# \#key\_value

**URL:** https://community.graylog.org/tag/key-value/79.md

[Latest](https://community.graylog.org/latest.md) · [Categories](https://community.graylog.org/categories.md) · [Tags](https://community.graylog.org/tags.md)

---

## [How do I get CSV lookup table parameter working in an event definition?](https://community.graylog.org/t/how-do-i-get-csv-lookup-table-parameter-working-in-an-event-definition/36831)

<div class="topic-metadata">

**Author:** [@huimin](https://community.graylog.org/u/huimin)\
**Replies:** 0\
**Last updated:** [January 8, 2026, 10:22am UTC](https://community.graylog.org/t/how-do-i-get-csv-lookup-table-parameter-working-in-an-event-definition/36831 "2026-01-08T10:22:43Z")

</div>

1. Describe your incident: I have followed the instructions in https://graylog.org/post/risk-based-alerts/ and gotten a working event. I am trying to do something similar using the CSV file data adapter. I am not sure w…

---

## [Trying to use Pipelines to extract falues from a field](https://community.graylog.org/t/trying-to-use-pipelines-to-extract-falues-from-a-field/36715)

<div class="topic-metadata">

**Author:** [@dannymccaslin](https://community.graylog.org/u/dannymccaslin)\
**Replies:** 2\
**Last updated:** [December 12, 2025, 8:21pm UTC](https://community.graylog.org/t/trying-to-use-pipelines-to-extract-falues-from-a-field/36715 "2025-12-12T20:21:57Z")

</div>

I’m trying to extract some data from a particular field using Pipelines and while I think I understand it theoretically, I can’t seem to wrap my head around making it happen. We have a Palo Alto firewall with a VPN. We …

---

## [Parsing bitwise values](https://community.graylog.org/t/parsing-bitwise-values/34095)

<div class="topic-metadata">

**Author:** [@Zoddo](https://community.graylog.org/u/Zoddo)\
**Replies:** 0\
**Last updated:** [November 8, 2024, 3:18pm UTC](https://community.graylog.org/t/parsing-bitwise-values/34095 "2024-11-08T15:18:10Z")

</div>

Hello, I’m trying to parse a bitwise value from a Windows event log (values from this table) in Graylog 5.2.12 (upgrade to 6.1 is planned before the end of the year). I’d like to get something like that: 0x00001 = R 0…

---

## [Pipeline Rule: Issues with key\_value function (fields can be created in Simulator, but not in real time)](https://community.graylog.org/t/pipeline-rule-issues-with-key-value-function-fields-can-be-created-in-simulator-but-not-in-real-time/33447)

<div class="topic-metadata">

**Author:** [@bettels-uhi](https://community.graylog.org/u/bettels-uhi)\
**Replies:** 1\
**Last updated:** [September 5, 2024, 1:45pm UTC](https://community.graylog.org/t/pipeline-rule-issues-with-key-value-function-fields-can-be-created-in-simulator-but-not-in-real-time/33447 "2024-09-05T13:45:30Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [How to receive Logs from Nodes](https://community.graylog.org/t/how-to-receive-logs-from-nodes/32254)

<div class="topic-metadata">

**Author:** [@yardtheyard](https://community.graylog.org/u/yardtheyard)\
**Replies:** 5\
**Last updated:** [April 29, 2024, 4:36pm UTC](https://community.graylog.org/t/how-to-receive-logs-from-nodes/32254 "2024-04-29T16:36:14Z")

</div>

1. Describe your incident: I need to set up GrayLog for my apprentice ship. So its just for documentation and skill proofing purposes. I have set up the GUI and now have 3 simple Debian systems wich I want to collect so…

---

## [Graylog pipeline: handling null values](https://community.graylog.org/t/graylog-pipeline-handling-null-values/31781)

<div class="topic-metadata">

**Author:** [@jgrammen\_agility](https://community.graylog.org/u/jgrammen_agility)\
**Replies:** 0\
**Last updated:** [March 11, 2024, 2:29pm UTC](https://community.graylog.org/t/graylog-pipeline-handling-null-values/31781 "2024-03-11T14:29:21Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Any plans on allowing dots in field names?](https://community.graylog.org/t/any-plans-on-allowing-dots-in-field-names/31324)

<div class="topic-metadata">

**Author:** [@ioniclysm](https://community.graylog.org/u/ioniclysm)\
**Replies:** 0\
**Last updated:** [January 25, 2024, 8:59am UTC](https://community.graylog.org/t/any-plans-on-allowing-dots-in-field-names/31324 "2024-01-25T08:59:42Z")

</div>

Any plans on giving an optional setting to users to allow field names with dots? " . " rather than enforcing underscore?

---

## [Graylog Lookup Table returning Null Values for lookup against CSV file?](https://community.graylog.org/t/graylog-lookup-table-returning-null-values-for-lookup-against-csv-file/30673)

<div class="topic-metadata">

**Author:** [@Jones453](https://community.graylog.org/u/Jones453)\
**Replies:** 6\
**Last updated:** [November 22, 2023, 9:21am UTC](https://community.graylog.org/t/graylog-lookup-table-returning-null-values-for-lookup-against-csv-file/30673 "2023-11-22T09:21:58Z")

</div>

Describe your incident: My Lookup Table in Graylog is returning null values for the lookups to my CSV key:value pairs. For this file, I do have the columns “Snacks,” “Calories,” “Sodium,” and “Type of Snack,” but the ke…

---

## [IPFIX input Multiple entries with same key](https://community.graylog.org/t/ipfix-input-multiple-entries-with-same-key/30047)

