# Logstash km filter issue

**URL:** <https://discuss.elastic.co/t/logstash-km-filter-issue/150426>\
**Category:** Logstash\
**Created:** [September 29, 2018, 12:03pm UTC](https://discuss.elastic.co/t/logstash-km-filter-issue/150426 "2018-09-29T12:03:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gopisa](https://avatars.discourse-cdn.com/v4/letter/g/7993a0/32.png) [@gopisa](https://discuss.elastic.co/u/gopisa)\
**Post date:** [September 29, 2018, 12:03pm UTC](https://discuss.elastic.co/t/logstash-km-filter-issue/150426/1 "2018-09-29T12:03:58Z")

</div>

Hi All,

I am facing KV filter issue. any one please help me on this.

I am using kv filter. In that configuration value\_split =\> ":\s" like that i spited my log file . if the any log file contain URL([https://googlr.com](https://googlr.com/)\facebook) that is coming in one filter ..

how to split my log file instead of ":". any one help me on this .

## input log file

"Payload\_exception" : "hhh.Integration.Com.Except.MePatieException:  
alert rules can proactively identify and respond to an issue!.

## output

```auto
		"Timestamp\"" => "2018-09-25T18:24:04.0064206Z",
"Payload_exception\"" => "hhh.Integration.Com.Except.MePatieException: <Error xmlns=",
              "http" => "//google.com/ecoeeement/eeee">",
      "<Message>The" => "alert",
          "rule" => "can",
            "proactively" => "identify",

```

## logstash config

input {  
file {  
path =\> "C:\SoftwareInstalls\logstash-2.3.2\testfilter.log"  
start\_position =\> "beginning"  
codec =\> multiline {  
pattern =\> "^{"  
negate =\> true  
what =\> previous  
auto\_flush\_interval =\> 3  
}  
}  
}

filter {

kv{  
value\_split =\> ":\s"  
field\_split =\> ",\s"  
trimkey =\> ""\ ()"  
}

mutate {  
remove\_field =\> ['message', 'tags']  
}  
}

## log file

{  
"EventId" : "1",  
"Keywords" : "1",  
"Level" : "Verbose",  
"Message" : "",  
"Opcode" : "Info",  
"Task" : "65534543 WriteVerbose",  
"Version" : "0",  
"Timestamp" : "2018-09-25T18:15:05.6201608Z",  
"Payload\_message" : "Message received by system. Set logging level above verbose to disable this message.",  
"Payload\_MessageType" : "MarkDd",  
"Payload\_MedseekPatientId" : "",  
"Payload\_OriginatingMessageId" : "454545-45454-4640-45454-a37ab3c945447",  
"EOE" : ""  
}  
{  
"EventId" : "545454",  
"Keywords" : "1",  
"Level" : "Critical",  
"Message" : "",  
"Opcode" : "Info",  
"Task" : "65545429 WriteException",  
"Version" : "0",  
"Timestamp" : "2018-09-25T18:15:22.1211900Z",  
"Payload\_exception" : "hhh.Integration.Com.Except.MePatieException:  
alert rules can proactively identify and respond to an issue!

at learned how alert rules can proactively identify and respond to an issue when they run log searches at scheduled intervals and match a particular criteria  
at learned how alert rules can proactively identify and respond to an issue when they run log searches at scheduled intervals and match a particular criteria",  
"Payload\_MessageType" : "Update",  
"Payload\_OriginatingMessageId" : "8053c528-867e-4d56-aed8-45454545454545",  
"Payload\_MedseekPatientId" : "",  
"EOE" : ""  
}

Thanks in advance

Gopisa

---

<div class="post-metadata">

**Author:** ![Shivamuppasani](https://avatars.discourse-cdn.com/v4/letter/s/8797f3/32.png) [@Shivamuppasani](https://discuss.elastic.co/u/Shivamuppasani)\
**Post date:** [October 2, 2018, 12:58pm UTC](https://discuss.elastic.co/t/logstash-km-filter-issue/150426/2 "2018-10-02T12:58:36Z")

</div>

I am facing same kind of issue help me on this ..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2018, 12:58pm UTC](https://discuss.elastic.co/t/logstash-km-filter-issue/150426/3 "2018-10-30T12:58:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
