# KV filter - for parsing my syslog ng

**URL:** <https://discuss.elastic.co/t/kv-filter-for-parsing-my-syslog-ng/107553>\
**Category:** Logstash\
**Created:** [November 14, 2017, 1:34pm UTC](https://discuss.elastic.co/t/kv-filter-for-parsing-my-syslog-ng/107553 "2017-11-14T13:34:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 14, 2017, 1:34pm UTC](https://discuss.elastic.co/t/kv-filter-for-parsing-my-syslog-ng/107553/1 "2017-11-14T13:34:18Z")

</div>

Hi All,

Iam using ELastic stack to store our syslog-ng logs, so I was able to get the logs into elasticsearch, which is perfect. So I thought I could go one further more to parse the message field , but the problem is

Certain times I get the message which has field split of space , sometimes comma and for value split i receive it certain messages use equal sign and some use colon .

Fo example:

In this its separated by colon and then space

**spamd: setuid to vmail succeeded**

In this its separated by comma and then value splitted by equal sign

**action=pass, reason=client AWL, client\_name=[m.web.in](http://m.web.in), client\_address=.1.6.1, sender=ren@we.i, recipient=arn@g-net.**

In this it uses \>\<  
EA79A800A7: message-id=[15fb@webjas.sr.aol](mailto:15fb@webjas.sr.aol)

In this it uses both colon and equal sign and field split uses space

**pop(oelg@sbj): Disconnected: Logged out top=0/0 retr=0/0 del=0/25 size=1740767**

I know since i receive the logs from different sources ,its understood I get in this format ,but how to complete this task in elasticsearch with use of logstash.

Could anyone help me to figure out this issue.

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2017, 1:34pm UTC](https://discuss.elastic.co/t/kv-filter-for-parsing-my-syslog-ng/107553/2 "2017-12-12T13:34:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
