# I want to import a 3GB system file to ELK in one go

**URL:** <https://discuss.elastic.co/t/i-want-to-import-a-3gb-system-file-to-elk-in-one-go/240572>\
**Category:** Elasticsearch\
**Created:** [July 9, 2020, 4:53pm UTC](https://discuss.elastic.co/t/i-want-to-import-a-3gb-system-file-to-elk-in-one-go/240572 "2020-07-09T16:53:45Z")\
**Posts on this page:** 1\
**Showing post:** 17

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 11, 2020, 10:58am UTC](https://discuss.elastic.co/t/i-want-to-import-a-3gb-system-file-to-elk-in-one-go/240572/17 "2020-07-11T10:58:01Z")

</div>

As the first few fields are not in Kv format you can not just use a KV filter. Instead you need to parse out the fields that are not in KV format first and store the long KV string in a separate field. You can then apply the KV filter to this field. Have a look at [this blog post](https://www.elastic.co/blog/a-practical-introduction-to-logstash) for a guide on how to parse data and work with Logstash.

---

_[View the full topic](https://discuss.elastic.co/t/i-want-to-import-a-3gb-system-file-to-elk-in-one-go/240572)._
