# Processing hashlist/Json attributes with fingerprint plugin

**URL:** <https://discuss.elastic.co/t/processing-hashlist-json-attributes-with-fingerprint-plugin/83363>\
**Category:** Logstash\
**Created:** [April 24, 2017, 6:57am UTC](https://discuss.elastic.co/t/processing-hashlist-json-attributes-with-fingerprint-plugin/83363 "2017-04-24T06:57:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![davidS](https://avatars.discourse-cdn.com/v4/letter/d/65b543/32.png) [@davidS](https://discuss.elastic.co/u/davidS)\
**Post date:** [April 24, 2017, 6:57am UTC](https://discuss.elastic.co/t/processing-hashlist-json-attributes-with-fingerprint-plugin/83363/1 "2017-04-24T06:57:31Z")

</div>

Hi all,

I try to get the values of a kv-plugin produces Key-Value Hashlist parameter to process it by the fingerprint-plugin. So here are my filter code and the result.

```
filter {
  kv {
    source => "uriparam"
    field_split => "=&"
    target => "uriparams"
  }
  json_encode {
    source => "uriparams"
  }
  json {
    source => "uriparams"
    target => "test"
  }
}

```

Result in:

```
"test" => {
    "key1" => "var1",
    "key2" => "var2"
},
"uriparams" => "{\"key1\":\"var1\",\"key2\":\"var2\"}"

```

How can I get all Values from the Hashlist or the Json-String to process all of them by the fingerprint-plugin to produces Hashed Values instead of human readable ones?

I could'nt find a solution for that usecase.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 25, 2017, 2:58pm UTC](https://discuss.elastic.co/t/processing-hashlist-json-attributes-with-fingerprint-plugin/83363/2 "2017-04-25T14:58:41Z")

</div>

You mean you want `{"key1": "<hash of var1>", ...}` instead of `{"key1": "var1", ...}`? You'll have to use a ruby filter for that.

---

<div class="post-metadata">

**Author:** ![davidS](https://avatars.discourse-cdn.com/v4/letter/d/65b543/32.png) [@davidS](https://discuss.elastic.co/u/davidS)\
**Post date:** [April 28, 2017, 11:20am UTC](https://discuss.elastic.co/t/processing-hashlist-json-attributes-with-fingerprint-plugin/83363/3 "2017-04-28T11:20:19Z")

</div>

Thanks for answering. So I found a solution for that with logstash's ruby filter plugin.

```
ruby {
  add_field => { "uriparams_hashed" => {} }
  code => "
    if event.get('[uriparams]')
      event.get('[uriparams]').each { |key, value| event.set('[uriparams_hashed]['+key.to_s+']', Digest::MD5.digest(value)) }
    end "
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2017, 11:26am UTC](https://discuss.elastic.co/t/processing-hashlist-json-attributes-with-fingerprint-plugin/83363/4 "2017-05-26T11:26:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
