# Logstash filtering iterating over list

**URL:** <https://discuss.elastic.co/t/logstash-filtering-iterating-over-list/240364>\
**Category:** Logstash\
**Created:** [July 8, 2020, 2:20pm UTC](https://discuss.elastic.co/t/logstash-filtering-iterating-over-list/240364 "2020-07-08T14:20:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ash2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ash2/32/45433_2.png) [@ash2](https://discuss.elastic.co/u/ash2)\
**Post date:** [July 8, 2020, 2:20pm UTC](https://discuss.elastic.co/t/logstash-filtering-iterating-over-list/240364/1 "2020-07-08T14:20:32Z")

</div>

I am trying to parse the following format of logs, starting value is a hostname, and the ending is timestamp always.

`blb12bkl4, data1 value1, data2 value2, data3 value3, 1594216629094`

and the final format for output should be :

```auto
        {
           host: "blb12bkl4",
           timestamp: 1594216629094,
           datalist: [
                {
                      data: "data1",
                      value: "value1"
                },
                {
                      data: "data2",
                      value: "value2"
                },
                {
                      data: "data3",
                      value: "value3"
                }
           ]
        }

```

And one more thing, in logs data[I] value[I] can be of any number of times, but always one or more like:

```auto
blb12bkl4, data1 10, data2 20, 1594216629094
blb12bkl4, data1 10, data2 20, data3 30, 1594216629094
blb12bkl4, data1 10, data2 20, data3 30, data4 49, 1594216629094

```

So for the starter I used grok and split:

```auto
filter{
   grok{
     match=>{ "message" => "(?<hostname>[a-zA-Z0-9]+(?=,)),\s(?<datalist>([a-zA-Z0-9]+\s[0-9]+,\s)+))\s(?<timestamp>[0-9]+)" }
   }
   mutate {
     split => {"datalist" => ", "}
   }
 }

```

so after this, I have data as

```auto
    {
       host: "blb12bkl4",
       timestamp: 1594216629094,
       datalist: ["data1 value1", "data2 value2", "data3 value3"]
    }

```

can anyone pls help in iteration over this datalist and make the output in the required format.

Thanks in Advance.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 8, 2020, 2:46pm UTC](https://discuss.elastic.co/t/logstash-filtering-iterating-over-list/240364/2 "2020-07-08T14:46:04Z")

</div>

I would not use the split option of the mutate filter. I'd use a KV filter with field\_split at commas and value\_split at spaces. Then I would iterate over the results with Ruby.

```
i = 0
event.get('kv_result').each { |key,value|
  event.set('[datalist]['+i.to_s+'][data]', key)
  event.set('[datalist]['+i.to_s+'][value]', value)
  i++
}

```

(I didn't test it. But something like this might work.)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2020, 2:59pm UTC](https://discuss.elastic.co/t/logstash-filtering-iterating-over-list/240364/3 "2020-08-05T14:59:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
