# Taking care of syslog PRI header in filter

**URL:** <https://discuss.elastic.co/t/taking-care-of-syslog-pri-header-in-filter/256732>\
**Category:** Logstash\
**Created:** [November 26, 2020, 7:53am UTC](https://discuss.elastic.co/t/taking-care-of-syslog-pri-header-in-filter/256732 "2020-11-26T07:53:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elitlogik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elitlogik/32/78920_2.png) [@Elitlogik](https://discuss.elastic.co/u/Elitlogik)\
**Post date:** [November 26, 2020, 7:53am UTC](https://discuss.elastic.co/t/taking-care-of-syslog-pri-header-in-filter/256732/1 "2020-11-26T07:53:36Z")

</div>

I use kv filter on a syslog data on the form key1=value1 key2=value2 etc.

However, every syslog row has a leading PRI header of key1=value1.

Is there a way to:

1. Parse the pri header and all key-value pairs.

2. Remove the pri header and parse the key-value pairs?

current filter is just

`filter { kv {} }`

Thank you very much for your support!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2020, 7:53am UTC](https://discuss.elastic.co/t/taking-care-of-syslog-pri-header-in-filter/256732/2 "2020-12-24T07:53:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