<div class="topic-metadata">

**Author:** [@mcury](https://community.graylog.org/u/mcury)\
**Replies:** 0\
**Last updated:** [September 7, 2023, 9:04pm UTC](https://community.graylog.org/t/ipfix-input-multiple-entries-with-same-key/30047 "2023-09-07T21:04:26Z")

</div>

I’m exporting IPFIX (netflow v10) flows from pfSense to Graylog using the IPFIX UDP input. I created the .json with the IPFIX field definitions found here iana and here RFC5102 and it is working. However, when I set pf…

---

## [HTTP JSON lookup adapter can not find property](https://community.graylog.org/t/http-json-lookup-adapter-can-not-find-property/29796)

<div class="topic-metadata">

**Author:** [@jmkofoed](https://community.graylog.org/u/jmkofoed)\
**Replies:** 3\
**Last updated:** [August 11, 2023, 10:23am UTC](https://community.graylog.org/t/http-json-lookup-adapter-can-not-find-property/29796 "2023-08-11T10:23:32Z")

</div>

1. Describe your incident: We have created a lookup table which has worked but is now failing. We have a http service which lookup SID and convert to account names. We have created a HTTP JSONPath data adapter: URL: h…

---

## [License error, imput error in ssl/tls configuration... What?](https://community.graylog.org/t/license-error-imput-error-in-ssl-tls-configuration-what/27473)

<div class="topic-metadata">

**Author:** [@jgutie45](https://community.graylog.org/u/jgutie45)\
**Replies:** 9\
**Last updated:** [February 3, 2023, 7:03am UTC](https://community.graylog.org/t/license-error-imput-error-in-ssl-tls-configuration-what/27473 "2023-02-03T07:03:02Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Microsoft365 ExtendedProperties](https://community.graylog.org/t/microsoft365-extendedproperties/26888)

<div class="topic-metadata">

**Author:** [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Replies:** 4\
**Last updated:** [December 15, 2022, 10:49pm UTC](https://community.graylog.org/t/microsoft365-extendedproperties/26888 "2022-12-15T22:49:12Z")

</div>

Hi, using Grylog 4.3.7 i’m wrking with Microsoft 365 ingestion log. Now the problem is ExtendedProperties like field. I use the default json extractor but I have differente valure from input and extracted tag: The lo…

---

## [The GPG key of Graylog is unvalid](https://community.graylog.org/t/the-gpg-key-of-graylog-is-unvalid/25329)

<div class="topic-metadata">

**Author:** [@Bob](https://community.graylog.org/u/Bob)\
**Replies:** 2\
**Last updated:** [August 20, 2022, 9:41am UTC](https://community.graylog.org/t/the-gpg-key-of-graylog-is-unvalid/25329 "2022-08-20T09:41:55Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Json with double quote](https://community.graylog.org/t/json-with-double-quote/23986)

<div class="topic-metadata">

**Author:** [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Replies:** 1\
**Last updated:** [May 24, 2022, 6:11pm UTC](https://community.graylog.org/t/json-with-double-quote/23986 "2022-05-24T18:11:05Z")

</div>

Hi guys, I have to manage some input message like this: "{""Actor"":\[{""ID"":""3bd441cb-efea-476f-8a2e-d528bc5373e8"",""Type"":0},{""ID"":""first.last@email.com"",""Type"":5}\], ""ActorContextId"":""9c848b2a-49ba-4c39-9…

---

## [Value comparision from different messages](https://community.graylog.org/t/value-comparision-from-different-messages/23392)

<div class="topic-metadata">

**Author:** [@Drevix](https://community.graylog.org/u/Drevix)\
**Replies:** 2\
**Last updated:** [April 15, 2022, 10:12am UTC](https://community.graylog.org/t/value-comparision-from-different-messages/23392 "2022-04-15T10:12:51Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question. Don’t forget to select tags to help index your topic! 1. Describ…

---

## [Difficulties to apply extractors using regex](https://community.graylog.org/t/difficulties-to-apply-extractors-using-regex/23328)

<div class="topic-metadata">

**Author:** [@lmattos90](https://community.graylog.org/u/lmattos90)\
**Replies:** 46\
**Last updated:** [April 8, 2022, 11:10pm UTC](https://community.graylog.org/t/difficulties-to-apply-extractors-using-regex/23328 "2022-04-08T23:10:14Z")

</div>

Hello Community, I’m having a hard time getting my regex rules to work in Graylog, more specifically in the extractors feature, like the examples below, I’m trying to get specific data inside of the message field, but, …

---

## [Log message with strange source Ip address](https://community.graylog.org/t/log-message-with-strange-source-ip-address/23265)

<div class="topic-metadata">

**Author:** [@miguel](https://community.graylog.org/u/miguel)\
**Replies:** 5\
**Last updated:** [April 7, 2022, 8:26am UTC](https://community.graylog.org/t/log-message-with-strange-source-ip-address/23265 "2022-04-07T08:26:35Z")

</div>

I everybody, I recently installed graylog. Until now everyting is ok except for one stuff: Messages from old cisco switchs 3500XL series it cannot get the IP. With tcpdump i can verify that the message arrivers corre…

---

## [Key\_value gummed up](https://community.graylog.org/t/key-value-gummed-up/22818)

<div class="topic-metadata">

**Author:** [@tmacgbay](https://community.graylog.org/u/tmacgbay)\
**Replies:** 1\
**Last updated:** [February 24, 2022, 9:51pm UTC](https://community.graylog.org/t/key-value-gummed-up/22818 "2022-02-24T21:51:45Z")

</div>

For some reason set\_fields() is not working after my key\_value() function and I can’t find that one thing causing an error. Maybe you can? Here is the scenario. I am running a powershell command that that inserts a te…
