata]" or [message] == "[Events]" or [message] =~ /^$/ {
        drop {}
    } else {
        if [message] =~ /^[0-9a-zA-Z]+:/ {
            dissect { mapping => { "message" => "%{key}: %{value}" } }
            ruby {
                init => '
                    @@metadata = {}
                '
                code => '
                    @@metadata[event.get("key")] = event.get("value")
                '
            }
            drop {}
        } else {
            ruby {
                code => '
                    event.set("metadata", @@metadata)
                '
            }
        }
    }

```

Essentially, if the line looks like "key: value" then stash it as metadata. If it does not then add all the stashed metadata items to the event.

I think this requires "--pipeline.workers 1"

This kind of ruby solution tends to be fragile, and has to be tuned to the input.

I use a class variable (@@metadata) rather than an instance variable (@metadata) because we need the same variable to visible across multiple ruby filters.

---

_[View the full topic](https://discuss.elastic.co/t/how-to-handle-metadata-in-file-headers/167544)._
