# Use KV filter in logstash can not filter?

**URL:** <https://discuss.elastic.co/t/use-kv-filter-in-logstash-can-not-filter/305446>\
**Category:** Logstash\
**Created:** [May 24, 2022, 3:41am UTC](https://discuss.elastic.co/t/use-kv-filter-in-logstash-can-not-filter/305446 "2022-05-24T03:41:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![GhostRaven](https://avatars.discourse-cdn.com/v4/letter/g/779978/32.png) [@GhostRaven](https://discuss.elastic.co/u/GhostRaven)\
**Post date:** [May 24, 2022, 3:41am UTC](https://discuss.elastic.co/t/use-kv-filter-in-logstash-can-not-filter/305446/1 "2022-05-24T03:41:01Z")

</div>

Use KV filter in logstash. I can get the value, but can not filter ? why ? Does the key can not be uppercase?

```auto
if [host] == "10.9.10.10"
    {
         kv
         {
           include_keys => ["ACMAC", "ACNAME", "APMAC", "APNAME", "SSID", "RADIOID", "USER", "MAC", "IPADDRESS"]
           default_keys => ["hostname", "XAFDWLC01", "type", "AC"]
           value_split => ":" 
           field_split => ";"
           trim_value => "<>\[\],"
         }

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/b/ab397d9c8722b7863f8f62f30c1a7493d1d7abdd.png)

the raw message like this :

```auto
	<189>2022-05-24 11:43:43+08:00 NJ_AC_1 %%01CM/5/USER_OFFLINERESULT(s)[8242]:[WLAN_STA_INFO_OFFLINE]ACMAC:c0-f6-c2-bc-db-4b;ACNAME:NJ_AC_1;APMAC:28-68-d2-24-b5-c0;APNAME:NJ-910-AP-03;SSID:xmly-guset;RADIOID:0;USER:322c3bbea931;MAC:32-2c-3b-be-a9-31;IPADDRESS:10.11.22.65;TIME:1653363823;ZONE:UTC+0800;DAYLIGHT:false;SESSIONTIME:208;ERRCODE:216;RESULT:STA disassociation;USERGROUP:NULL;AUTHENPLACE:None;EXTENDINFO:The signal strength of the STA is -36 dbm.;CIB ID:12255;INTERFACE:Wlan-Dbss17524;ACCESS TYPE:None;RDSIP:-;Portal TYPE:-;AUTHID=2808033750;

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 24, 2022, 3:45am UTC](https://discuss.elastic.co/t/use-kv-filter-in-logstash-can-not-filter/305446/2 "2022-05-24T03:45:33Z")

</div>

Without showing us what you [message] field looks like there is no way we can know what the filter should look like.

---

<div class="post-metadata">

**Author:** ![GhostRaven](https://avatars.discourse-cdn.com/v4/letter/g/779978/32.png) [@GhostRaven](https://discuss.elastic.co/u/GhostRaven)\
**Post date:** [May 24, 2022, 10:29am UTC](https://discuss.elastic.co/t/use-kv-filter-in-logstash-can-not-filter/305446/3 "2022-05-24T10:29:45Z")

</div>

It is done. ES has no mapping about this type device. [reason I don't know]. I restart es and rebulid the index of kibana, then all is ok

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 21, 2022, 10:30am UTC](https://discuss.elastic.co/t/use-kv-filter-in-logstash-can-not-filter/305446/4 "2022-06-21T10:30:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
