# Working with key:value arrays

**URL:** <https://discuss.elastic.co/t/working-with-key-value-arrays/283772>\
**Category:** Logstash\
**Created:** [September 9, 2021, 12:34pm UTC](https://discuss.elastic.co/t/working-with-key-value-arrays/283772 "2021-09-09T12:34:32Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![awer1967](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/awer1967/32/60187_2.png) [@awer1967](https://discuss.elastic.co/u/awer1967)\
**Post date:** [September 9, 2021, 12:34pm UTC](https://discuss.elastic.co/t/working-with-key-value-arrays/283772/1 "2021-09-09T12:34:32Z")

</div>

Good day !

Accordingly to my logstash configuration I get a message with an array consists of key:value pairs.

I have to mutate it on a very special way adding two fields and put there the key and the value . For example

An incoming message looks like:

"22.114":"1234,88","22.456":"345"

So the mutated one should look as

"Field1":"22.114","Field2":"1234,88"  
"Field1":"22.456","Field2":"345"

I guess that I should use ruby but it is unclear to me how to use it to get the result.  
Any help would be appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 9, 2021, 6:56pm UTC](https://discuss.elastic.co/t/working-with-key-value-arrays/283772/2 "2021-09-09T18:56:58Z")

</div>

It is unclear what you want to do. Do you want two events each containing [Field1] and [Field2]?

---

<div class="post-metadata">

**Author:** ![awer1967](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/awer1967/32/60187_2.png) [@awer1967](https://discuss.elastic.co/u/awer1967)\
**Post date:** [September 9, 2021, 8:23pm UTC](https://discuss.elastic.co/t/working-with-key-value-arrays/283772/3 "2021-09-09T20:23:23Z")

</div>

I have an event looks like an array of key:value pairs . I want to transform it into multiple events ,where each of them consists of two fields . A first field value is the key from array and a second field value is the value from array.  
Sure , based on my example I want to transform the array into 2 events with those 2 fields

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 9, 2021, 9:37pm UTC](https://discuss.elastic.co/t/working-with-key-value-arrays/283772/4 "2021-09-09T21:37:31Z")

</div>

Your values contain commas, so a simple mutate+split will incorrectly parse the [message]. Luckily, a kv filter parses it correctly

```
kv { field_split => "," value_split => ":" trim_key => '"' target => "[@metadata][kvData]" }
    ruby {
        code => '
            kvData = event.get("[@metadata][kvData]")
            if kvData
                data = []
                kvData.each { |k, v|
                    data << { "Field1" => k, "Field2" => v }
                }
                event.set("someField", data)
            end
        '
    }
    split { field => "someField" }

```

You can move the results to the top level using [this](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2) code.

I think using a kv filter is fragile, and I would do it in ruby.

```
    ruby {
        code => '
            matches = event.get("message").scan(/"([^"]*)":"([^"]*)"(,|$)/)
            data = []
            matches.each_index { |x|
                data << { "Field1" => matches[x][0], "Field2" => matches[x][1] }
            }
            event.set("someField", data)
        '
    }
    split { field => "someField" }

```

Although that regexp may not be any less fragile than the kv filter 😃

---

<div class="post-metadata">

**Author:** ![awer1967](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/awer1967/32/60187_2.png) [@awer1967](https://discuss.elastic.co/u/awer1967)\
**Post date:** [September 10, 2021, 1:06am UTC](https://discuss.elastic.co/t/working-with-key-value-arrays/283772/5 "2021-09-10T01:06:04Z")

</div>

Thanks a lot ! It is the thing I have been looking for !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 8, 2021, 1:07am UTC](https://discuss.elastic.co/t/working-with-key-value-arrays/283772/6 "2021-10-08T01:07:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
