WARNING: Version 6.0 of Elasticsearch has passed its EOL date.
This documentation is no longer being maintained and may be removed. If you are running this version, we strongly advise you to upgrade. For the latest information, see the current release documentation.
KV Processor
editKV Processor
editThis processor helps automatically parse messages (or specific event fields) which are of the foo=bar variety.
For example, if you have a log message which contains ip=1.2.3.4 error=REFUSED
, you can parse those automatically by configuring:
{ "kv": { "field": "message", "field_split": " ", "value_split": "=" } }
Table 24. Kv Options
Name | Required | Default | Description |
---|---|---|---|
|
yes |
- |
The field to be parsed |
|
yes |
- |
Regex pattern to use for splitting key-value pairs |
|
yes |
- |
Regex pattern to use for splitting the key from the value within a key-value pair |
|
no |
|
The field to insert the extracted keys into. Defaults to the root of the document |
|
no |
|
List of keys to filter and insert into document. Defaults to including all keys |
|
no |
|
List of keys to exclude from document |
|
no |
|
If |