# KV Plugin Not working

**URL:** <https://discuss.elastic.co/t/kv-plugin-not-working/192188>\
**Category:** Logstash\
**Created:** [July 25, 2019, 7:19am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188 "2019-07-25T07:19:00Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 25, 2019, 7:19am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/1 "2019-07-25T07:19:00Z")

</div>

Hi All,

I have been trying to extract key value pairs from a certain log message.

**Log Message Sample**  
a=a1, b=b1, c=c1, d=d1,d2, e=e1 hello world, f=f1

**Expected Output**  
a=a1  
b=b1  
c=c1  
d=d1,d2  
e=e1  
f=f1

**Actual Output**  
a=a1  
b=b1  
c=c1  
d=d1  
e=e1 hello world  
f=f1

**KV Plugin**  
kv {  
source =\> "body"  
field\_split =\> ","  
value\_split =\> "="  
trim\_value =\> "},"  
tag\_on\_failure =\> ["kv-parse-failed"]  
}

Need help on this. Have been trying for a very long time.  
Not sure whether to use any other plugin to obtain the expected result.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 25, 2019, 1:11pm UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/2 "2019-07-25T13:11:52Z")

</div>

You can use

```
field_split_pattern => ", "

```

to define a two character field delimiter. That will result in d being parsed the way you want.

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 26, 2019, 6:01am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/3 "2019-07-26T06:01:16Z")

</div>

@Badger, it did not work out

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 26, 2019, 7:46am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/4 "2019-07-26T07:46:00Z")

</div>

You expected output is not the expected one when using the kv filter. The whole string is parsed which means hello world will need to go somewhere.

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 26, 2019, 8:41am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/5 "2019-07-26T08:41:19Z")

</div>

But, is it possible to remove the hello world after the e field is extracted?

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [July 26, 2019, 9:45am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/6 "2019-07-26T09:45:19Z")

</div>

Yes, you can use [mutate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-gsub) to replace hello world with empty string

So, you will have it something like below. Below code should remove hello world from **e** field. Place the below filter after your **kv** filter.

```
mutate {
    gsub => [
      "e", " hello world", "",
    ]
  }
```

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 30, 2019, 6:36am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/7 "2019-07-30T06:36:21Z")

</div>

Hi @sjabiulla,  
The mutate filter is not working out. Tried it multiple times.

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [July 30, 2019, 6:44am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/8 "2019-07-30T06:44:49Z")

</div>

Can you please show the config that you have tried with mutate filter and it's better to share your whole config, so that we can try this side and provide the solution

---

<div class="post-metadata">

**Author:** ![premkumar](https://avatars.discourse-cdn.com/v4/letter/p/e99b99/32.png) [@premkumar](https://discuss.elastic.co/u/premkumar)\
**Post date:** [July 30, 2019, 9:20am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/10 "2019-07-30T09:20:53Z")

</div>

I have found out the issue. Need to use the mutate filter plugin before the kv filter plugin.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2019, 9:21am UTC](https://discuss.elastic.co/t/kv-plugin-not-working/192188/11 "2019-08-27T09:21:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
