# KV Filter usage

**URL:** <https://discuss.elastic.co/t/kv-filter-usage/131564>\
**Category:** Logstash\
**Created:** [May 12, 2018, 9:39am UTC](https://discuss.elastic.co/t/kv-filter-usage/131564 "2018-05-12T09:39:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bec33](https://avatars.discourse-cdn.com/v4/letter/b/7cd45c/32.png) [@bec33](https://discuss.elastic.co/u/bec33)\
**Post date:** [May 12, 2018, 9:39am UTC](https://discuss.elastic.co/t/kv-filter-usage/131564/1 "2018-05-12T09:39:55Z")

</div>

I am following up on this thread,

can you help

> [@KV Filter Pattern Usage](https://discuss.elastic.co/t/kv-filter-pattern-usage/125657):
>
> Using the latest KV filter plugin (4.1.0)... I'm trying to use the KV filter to parse a log formatted like the following: Protocol: TCP, SrcIP: 192.168.1.1 and so on... (the main idea here is that the key/values are separated by colon+space and fields are separate by comma+space I've tried the following: filter { if [log\_header] =~ "desired\_value" { mutate { add\_tag =\> ["blah"] } kv { value\_split\_pattern =\> ": " field\_split\_pattern =\> ", " } } } I'…

---

<div class="post-metadata">

**Author:** ![bec33](https://avatars.discourse-cdn.com/v4/letter/b/7cd45c/32.png) [@bec33](https://discuss.elastic.co/u/bec33)\
**Post date:** [May 12, 2018, 6:16pm UTC](https://discuss.elastic.co/t/kv-filter-usage/131564/2 "2018-05-12T18:16:17Z")

</div>

I found the solution,

event source time was wrong

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2018, 6:16pm UTC](https://discuss.elastic.co/t/kv-filter-usage/131564/3 "2018-06-09T18:16:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
