# Kv filter's behavior when square brackets in log data

**URL:** <https://discuss.elastic.co/t/kv-filters-behavior-when-square-brackets-in-log-data/93358>\
**Category:** Logstash\
**Created:** [July 17, 2017, 8:35am UTC](https://discuss.elastic.co/t/kv-filters-behavior-when-square-brackets-in-log-data/93358 "2017-07-17T08:35:19Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pranav1](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@Pranav1](https://discuss.elastic.co/u/Pranav1)\
**Post date:** [July 17, 2017, 8:35am UTC](https://discuss.elastic.co/t/kv-filters-behavior-when-square-brackets-in-log-data/93358/1 "2017-07-17T08:35:19Z")

</div>

In logstash I am using the following filter-

> filter {  
> kv {  
> field\_split =\> "\t"  
> }  
> }

So here I am using tab as field split and the value split I have kept default (i.e. '=')

Now I am sending a log like this-

> animal=cat fruit=[apple]banana

where there is a **tab** between cat and fruit.

This is producing the filtered output as-

> {  
> "animal": "cat"  
> **"fruit": "apple"**  
> "message": "animal=cat\tfruit=[apple]banana"  
> }

But I was expecting - "fruit": "[apple]banana".

Also then if I send a log like this-

> animal=cat fruit=[apple]banana=healthy

where **tab** is only between cat and fruit  
then the output produced is -

> {  
> "banana" : "healthy"  
> "animal": "cat"  
> "fruit": "apple"  
> "message": "animal=cat\tfriut=[apple]banana=healthy"  
> }

But here I was expecting - "fruit": "[apple]banana=healthy" and no separate key as 'banana'.

Is this a bug or am I missing something here?

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [July 21, 2017, 4:01pm UTC](https://discuss.elastic.co/t/kv-filters-behavior-when-square-brackets-in-log-data/93358/2 "2017-07-21T16:01:22Z")

</div>

The kv filter works with many many regular expressions, and characteres like [|]\<\> can severely interfere with how the plugin works. There are even [options to remove these characters](https://www.elastic.co/guide/en/logstash/5.4/plugins-filters-kv.html#plugins-filters-kv-remove_char_value) if you know in advance they appear in the data

I suggest maybe using mutate gsub operations to make the text string more uniform so that the kv filter doesn't have to guess (and make the wrong decisions).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2017, 4:01pm UTC](https://discuss.elastic.co/t/kv-filters-behavior-when-square-brackets-in-log-data/93358/3 "2017-08-18T16:01:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
