# Kv filter value is not always correctly extracted using value\_split\_pattern

**URL:** <https://discuss.elastic.co/t/kv-filter-value-is-not-always-correctly-extracted-using-value-split-pattern/154598>\
**Category:** Logstash\
**Created:** [October 30, 2018, 9:36am UTC](https://discuss.elastic.co/t/kv-filter-value-is-not-always-correctly-extracted-using-value-split-pattern/154598 "2018-10-30T09:36:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![CaptainAye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/captainaye/32/37271_2.png) [@CaptainAye](https://discuss.elastic.co/u/CaptainAye)\
**Post date:** [October 30, 2018, 9:36am UTC](https://discuss.elastic.co/t/kv-filter-value-is-not-always-correctly-extracted-using-value-split-pattern/154598/1 "2018-10-30T09:36:58Z")

</div>

Hello,

I have a problem extracting values using kv filter. I would like to extract the values which are seperated from key by the spaces or by the equal signs. My configuration looks like that:

```
		kv {
			include_keys => ["key1", "key2", "key3", "key4"]
			include_brackets => true
			source => "message"
			value_split_pattern => "\s=?\s?"
		}

```

The key value pairs like:

```
key1 <value1>
key2 = value2

```

Are correctly extracted in the elasticsearch but the value like:

```
key3 = <value3>

```

Are not extracted at all. I expected it to be extracted without the angle brackets, as `include_brackets` option is set to `true`.

**Is there some problem with the configuration I am not aware of or is it a problem with kv filter?**

---

<div class="post-metadata">

**Author:** ![tamara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tamara/32/47095_2.png) [@tamara](https://discuss.elastic.co/u/tamara)\
**Post date:** [October 31, 2018, 10:33pm UTC](https://discuss.elastic.co/t/kv-filter-value-is-not-always-correctly-extracted-using-value-split-pattern/154598/2 "2018-10-31T22:33:43Z")

</div>

Hi,

I am trying to replicate your problem and I can not find the issue, which version of logstash are you using?

Logstash version 6.4.2 works just fine with this kv configuration.

---

<div class="post-metadata">

**Author:** ![CaptainAye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/captainaye/32/37271_2.png) [@CaptainAye](https://discuss.elastic.co/u/CaptainAye)\
**Post date:** [November 4, 2018, 8:11pm UTC](https://discuss.elastic.co/t/kv-filter-value-is-not-always-correctly-extracted-using-value-split-pattern/154598/3 "2018-11-04T20:11:42Z")

</div>

Hi,  
Thanks for your reply. I used Logstash 6.4.0 for that task - I'll check with 6.4.2 and I'll be back with the answer if the problem still exists or not.

---

<div class="post-metadata">

**Author:** ![CaptainAye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/captainaye/32/37271_2.png) [@CaptainAye](https://discuss.elastic.co/u/CaptainAye)\
**Post date:** [November 6, 2018, 6:25am UTC](https://discuss.elastic.co/t/kv-filter-value-is-not-always-correctly-extracted-using-value-split-pattern/154598/4 "2018-11-06T06:25:31Z")

</div>

kv filter works fine with logstash 6.4.2 - the issue must have been fixed halfway from 6.4.0.

---

<div class="post-metadata">

**Author:** ![tamara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tamara/32/47095_2.png) [@tamara](https://discuss.elastic.co/u/tamara)\
**Post date:** [November 6, 2018, 5:57pm UTC](https://discuss.elastic.co/t/kv-filter-value-is-not-always-correctly-extracted-using-value-split-pattern/154598/5 "2018-11-06T17:57:02Z")

</div>

Great, glad to hear that the problem was solved. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2018, 5:57pm UTC](https://discuss.elastic.co/t/kv-filter-value-is-not-always-correctly-extracted-using-value-split-pattern/154598/6 "2018-12-04T17:57:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
