# How to ingest kv field values as seperate records in kibana

**URL:** <https://discuss.elastic.co/t/how-to-ingest-kv-field-values-as-seperate-records-in-kibana/226904>\
**Category:** Logstash\
**Created:** [April 7, 2020, 1:28pm UTC](https://discuss.elastic.co/t/how-to-ingest-kv-field-values-as-seperate-records-in-kibana/226904 "2020-04-07T13:28:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mithuna](https://avatars.discourse-cdn.com/v4/letter/m/e495f1/32.png) [@Mithuna](https://discuss.elastic.co/u/Mithuna)\
**Post date:** [April 7, 2020, 1:28pm UTC](https://discuss.elastic.co/t/how-to-ingest-kv-field-values-as-seperate-records-in-kibana/226904/1 "2020-04-07T13:28:31Z")

</div>

Hi,

I'm trying to ingest API data into kibana with Logstash. In this i'm not getting the value as expected.

My config file is

input {  
stdin{}  
http\_poller {  
urls =\> {  
q1 =\> {  
method =\> get  
user =\> "me"  
password =\> "mypassword"   
url =\> "myurl"   
headers =\> {  
Accept =\> "application/json"  
"Content-Type" =\> "application/json"  
}  
}  
}  
keepalive =\> false  
request\_timeout =\> 900000  
socket\_timeout =\> 1800  
codec =\> "plain"  
# Supports "cron", "every", "at" and "in" schedules by rufus scheduler  
schedule =\> { cron =\> "\*/5 \* \* \* \* UTC"}  
metadata\_target =\> "http\_poller\_metadata"   
}  
}  
filter {  
kv {  
remove\_char\_key =\> "{}\+"  
remove\_char\_value =\> "{}\+"  
field\_split =\> ","  
value\_split =\> ":"  
source =\> message   
}   
mutate {  
remove\_field =\> "message"  
}   
}  
output{  
stdout {  
codec =\> rubydebug  
}   
elasticsearch {  
action =\> "index"  
index =\> "myindex"  
hosts =\> ["localhost:9200"]   
}   
}

i'm getting the output as follows:  
""Teams\_AgentAssignment\_connectedOn"" =\> [  
[0] ""2020-04-02T15:45:32.698"",  
[1] ""2020-04-02T15:34:55.480""  
],  
""Dialogs\_ChatSession\_isAbandoned"" =\> [  
[0] "false",  
[1] "false"  
],  
""Teams\_AgentAssignment\_timeStamp"" =\> [  
[0] ""2020-04-02T15:45:32.698"",  
[1] ""2020-04-02T15:34:55.480""  
],

but i need it as seperate records in kibana like:  
"Teams\_AgentAssignment\_connectedOn" =\> "2020-04-02T15:45:32.698",  
"Dialogs\_ChatSession\_isAbandoned" =\> "false",  
"Teams\_AgentAssignment\_timeStamp" =\> "2020-04-02T15:45:32.698",

Please help me in getting this.

Thanks,  
Mithuna

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2020, 1:28pm UTC](https://discuss.elastic.co/t/how-to-ingest-kv-field-values-as-seperate-records-in-kibana/226904/2 "2020-05-05T13:28:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
