# Key:value extractor

**URL:** <https://community.graylog.org/t/key-value-extractor/17585>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [October 21, 2020, 2:57pm UTC](https://community.graylog.org/t/key-value-extractor/17585 "2020-10-21T14:57:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [October 21, 2020, 2:57pm UTC](https://community.graylog.org/t/key-value-extractor/17585/1 "2020-10-21T14:57:57Z")

</div>

Hi all,  
I need an help. I’m using Graylog for VPN target that send me messages like this:

message: “some data that I don’t need - [userid:xxx; action:Log In; …]”  
Is there some extractors that I can use to have key - value attributes?

I means: something that is able to set the internal square brackets data as key/value fields?  
So that I have the original message and the additional fields extracted like:  
userid - xxx  
action - Lon In

and so on  
Thanks

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [October 22, 2020, 8:27am UTC](https://community.graylog.org/t/key-value-extractor/17585/2 "2020-10-22T08:27:11Z")

</div>

Easiest way is to use pipeline rule, first extract content within `[]` with `regex()` function and than use `key_value()` function:

```auto
rule "KV VPN"
when
    has_field("message")
then
    let kv_extract = regex("\\[(.*?)\\]",to_string($message.message));
    let kv_value = to_string(kv_extract["0"]);
    set_fields(key_value(
            value: kv_value,
            delimiters: ";",
            kv_delimiters: ":",
            ignore_empty_values: true,
            allow_dup_keys: true, // the default
            handle_dup_keys: "," // meaning concat, default "take_first"
    ));
end

```

---

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [October 22, 2020, 10:07am UTC](https://community.graylog.org/t/key-value-extractor/17585/3 "2020-10-22T10:07:46Z")

</div>

Hi @shoothub,  
thanks a lot for your help and suggestions

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [November 5, 2020, 10:07am UTC](https://community.graylog.org/t/key-value-extractor/17585/4 "2020-11-05T10:07:53Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
