# Graylog pipeline keys with spaces

**URL:** <https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, debuggingpl\
**Created:** [August 19, 2021, 6:21am UTC](https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940 "2021-08-19T06:21:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![syntax](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@syntax](https://community.graylog.org/u/syntax)\
**Post date:** [August 19, 2021, 6:21am UTC](https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940/1 "2021-08-19T06:21:38Z")

</div>

Does anyone know if graylog pipeline rule supports keys with spaces? Mine seems to completely skip the parsing.

```
set_fields (
    key_value(
        value: $message.message,
        delimiters: ",",
        kv_delimiters: ":",
        trim_value_chars: "",
        trim_key_chars:""
    )
);

```

e.g. `test key:value`

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [August 19, 2021, 8:22am UTC](https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940/2 "2021-08-19T08:22:01Z")

</div>

Hi @syntax

I don’t think so. Please post your real example messages, so we can help. Maybe replace space with something will work.

---

<div class="post-metadata">

**Author:** ![syntax](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@syntax](https://community.graylog.org/u/syntax)\
**Post date:** [August 19, 2021, 8:35am UTC](https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940/3 "2021-08-19T08:35:56Z")

</div>

@shoothub

example:

2021-06-19 14:23:15 Message details, file: c:\users\admin\desktop\file.exe, **log type** : alert, **ip address** : 127.0.0.1

i have about a thousand log formats…so adding a dash/underscore would be very tedious.

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [August 19, 2021, 2:06pm UTC](https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940/4 "2021-08-19T14:06:44Z")

</div>

There is already a feature request out there to solve this that has been sitting around for a bit (since Jan 2020)- here is the original post I had on it that includes a link to the feature request to handle it:

> [@Key\_value - remove space in field portion](https://community.graylog.org/t/key-value-remove-space-in-field-portion/13398):
>
> I have a key\_value result but the fields portion have spaces that I need to convert to underscore to use the set\_fields() function. I can use regex\_replace -but- the regex I have matches on spaces in the key and value portion. So for instance: client os version=microsoft windows 10 pro 64-bit becomes client\_os\_version=microsoft\_windows\_10\_pro\_64-bit when what I want is: client\_os\_version=microsoft windows 10 pro 64-bit The usable but not optimal regex with example data ([https://regex101…](https://regex101.com/r/W3kxCd/1)

Get all your friends to look at it and comment that it should be prioritized… 😛

---

<div class="post-metadata">

**Author:** ![syntax](https://avatars.discourse-cdn.com/v4/letter/s/41988e/32.png) [@syntax](https://community.graylog.org/u/syntax)\
**Post date:** [August 20, 2021, 1:38am UTC](https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940/5 "2021-08-20T01:38:51Z")

</div>

@tmacgbay interesting. how did u manage to circumvent the issue?

---

<div class="post-metadata">

**Author:** ![tmacgbay](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/tmacgbay/32/3878_2.png) [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Post date:** [August 20, 2021, 11:59am UTC](https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940/6 "2021-08-20T11:59:43Z")

</div>

I had a previous rule that broke out the `event_description` field as defined by a quoted section of the message, then broke out the portion that needed `key_value()` applied, cleaning up the spaces and commas. Note how the regex is non-capturing for the first two words, then once it’s done its work I am referencing indexes. Also note the commented out `debug()` functions so I could watch what this looked like as it went through. Not pretty and likely not efficient, but I didn’t have thousands of these coming in (small company)

```auto
    let e_message = to_string($message.event_description);

    let desc_parts = regex(pattern: "^(?:\\w+\\s+){2}(.*)\\.\\s+(.+)", value: e_message);
    set_field("event_action", to_string(desc_parts["0"]));
    let desc_lowered = replace(lowercase(to_string(desc_parts["1"]))," , ", ", "); //might have extranious comma's
    let desc_cleaned = regex_replace("\\b\\s+", desc_lowered , "_"); //replace unwonted spaces 
    let keyed_up = key_value(desc_cleaned,
                                ",",
                                ":",
                                true,
                                true,
                                "take_last",
                                " ",
                                " "
                    );

    //debug("$$$$---Event to be :");
    //debug(to_string(keyed_up));

    set_fields(keyed_up);

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 3, 2021, 12:00pm UTC](https://community.graylog.org/t/graylog-pipeline-keys-with-spaces/20940/7 "2021-09-03T12:00:42Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
