# How to use Ruby to preprocess k,v -pairs value

**URL:** <https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684>\
**Category:** Logstash\
**Created:** [February 9, 2021, 7:13am UTC](https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684 "2021-02-09T07:13:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![GL\_Choong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gl_choong/32/82493_2.png) [@GL\_Choong](https://discuss.elastic.co/u/GL_Choong)\
**Post date:** [February 9, 2021, 7:13am UTC](https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684/1 "2021-02-09T07:13:44Z")

</div>

Hi,  
I`m new to Logstash and Ruby.  
Would like to get help.  
Currently I have a data as below

test:result testcase: #TEMP\_BTWLAN:ok; loop:24;Temperature:28;

My initial target is by using ruby to generate as below Output.  
test =\> result testcase  
TEMP\_BTWLAN =\> ok  
loop =\> 24  
Temperature =\> 28

Below is my code  
#using kv to split the message  
kv {  
source =\> "message"  
field\_split =\> ";"  
value\_split =\> ":"  
}

ruby {  
code =\> "  
hash = event.to\_hash  
hash.each { |key, value|  
if value.include? '"'  
event.set(key, value.gsub!('"', ''))  
end  
}  
"  
}

Output as below:  
test =\> result testcase: #TEMP\_BTWLAN:ok \<== Problem  
loop =\> 24  
Temperature =\> 28

How to solve Problem that I stated above?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 9, 2021, 4:44pm UTC](https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684/2 "2021-02-09T16:44:39Z")

</div>

> [@GL\_Choong](#):
>
> test =\> result testcase: #TEMP\_BTWLAN:ok \<== Problem

Why is that a problem?

---

<div class="post-metadata">

**Author:** ![GL\_Choong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gl_choong/32/82493_2.png) [@GL\_Choong](https://discuss.elastic.co/u/GL_Choong)\
**Post date:** [February 10, 2021, 1:22am UTC](https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684/3 "2021-02-10T01:22:01Z")

</div>

I know the result is behave like this -\> test =\> result testcase: #TEMP\_BTWLAN:ok

But my expected result as below  
test =\> result testcase  
TEMP\_BTWLAN =\> ok

Would like to get advise, how to perform second layer split by using ruby in order to meet my expected result?

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [February 15, 2021, 8:12pm UTC](https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684/4 "2021-02-15T20:12:01Z")

</div>

hi,

Did you have tried to put a `;` after `testcase` in your log ?  
You can, if ou want, use grok :

```auto
(?<key1>[^:]+):(?<value1>[^:]+):%{SPACE}#(?<key2>[^:]+):(?<value2>[^;]+);%{SPACE}(?<key3>[^:]+):(?<value3>[^;]+);%{SPACE}(?<key4>[^:]+):(?<value4>[^;]+);

```

Cad

---

<div class="post-metadata">

**Author:** ![GL\_Choong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gl_choong/32/82493_2.png) [@GL\_Choong](https://discuss.elastic.co/u/GL_Choong)\
**Post date:** [February 19, 2021, 1:48am UTC](https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684/5 "2021-02-19T01:48:26Z")

</div>

Hi Cad,

Log Output ==\> test:result testcase: #TEMP\_BTWLAN:ok; loop:24;Temperature:28;

This log output is fixed which i not allowed to change.  
The example you show is kv for grok?

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [February 20, 2021, 8:46pm UTC](https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684/6 "2021-02-20T20:46:07Z")

</div>

Hi,

This is my interpretation for kv. I don't know how the syntaxe is analysed but we can create a grok pattern with the same result.

This grok pattern signification is :  
`(?<key>[^:]+):` = take all caracter while it is not a `:`, put it in "key" and after take `:`.  
`(?<value>[^;]+);` = take all caracter while it is not a `;`, put it in "value" and after take `;`.

So you just have to duplicate this two pattern as many time as necessary.

Cad

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2021, 8:46pm UTC](https://discuss.elastic.co/t/how-to-use-ruby-to-preprocess-k-v-pairs-value/263684/7 "2021-03-20T20:46:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
