# KV how to extract data between square brackets

**URL:** <https://discuss.elastic.co/t/kv-how-to-extract-data-between-square-brackets/221678>\
**Category:** Logstash\
**Created:** [March 2, 2020, 12:48pm UTC](https://discuss.elastic.co/t/kv-how-to-extract-data-between-square-brackets/221678 "2020-03-02T12:48:47Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![sahar](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@sahar](https://discuss.elastic.co/u/sahar)\
**Post date:** [March 2, 2020, 4:56pm UTC](https://discuss.elastic.co/t/kv-how-to-extract-data-between-square-brackets/221678/4 "2020-03-02T16:56:12Z")

</div>

So after I understood that recursive regex isn't supported probably I tried a different regex with max 2 levels of nesting:  
`\[(?:[^\]\[]+|\[(?:[^\]\[]+|\[[^\]\[]*\])*\])*\]`

It seems to work when testing:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a684dc13610d989de4841ed4a1b5cf907fe74c0.png)

Logstash also loads successfully, but still splits the fields in the wrong way...

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/a/fa7614fe5bde90e99344d9dff9d7e72f62dbc7eb.png)

What am I missing? perhaps need a different filter for this one? or even ruby code?  
Thanks for the help.

---

_[View the full topic](https://discuss.elastic.co/t/kv-how-to-extract-data-between-square-brackets/221678)._
