# Repeated keys converted to array

**URL:** <https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035>\
**Category:** Logstash\
**Created:** [October 27, 2015, 2:02am UTC](https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035 "2015-10-27T02:02:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mihir\_ray](https://avatars.discourse-cdn.com/v4/letter/m/e95f7d/32.png) [@mihir\_ray](https://discuss.elastic.co/u/mihir_ray)\
**Post date:** [October 27, 2015, 2:02am UTC](https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035/1 "2015-10-27T02:02:28Z")

</div>

HI,

I am getting repeated keys in my log data.  
In such a case i want to just pick one key-value pair for my output, but logstash creates a array of values.

Is there a way to pick just one key-value when there are duplicate keys?

Thanks,  
Mihir Ray

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 27, 2015, 7:07am UTC](https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035/2 "2015-10-27T07:07:20Z")

</div>

It's not very clear what you're asking. Please provide an example of what you currently have and what you'd like to get instead.

---

<div class="post-metadata">

**Author:** ![mihir\_ray](https://avatars.discourse-cdn.com/v4/letter/m/e95f7d/32.png) [@mihir\_ray](https://discuss.elastic.co/u/mihir_ray)\
**Post date:** [November 16, 2015, 8:21pm UTC](https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035/3 "2015-11-16T20:21:37Z")

</div>

Suppose my data is "a=1&c=1&a=2", if i use the kv filter, i will get:

a=[1,2]  
c=1

Instead of creating an array for "a", i want it to be a regular string(either 1 or 2), any random value is fine.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 16, 2015, 8:31pm UTC](https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035/4 "2015-11-16T20:31:44Z")

</div>

See [`allow_duplicate_values`](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html#plugins-filters-kv-allow_duplicate_values). When in doubt, consult the documentation and look at what's available.

---

<div class="post-metadata">

**Author:** ![mihir\_ray](https://avatars.discourse-cdn.com/v4/letter/m/e95f7d/32.png) [@mihir\_ray](https://discuss.elastic.co/u/mihir_ray)\
**Post date:** [November 16, 2015, 8:34pm UTC](https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035/5 "2015-11-16T20:34:14Z")

</div>

allow\_duplicate\_values works when the values are same for duplicate keys.  
In my case the values are different and i want to pick one.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 16, 2015, 9:41pm UTC](https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035/6 "2015-11-16T21:41:30Z")

</div>

Oh, right. In that case you'll have to use a ruby filter to iterate over fields and turn array fields into scalar values.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:22am UTC](https://discuss.elastic.co/t/repeated-keys-converted-to-array/33035/7 "2017-07-06T05:22:40Z")

</div>


