# How to match 2 key value pairs in unstructured string that looks like column

**URL:** <https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541>\
**Category:** Logstash\
**Created:** [September 18, 2021, 11:05am UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541 "2021-09-18T11:05:58Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ansamHox](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Post date:** [September 18, 2021, 11:05am UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/1 "2021-09-18T11:05:58Z")

</div>

I have a document with some lines like:

```
  Example requested: 24:00:00 Example Used: 01:14:11        

```

What I want is to have is:

```
{
"example_requested": "24:00:00",
"example_used": 01:14:11
}

```

What I tried (this is `ruby` block):

```
if x =~ /(Example requested)/
        example_used = x.scan(/^(?:.*?: ){2}(.*)$/)[0]
   	    example_used = (example_requested * "").gsub(/\s+/, "")

```

I get

```
"example_used": 01:14:11

```

but when i change {2} to {1} to get example\_requested, the only thing I was able to get is:  
`"example_requested" : "24:00:00ExampleUsed:01:14:11"`

What is the best way to achieve this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 18, 2021, 4:36pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/2 "2021-09-18T16:36:45Z")

</div>

You could use a kv filter

```
    kv {
        field_split_pattern => "\s+"
        value_split_pattern => ":"
        trim_value => " "
    }

```

to get

```
 "requested" => "24:00:00",
      "Used" => "01:14:11",

```

or you could use ruby

```
    ruby {
        code => '
            message = event.get("message")
            matches = message.scan(/\s*([a-zA-Z]+): (\d{2}:\d{2}:\d{2})/)
            matches.each { |x|
                event.set(x[0].downcase.gsub(/ /, "_"), x[1])
            }
        '
    }

```

will get you

```
"example_requested" => "24:00:00",
     "example_used" => "01:14:11",

```

Both look fragile to me.

---

<div class="post-metadata">

**Author:** ![ansamHox](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Post date:** [September 18, 2021, 5:06pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/3 "2021-09-18T17:06:24Z")

</div>

That's true, but I forgot to mention that sometimes lines don't contain just numbers, e.g. one of them looks like

```auto

Memory Requested: 3.5TB Memory Used: 668.41GB

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 18, 2021, 5:10pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/4 "2021-09-18T17:10:20Z")

</div>

Then change the regexp from `(\d{2}:\d{2}:\d{2})/)` to something like `([\d:.BKMGT])`.

---

<div class="post-metadata">

**Author:** ![ansamHox](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Post date:** [September 18, 2021, 5:28pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/5 "2021-09-18T17:28:58Z")

</div>

`(\d{2}:\d{2}:\d{2})/)` works for case

```auto
"example_requested" => "24:00:00",
 "example_used" => "01:14:11",

```

but `([\d:.BKMGT])` leaves me with some strange numbers, something that was `Memory Requested: 4.5TB` becomes `tb ______ memory_requested => "6"`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 18, 2021, 5:30pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/6 "2021-09-18T17:30:22Z")

</div>

> [@ansamHox](#):
>
> ([\d:.BKMGT])

`([\d:.BKMGT]+)` perhaps

---

<div class="post-metadata">

**Author:** ![ansamHox](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Post date:** [September 18, 2021, 5:37pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/7 "2021-09-18T17:37:44Z")

</div>

> [@Badger](#):
>
> ([\d:.BKMGT+])

Now values are fine, but example\_requested is messed up.

```auto
======================================================================================
                  Resource Usage on 2021-06-27 00:18:22:         
                                           CPU Time Used: 1282:26:07                                 
   Memory Requested: 4.5TB Memory Used: 668.34GB        
   Example requested: 24:00:00 Example Used: 01:14:11        
   FS requested: 400.0GB FS used: 8.16MB          
======================================================================================

```

output is:

```auto
          "tb _________________ memory_used" : "668.34GB",
          "gb ________________ fs_used" : "8.16MB",
          "example_requested" : "24",
          "cpu_time_used" : "1282",
          "example_used" : "01"

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 18, 2021, 6:15pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/8 "2021-09-18T18:15:52Z")

</div>

> [@Badger](#):
>
> ([\d:.BKMGT+])

I suggested `([\d:.BKMGT]+)`, not `([\d:.BKMGT+])`

---

<div class="post-metadata">

**Author:** ![ansamHox](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Post date:** [September 18, 2021, 6:28pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/9 "2021-09-18T18:28:42Z")

</div>

was wrongly editing your qoute, sorry, still, it doesn't find **memory requested** and **FS requested fields**.

Is there any reason why is this unable to get matched with regex, [Rubular: (?:.?Memory Requested:\s+)(.\*\s\s)](https://rubular.com/r/Rl95Uf5l3ltmqx) and just trim blank spaces with gsub, because I can get memory used, example used and fs used fields with it, but don't understand why exactly can't get the first one (requested) ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 18, 2021, 7:05pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/10 "2021-09-18T19:05:14Z")

</div>

Use

```
matches = message.scan(/\s*([a-zA-Z]+):\s+(([\d:.BKMGT]+))/)

```

If the names of the fields are fixed you can use a [bytes filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-bytes.html) to convert them to numbers.

---

<div class="post-metadata">

**Author:** ![ansamHox](https://avatars.discourse-cdn.com/v4/letter/a/54ee81/32.png) [@ansamHox](https://discuss.elastic.co/u/ansamHox)\
**Post date:** [September 18, 2021, 7:15pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/11 "2021-09-18T19:15:51Z")

</div>

Well, now it works even field names are correct.. thank you sir

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 16, 2021, 7:15pm UTC](https://discuss.elastic.co/t/how-to-match-2-key-value-pairs-in-unstructured-string-that-looks-like-column/284541/12 "2021-10-16T19:15:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
