# Extractor Key value with spaces

**URL:** <https://community.graylog.org/t/extractor-key-value-with-spaces/3219>\
**Category:** Graylog Central (peer support)\
**Created:** [November 20, 2017, 11:39am UTC](https://community.graylog.org/t/extractor-key-value-with-spaces/3219 "2017-11-20T11:39:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![xoroz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/xoroz/32/1232_2.png) [@xoroz](https://community.graylog.org/u/xoroz)\
**Post date:** [November 20, 2017, 11:39am UTC](https://community.graylog.org/t/extractor-key-value-with-spaces/3219/1 "2017-11-20T11:39:43Z")

</div>

Hello,

I enjoy using the Extractor Copy Input \> Key Value option  
But when there is value like  
msg=New session created

the space breaks the extraction, and I get only "New"  
Anyone knows a better way to do it?

The whole source message is like this:  
CEF:0|A10|vThunder|2.7.2-P10|WAF|session-id|2|rt=Nov 20 2017 12:37:23 src=93.55.113.54 spt=14142 dst=172.27.234.19 dpt=443 [dhost=asd-wartsila.dsa.it](http://dhost=asd-wartsila.dsa.it) cs1=WAF\_relaxed\_Tmpl cs2=a4d74bbd421bda8c act=learn cs3=learn app=HTTPS requestMethod=GET request=/asdoij/jspgepestyle/FilecomuniReport.jsp?p=5.0.186-001 msg=New session created: Id=a4d74bbd42df1bda8c

thank you

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [November 20, 2017, 11:40am UTC](https://community.graylog.org/t/extractor-key-value-with-spaces/3219/2 "2017-11-20T11:40:38Z")

</div>

You can use the CEF plugin for CEF messages. 😉

> **[Graylog](https://marketplace.graylog.org/addons/b2c55194-a76e-4fd7-89fd-5421188bf33f)**
>
> Graylog

---

<div class="post-metadata">

**Author:** ![xoroz](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/xoroz/32/1232_2.png) [@xoroz](https://community.graylog.org/u/xoroz)\
**Post date:** [November 20, 2017, 1:52pm UTC](https://community.graylog.org/t/extractor-key-value-with-spaces/3219/3 "2017-11-20T13:52:50Z")

</div>

Hi Jochen,  
Thank you for the quick reply.  
I installed and activated the plugin CEF.  
Started on UDP port, traffic is comming ( i can see w/ tcpdump) messages arive but maybe the  
input filter is not working?

org.graylog.plugins.cef.codec.CEFCodec.5a12d75392c2117519b6f7dc.failures  
Meter  
Total:  
138 events

But maybe my messages are not in the correct format…?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [November 20, 2017, 2:27pm UTC](https://community.graylog.org/t/extractor-key-value-with-spaces/3219/4 "2017-11-20T14:27:47Z")

</div>

Try searching “in the future”, e. g. use an absolute time range and set the end a some point some hours in the future to rule out timezone issues.

If the plugin doesn’t work for you, please create a bug report at [https://github.com/Graylog2/graylog-plugin-cef/issues](https://github.com/Graylog2/graylog-plugin-cef/issues) and include some example messages (ideally captured with tcpdump or Wireshark) so we can reproduce the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [December 4, 2017, 2:27pm UTC](https://community.graylog.org/t/extractor-key-value-with-spaces/3219/5 "2017-12-04T14:27:56Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
