# Parsing logs with a value\_split

**URL:** <https://discuss.elastic.co/t/parsing-logs-with-a-value-split/367059>\
**Category:** Logstash\
**Created:** [September 24, 2024, 3:09pm UTC](https://discuss.elastic.co/t/parsing-logs-with-a-value-split/367059 "2024-09-24T15:09:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![user-27022024](https://avatars.discourse-cdn.com/v4/letter/u/ce7236/32.png) [@user-27022024](https://discuss.elastic.co/u/user-27022024)\
**Post date:** [September 24, 2024, 3:09pm UTC](https://discuss.elastic.co/t/parsing-logs-with-a-value-split/367059/1 "2024-09-24T15:09:44Z")

</div>

```auto
  "processors" : [
      {
        "grok": {
          "field": "log",
          "patterns": ["%{TIME_STAMP:ts} %{GREEDYDATA:logtail}"],
          "pattern_definitions" : {
             "TIME_STAMP" : "%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{TIME}"
          },
          "ignore_failure" : true,
          "ignore_missing" : true
        }
      },
      {
        "kv" : {
          "field": "logtail",
          "field_split": "\\s(?![^=]+?(\\s|$))",
          "value_split": "=",
          "ignore_failure" : true
        }
      },
      {
        "remove" : {
          "field": "logtail",
          "ignore_failure" : true
        }
      },
      {
        "date" : {
          "field" : "ts",
          "formats" : ["yyyy-MM-dd HH:mm:ss,SSS"],
          "ignore_failure" : true
        }
      }
  ]

```

Above is our grok pipeline.

Normally our logs are nice and clean

e.g "2024-09-24 15:07:59,572 level=INFO channel=wsgi.request method=GET path=/health/ user\_agent="ELB-HealthChecker/2.0" request\_action=finish duration=0.005 status=200 content\_length=26"

That works perfectly.

but for example if we have another `=` in the log all hell breaks loose!

e.g.

`2024-09-24 15:07:59,572 level=INFO channel=wsgi.request method=GET path=/job?id=12345 user_agent="ELB-HealthChecker/2.0" request_action=finish duration=0.005 status=200 content_length=26"`

This seems like it must be a very common use case, is there an off the shelf fix for it?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 24, 2024, 3:14pm UTC](https://discuss.elastic.co/t/parsing-logs-with-a-value-split/367059/2 "2024-09-24T15:14:17Z")

</div>

That's really not a logstash question.

---

<div class="post-metadata">

**Author:** ![user-27022024](https://avatars.discourse-cdn.com/v4/letter/u/ce7236/32.png) [@user-27022024](https://discuss.elastic.co/u/user-27022024)\
**Post date:** [September 25, 2024, 9:12am UTC](https://discuss.elastic.co/t/parsing-logs-with-a-value-split/367059/3 "2024-09-25T09:12:06Z")

</div>

What type of question is it then?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 25, 2024, 12:30pm UTC](https://discuss.elastic.co/t/parsing-logs-with-a-value-split/367059/4 "2024-09-25T12:30:29Z")

</div>

It is about elasticsearch ingestion pipelines, not logstash.
