# Logstash KV filter not working on Greedydata

**URL:** <https://discuss.elastic.co/t/logstash-kv-filter-not-working-on-greedydata/376764>\
**Category:** Logstash\
**Created:** [April 3, 2025, 5:55pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-not-working-on-greedydata/376764 "2025-04-03T17:55:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elk\_huh](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Post date:** [April 3, 2025, 5:55pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-not-working-on-greedydata/376764/1 "2025-04-03T17:55:53Z")

</div>

Raw logs

\<190\>SCO-0000-CS01: 2025 Apr 3 17:53:36 UTC: %ACLLOG-6-ACLLOG: SGT: 0, Src IP: 1.1.1.1, Dst IP: 9.9.9.9, Src Port: 504, Dst Port: 443, Src Intf: port-channel1002, Protocol: "UDP"(17), ACL Name: alltraffic, ACE Action: Permit, Appl Intf: Vlan16, Hit-count: 1

The KV on the rest on the greedydata is not processing

```auto

filter {

 dissect {
      mapping => {
        "message" => "<%{INT:syslog_priority}>%{WORD:device_location}-%{WORD:device_model}-%{WORD:device_id}: %{YEAR:year} %{MONTH:month} %{MONTHDAY:day} %{TIME:time} %{WORD:timezone}: %%{DATA:syslog_message_type}: %{GREEDYDATA:restOfLine}"
      }
    }
    kv {
      source => "restOfLine"
      field_split => ","
      trim_key => " "
      value_split => ":"
    }

}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 3, 2025, 6:27pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-not-working-on-greedydata/376764/2 "2025-04-03T18:27:44Z")

</div>

You cannot use dissect in that way. That is the grok syntax. It should be like this:  
`grok { match => { "message" => "<%{INT:syslog_priority}>%{WORD:device_location}-%{WORD:device_model}-%{WORD:device_id}: %{YEAR:year} %{MONTH:month} %{MONTHDAY:day} %{TIME:time} %{WORD:timezone}: %%{DATA:syslog_message_type}: %{GREEDYDATA:restOfLine}" } }`

PS. You had double spaces in front of %{MONTHDAY:day}

---

<div class="post-metadata">

**Author:** ![Elk\_huh](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Post date:** [April 3, 2025, 6:45pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-not-working-on-greedydata/376764/3 "2025-04-03T18:45:22Z")

</div>

the raw message has 2 spaces after the Month , that was intended ! , but is there a way to keep this part together

SCO-N000-CS01 as hostname and its not parsing at all now

```auto

     grok { match => { "message" => "<%{INT:syslog_priority}>%{WORD:device_location}-%{WORD:device_model}-%{WORD:device_id}: {YEAR:year} %{MONTH:month} %{MONTHDAY:day} %{TIME:time} %{WORD:timezone}: %%{DATA:syslog_message_type}: %{GREEDYDATA:restOfLine}" } }
    kv {
      source => "restOfLine"
      field_split => ","
      trim_key => " "
      value_split => ":"
    }

#}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 3, 2025, 6:59pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-not-working-on-greedydata/376764/4 "2025-04-03T18:59:39Z")

</div>

> [@Elk\_huh](#):
>
> is there a way to keep this part together

Of course. You can do it with grok, or you can do it with dissect. With grok you could try

```
    grok {
        pattern_definitions => {
            "MYTIMESTAMP" => "%{YEAR} %{SYSLOGTIMESTAMP} %{WORD:timezone}"
            "MYHOSTNAME" => "%{WORD}-%{WORD}-%{WORD}"
        }
        match => { "message" => "<%{INT:syslog_priority}>%{MYHOSTNAME:hostname}: %{MYTIMESTAMP:timestamp}: %%{DATA:syslog_message_type}-%{INT:severity}-%{WORD:log_message}: %{GREEDYDATA:restOfLine}" }
    }

```

with dissect you could try

```
dissect { mapping => { "message" => "<%{priority}>%{hostname}: %{timestamp}: %{msgcode}: %{restOfLine}" } }

```

Either way the kv will produce

```
 "Hit-count" => "1",
  "Src Intf" => "port-channel1002",
    "Dst IP" => "9.9.9.9",
  "Protocol" => "\"UDP\"(17)",
    "Src IP" => "1.1.1.1",
       "SGT" => "0",
  "Dst Port" => "443",

```

etc.

Your grok pattern has to match either `Mar 9` with two spaces or `Mar 10` with one. The [grok SYSLOGTIMESTAMP](https://github.com/logstash-plugins/logstash-patterns-core/blob/f01f3f34cfab13a28b0822bdba33db41823cb1d8/patterns/legacy/grok-patterns#L81) pattern does this.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 4, 2025, 12:40pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-not-working-on-greedydata/376764/5 "2025-04-04T12:40:44Z")

</div>

Just to add:

- in case you have variable size delimiters or optional fields go for grok otherwise dissect is much faster
- don't forget to convert datetime to the date format otherwise you will have datetime as string.
