# KV Filter Pattern Usage

**URL:** <https://discuss.elastic.co/t/kv-filter-pattern-usage/125657>\
**Category:** Logstash\
**Created:** [March 26, 2018, 6:11pm UTC](https://discuss.elastic.co/t/kv-filter-pattern-usage/125657 "2018-03-26T18:11:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cappy](https://avatars.discourse-cdn.com/v4/letter/c/22d042/32.png) [@cappy](https://discuss.elastic.co/u/cappy)\
**Post date:** [March 26, 2018, 6:11pm UTC](https://discuss.elastic.co/t/kv-filter-pattern-usage/125657/1 "2018-03-26T18:11:38Z")

</div>

Using the latest KV filter plugin (4.1.0)...

I'm trying to use the KV filter to parse a log formatted like the following:

Protocol: TCP, SrcIP: 192.168.1.1

and so on... (the main idea here is that the key/values are separated by colon+space and fields are separate by comma+space

I've tried the following:

```
filter {
   if [log_header] =~ "desired_value" {
     mutate {
      add_tag => ["blah"]
    }
    kv {
      value_split_pattern => ": "
      field_split_pattern => ", "
    }
  }
}

```

I've also tried the following for the value\_split\_pattern and field\_split\_pattern:

```
value_split_pattern => ":\s"
field_split_pattern => ",\s"

```

...however, the logs never make it into ES, and just stay in the queue.

If I remark the KV part and just let the log go in tagged, it works fine (unparsed, of course).

I have both PQ and DLQ enabled, and dead letter does not show a failure -- again, the log just stays in the queue forever.

Any thoughts?

Thanks,  
Cappy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2018, 6:12pm UTC](https://discuss.elastic.co/t/kv-filter-pattern-usage/125657/2 "2018-04-23T18:12:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
