# Logstash kv filter questions

**URL:** <https://discuss.elastic.co/t/logstash-kv-filter-questions/86133>\
**Category:** Logstash\
**Created:** [May 17, 2017, 3:11pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-questions/86133 "2017-05-17T15:11:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Singard123](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@Singard123](https://discuss.elastic.co/u/Singard123)\
**Post date:** [May 17, 2017, 3:11pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-questions/86133/1 "2017-05-17T15:11:39Z")

</div>

I am trying to parse the log but right now all the messages has been parsed into one field and it looks like this

> message:time=2017-05-17T11:01:05.810417-04:00 e[32mseverity=INFO e[0m pid=76561 method=GET path=/studies/408934/report format=xlsx controller=ReportsController action=show status=200 duration=2653.09 view=2258.61 db=237.51 time=2017-05-17 11:01:03 -0400 ip=127.0.0.1 [host=dev.central.miovision.com](http://host=dev.central.miovision.com) [user=ywang@miovision.com](mailto:user=ywang@miovision.com) params={"download\_token"=\>"1495033261", "report"=\>{"format"=\>"xlsx", "bin\_size"=\>"900", "legs\_and\_movements"=\>"processed", "approach\_order"=\>"n\_ne\_e\_se\_s\_sw\_w\_nw", "movement\_order"=\>"rtlu", "include\_raw\_data"=\>"false", "pces\_enabled"=\>"false"}, "study\_id"=\>"408934"}

However, I am trying to get the field `"download_token"=>"1495033261"` from `params`. Is there a way to do this?

My current filter is as follows

```auto
filter {
  kv { 
    trimkey => "<>\[\],`\."
    remove_field => ["\\%{some_field}", "{%{some_field}"]
    include_brackets => false
  }
}

```

Thanks so much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2017, 3:15pm UTC](https://discuss.elastic.co/t/logstash-kv-filter-questions/86133/2 "2017-06-14T15:15:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
