# Logstash mutate not working after kv filter applied

**URL:** <https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849>\
**Category:** Logstash\
**Created:** [May 3, 2022, 3:05pm UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849 "2022-05-03T15:05:35Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![splitmessage88](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Post date:** [May 3, 2022, 3:05pm UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849/1 "2022-05-03T15:05:35Z")

</div>

Hi,  
I created a filter for cisco syslog, input source cisco FTD.  
All the fields are parsing correctly but I can't rename/remove fields with mutate after I used the kv {} filter.

1. Is it possible to use mutate after kv filter, or do I need to use grok patterns then mutate?
2. I'm able to remove the "data" field from ES output, is it possible to only remove fields, not change them?

```auto
filter {
  if [type] == "ling_ftd" {
    grok {
      match => { "message" => "(?<timestamp>%{MONTH} %{MONTHDAY} %{YEAR} %{TIME}) %{WORD:hosthostname}%{SPACE}%(.*?):%{SPACE} %{GREEDYDATA:data}" }
      overwrite => ["data"]
  }
    kv {
      source => "data"
      field_split => ","
      value_split => ":"
 }
    mutate {
      rename => [
        "Client", "client",
        "DstIP", "destination.ip"
        ]
    remove_field => ['data']
 }
}
  else if [type] == "trend_dsm" {
    grok {
      match => { "message" => "%{GREEDYDATA:message}" }
  }
 }
  else if [type] == "meraki" {
    grok {
      match => { "message" => "%{GREEDYDATA:message}" }
  }
 }
}

```

Some sample output

```auto
  "_version": 1,
    "_score": 1,
    "_ignored": [
      "event.original.keyword",
      "message.keyword"
    ],
    "_source": {
      " EgressVRF": "test",
      " ResponderBytes": "46",
      " ApplicationProtocol": "ICMP",

```

```auto
"fields": {
      "EventPriority.keyword": [
        "Low"
      ],
      " IngressVRF": [
        "Global"
      ],
      " InstanceID.keyword": [
        "3"
      ],

.......
  ],
      " DstIP.keyword": [
        "10.x.x.x"

.....
 ],
      " ACPolicy": [
        "Policy"
      ],
      "EventPriority": [
        "Low"
      ],
      "timestamp": [
        "May 03 2022 15:03:09"
      ],
      " DstIP": [
        "10.x.x.x"

```

Thanks.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 3, 2022, 3:15pm UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849/2 "2022-05-03T15:15:47Z")

</div>

You need to provide an example message so people can try to replicate your issue.

---

<div class="post-metadata">

**Author:** ![splitmessage88](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Post date:** [May 3, 2022, 3:20pm UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849/3 "2022-05-03T15:20:14Z")

</div>

Hello leandrojmp,

Sample message below

> message  
> May 03 2022 15:03:09 hostname %FTD-1-4123: EventPriority: Low, DeviceUUID: 123-456-789-146-a34612, InstanceID: 3, FirstPacketSecond: 2022-05-03T15:03:09Z, ConnectionID: 536, AccessControlRuleAction: Allow, SrcIP: 10.10.10.2, DstIP: 192.168.52.71, ICMPType: Echo Request, ICMPCode: No Code, Protocol: icmp, IngressInterface: outside, EgressInterface: test

Thank you.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 3, 2022, 5:03pm UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849/4 "2022-05-03T17:03:16Z")

</div>

All your field names extract from the `data` field, except the first one, have a leading space, your mutate is not working because the fields `"Client"` or `"DstIp"` don't exist, you have `" Client"` and `" DstIp"`.

Try to change your `field_split` in the kv filter to `", "`

Also, the `rename` option from the mutate filter expects a hash and the correct way to reference to nested fields in logstash is `[top][nested]`, not `top.nested`, the second way will create a field with a literal dot in the name.

Your mutate should be.

```auto
mutate {
    rename => {
        "Client" => "client"
        "DstIp" => "[destination][ip]"
   }
    remove_field => ["data"]
}

```

---

<div class="post-metadata">

**Author:** ![splitmessage88](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Post date:** [May 3, 2022, 8:08pm UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849/5 "2022-05-03T20:08:46Z")

</div>

Thank you for the support leandrojmp!

I changed the field\_split in the kv filter to ", " and used your mutate proposal and it solved my problem. I didn't see the space at all. 😃

Is it possible to set a configuration to ignore spaces so this doesn't happen again?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2022, 3:09am UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849/6 "2022-05-04T03:09:33Z")

</div>

> [@splitmessage88](#):
>
> Is it possible to set a configuration to ignore spaces so this doesn't happen again?

Another approach is to use the [trim\_key](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html#plugins-filters-kv-trim_key) and trim\_value options on the filter to remove these if they are not always present.

---

<div class="post-metadata">

**Author:** ![splitmessage88](https://avatars.discourse-cdn.com/v4/letter/s/a87d85/32.png) [@splitmessage88](https://discuss.elastic.co/u/splitmessage88)\
**Post date:** [May 4, 2022, 5:56am UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849/7 "2022-05-04T05:56:19Z")

</div>

Hi Badger,

Thank you for the advice!

Now the script works.

```auto
 kv {
      source => "data"
      trim_key => "\s"
      field_split => ","
      value_split => ":"
 }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2022, 5:56am UTC](https://discuss.elastic.co/t/logstash-mutate-not-working-after-kv-filter-applied/303849/8 "2022-06-01T05:56:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
