# Kv filter usage

**URL:** <https://discuss.elastic.co/t/kv-filter-usage/284718>\
**Category:** Logstash\
**Created:** [September 21, 2021, 12:04pm UTC](https://discuss.elastic.co/t/kv-filter-usage/284718 "2021-09-21T12:04:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PaoloZhao](https://avatars.discourse-cdn.com/v4/letter/p/d07c76/32.png) [@PaoloZhao](https://discuss.elastic.co/u/PaoloZhao)\
**Post date:** [September 21, 2021, 12:04pm UTC](https://discuss.elastic.co/t/kv-filter-usage/284718/1 "2021-09-21T12:04:15Z")

</div>

Hi guys!  
I am a fresh fish.  
I have some logs like blow.

```auto
15:08:16.2104 Info {"message":"BlankProcess execution started","level":"Information","logType":"Default","timeStamp":"2021-09-21T15:08:16.2015207+08:00","fingerprint":"1ac6b349","windowsIdentity":"abc","machineName":"123","processName":"BlankProcess","processVersion":"1.0.0","jobId":"4e65df55-6001-4f4c-aa90-910346e5e0eb","robotName":"abc","machineId":0,"fileName":"Main","initiatedBy":"Studio"}
15:08:18.2199 Error {"message":"Throw: Test","level":"Error","logType":"Default","timeStamp":"2021-09-21T15:08:18.2199587+08:00","fingerprint":"bb6488d3","windowsIdentity":"abc","machineName":"123","processName":"BlankProcess","processVersion":"1.0.0","jobId":"4e65df55-6001-4f4c-aa90-910346e5e0eb","robotName":"abc","machineId":0,"fileName":"Main"}
15:08:18.2748 Info {"message":"BlankProcess execution ended","level":"Information","logType":"Default","timeStamp":"2021-09-21T15:08:18.2738121+08:00","fingerprint":"61ab270f","windowsIdentity":"abc","machineName":"123","processName":"BlankProcess","processVersion":"1.0.0","jobId":"4e65df55-6001-4f4c-aa90-910346e5e0eb","robotName":"abc","machineId":0,"totalExecutionTimeInSeconds":2,"totalExecutionTime":"00:00:02","fileName":"Main"}

```

I thinks that It should be used kv filter.  
before kv filter need extract string between {}.  
How can I do this, who can give me a sample for that.

Best Regards!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 21, 2021, 1:04pm UTC](https://discuss.elastic.co/t/kv-filter-usage/284718/2 "2021-09-21T13:04:00Z")

</div>

There is no `kv` in your message, you have a static part and a json part.

You can parse it using `dissect` to split your message in three different fields, where the last one will be a json, then you use a `json` filter to parse this last field.

You need something like this.

```auto
filter {
  dissect {
    mapping => {
      "message" => "%{timestamp} %{loglevel} %{jsonMsg}"
    }
  }
  json {
    source => "jsonMsg"
  }
}

```

The dissect filter will create three fields, using your first message as an example you will have.

```auto
timestamp: 15:08:16.2104
loglevel: Info
jsonMsg: {"message":"BlankProcess execution started","level":"Information","logType":"Default","timeStamp":"2021-09-21T15:08:16.2015207+08:00","fingerprint":"1ac6b349","windowsIdentity":"abc","machineName":"123","processName":"BlankProcess","processVersion":"1.0.0","jobId":"4e65df55-6001-4f4c-aa90-910346e5e0eb","robotName":"abc","machineId":0,"fileName":"Main","initiatedBy":"Studio"}

```

The `json` filter will parse your `jsonMsg` field and extract the fields in the root of the document.

---

<div class="post-metadata">

**Author:** ![PaoloZhao](https://avatars.discourse-cdn.com/v4/letter/p/d07c76/32.png) [@PaoloZhao](https://discuss.elastic.co/u/PaoloZhao)\
**Post date:** [September 21, 2021, 1:40pm UTC](https://discuss.elastic.co/t/kv-filter-usage/284718/3 "2021-09-21T13:40:27Z")

</div>

Hi @leandrojmp  
Thanks for your reply!  
It's perfect!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 19, 2021, 1:40pm UTC](https://discuss.elastic.co/t/kv-filter-usage/284718/4 "2021-10-19T13:40:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
