# KV filter is unable to handle = within a key value

**URL:** <https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878>\
**Category:** Logstash\
**Created:** [October 13, 2017, 10:38am UTC](https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878 "2017-10-13T10:38:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![elvarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvarb/32/44840_2.png) [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Post date:** [October 13, 2017, 10:38am UTC](https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878/1 "2017-10-13T10:38:30Z")

</div>

When I have the KV filter run against this string

last="3367" post="" ltime="3"

Instead of ending up with

```
last: 3367
post: " ltime="3

```

I end up with

```
last: 3367
post: \
ltime: \"3"

```

I am expecting the KV filter to accept \ as an escape characters so that the value is encapsulated by the non escaped quotation marks but it seems that the kv seperator process kicks in before the kv value is read completely.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 13, 2017, 11:40am UTC](https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878/2 "2017-10-13T11:40:36Z")

</div>

It looks like a few characters were trimmed from your log example. Format it as preformatted text to avoid this.

---

<div class="post-metadata">

**Author:** ![elvarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvarb/32/44840_2.png) [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Post date:** [October 13, 2017, 2:32pm UTC](https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878/3 "2017-10-13T14:32:19Z")

</div>

```
last="3367" post="\" ltime=\"3"

```

There, this is the original string

---

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [October 16, 2017, 5:48am UTC](https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878/4 "2017-10-16T05:48:11Z")

</div>

This is normal behaviour like in Java (String.split(" ")) or PHP (explode(" ", String)).

So you split your string by " " and after that in this parts you split it again on "=" to determine the key and the value part.  
It just trimmed your " away because you have include\_brackets enabled.  
[KV Man - Include brackets](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html#plugins-filters-kv-include_brackets)

This is how I understand this, the developer of KV can have other views on this.

---

<div class="post-metadata">

**Author:** ![elvarb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elvarb/32/44840_2.png) [@elvarb](https://discuss.elastic.co/u/elvarb)\
**Post date:** [October 16, 2017, 2:03pm UTC](https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878/5 "2017-10-16T14:03:44Z")

</div>

Aha

So Logstash keeps the brackets and Elasticsearch takes them away so I never see them. This also explains that when there is nothing in the field Logstash sends it as key="" and in this case Elasticsearch does not strip them away and stores the value as ""

Sometimes the Logstash documentation really needs more examples.

---

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [October 17, 2017, 5:34am UTC](https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878/6 "2017-10-17T05:34:40Z")

</div>

Logstash aka KV filter takes the brackets away.  
But this option is confusing. Because if `include_brackets` it's enabled it  
will trim the brackets away.

I was wrong with the part of trimming the " away.  
Because `include_brackets` only trim away brackets ()[]{}...

I'm wondering if with brackets option enabled you could split by " " and preserve the string as one value.  
I've wrote my own splitter in ruby, so I won't test this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2017, 5:34am UTC](https://discuss.elastic.co/t/kv-filter-is-unable-to-handle-within-a-key-value/103878/7 "2017-11-14T05:34:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
