# Parsing array elements in logs into array

**URL:** <https://discuss.elastic.co/t/parsing-array-elements-in-logs-into-array/109407>\
**Category:** Logstash\
**Created:** [November 28, 2017, 2:09pm UTC](https://discuss.elastic.co/t/parsing-array-elements-in-logs-into-array/109407 "2017-11-28T14:09:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tanji](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@tanji](https://discuss.elastic.co/u/tanji)\
**Post date:** [November 28, 2017, 2:09pm UTC](https://discuss.elastic.co/t/parsing-array-elements-in-logs-into-array/109407/1 "2017-11-28T14:09:00Z")

</div>

My logs contain arbitrary array elements e.g. `item[0]=value0`, `item[1]=value1`.  
The number of elements can vary from logline to logline.

I'm looking for a way to parse those elements and combine them into an array, e.g. `items=[value0, value1]` or join them into a string, but I haven't found any filter so far that appears to cover this use case.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 28, 2017, 2:13pm UTC](https://discuss.elastic.co/t/parsing-array-elements-in-logs-into-array/109407/2 "2017-11-28T14:13:28Z")

</div>

Can you give a concrete example of a log entry?

---

<div class="post-metadata">

**Author:** ![tanji](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@tanji](https://discuss.elastic.co/u/tanji)\
**Post date:** [November 28, 2017, 2:32pm UTC](https://discuss.elastic.co/t/parsing-array-elements-in-logs-into-array/109407/3 "2017-11-28T14:32:03Z")

</div>

Of course, here's one:

```auto
rnd=0.013803167429344732&version=1.0&_l=https://www.example.de/checkout/success&_ld=www.example.de&_r=https://www.example.com/webapps/hermes?flow=1-P&ulReturn=true&token=EC-token&useraction=commit&country.x=DE&locale.x=de_DE&_rd=www.example.com&siteid=443286&item[name]=Order Done&order[id]=DE606153525&order[shipping]=0.00&order[revenue]=35.03&order[profit]=0.00&order[currency]=EUR&order_items[ids][0]=364110&order_items[ids][1]=1000857&order_items[prices][0]=23.16&order_items[prices][1]=11.87&order_items[quantities][0]=1&order_items[quantities][1]=1&category[name]=Order&category[path]=order/done&r=0.09882929320583189&u=05ht69iasqdt.1509025003878&remote_addr=1.1.1.1&time=1511875322&user_agent=Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0&_auid=8317460762713324393&cookie__auid=8317460762713324393

```

Typical example above is `order_items[ids][n]` fields.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 28, 2017, 3:02pm UTC](https://discuss.elastic.co/t/parsing-array-elements-in-logs-into-array/109407/4 "2017-11-28T15:02:17Z")

</div>

Use a kv filter to parse the key=value pairs in the string into fields. Then write a piece of Ruby code in a ruby filter that processes the resulting fields and gathers the values of the fields whose names have the form `order_items[ids][n]`.

---

<div class="post-metadata">

**Author:** ![tanji](https://avatars.discourse-cdn.com/v4/letter/t/7993a0/32.png) [@tanji](https://discuss.elastic.co/u/tanji)\
**Post date:** [November 28, 2017, 3:21pm UTC](https://discuss.elastic.co/t/parsing-array-elements-in-logs-into-array/109407/5 "2017-11-28T15:21:18Z")

</div>

Magnus, thanks for the hint. I actually do use a kv filter already. I would have expected to do the rest without a Ruby filter, but seems I'll have to regardless. I'll see what I can come up with.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2017, 3:21pm UTC](https://discuss.elastic.co/t/parsing-array-elements-in-logs-into-array/109407/6 "2017-12-26T15:21:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
