Try it free

DPL Key-Value Pairs

  • Latest Dynatrace
  • Reference

KVP

Parses a list of unordered, variable-length key-value pairs according to the supplied pattern.

The pattern must export the following fields:

  • one field named key
  • one or more fields, with the name beginning with value

The specified pattern is applied repeatedly until:

  • an unmatch occurs, or
  • the maximum number of matches has been reached.

The pattern should describe the whole sequence of key-value pairs: that is, the key and value matchers, the separator between key and value, and the separator between pairs. Special attention must be paid to matching the last key-value pair—it is usually not followed by a separator.

Use the following expression to parse the value:

KVP{ WORD:key '=' INT:value ' '? }:result

For example:

Descriptioninput (string)result (record)

Single pair

status=200

{"status":200}

Multiple pairs

status=200 duration=45 retries=3

{"status":200, "duration":45, "retries":3}

Non-matching input

notapair

null

See how to use in DQL
data record(input = "status=200"),
record(input = "status=200 duration=45 retries=3"),
record(input = "notapair")
| parse input, "KVP{ WORD:key '=' INT:value ' '? }:result"

Syntax

KVP{ matcher_expression }( parameter = value, ... ){ min, max }:result

Configuration

parametertypeDescription

charset

string

Character set name enclosed in single or double quotes (for example charset="ISO-8859-1"). Default: none.

locale

string

String specifying an IETF BCP 47 language tag enclosed in single or double quotes (see IANA language subtag registry). The default locale is English. Default: none.

Quantifier

ParameterTypeDescription

min

integer

Minimum number of key-value pairs, as a non-negative integer. Parsing fails and the output returns null if fewer than min pairs match.

max

integer

Maximum number of key-value pairs to capture, greater than or equal to min. Default: 128; maximum: 32768.

Returns

The data type of the extracted value is record.

Practical examples

Example 1: Parse key-value pairs from an XML payload in a log record

Given the following input:

sensor_data: <data>BookingType=STANDARD_BOOKING|Channel=Mobile|PaxCount=1|IsReservation=false</data>

Use the following expression to extract the value:

DATA '>' KVP{ALPHA:key '=' LD:value ('|' | '<')}:result DATA
result (record)
{
"BookingType": "STANDARD_BOOKING",
"Channel": "Mobile",
"PaxCount": "1",
"IsReservation": "false"
}
See how to use in DQL
data record(input = "sensor_data: <data>BookingType=STANDARD_BOOKING|Channel=Mobile|PaxCount=1|IsReservation=false</data>")
| parse input, "DATA '>' KVP{ALPHA:key '=' LD:value ('|' | '<')}:result DATA"
Example 2: Parse structured fields from a WebLogic access log

Given the following input:

[2024-10-31T14:59:48.200+0000] [] [INFO] [] [DEP-ACCESS-LOG] [tid: 125] [timeMillis: 1730386788200] [levelValue: 800] APP_ENV="abc" APP_NAME="dt" HTTP_METHOD="POST" HTTP_STATUS_CODE="200"

Use the following expression to extract the value:

LD KVP{
([A-Z'_']* >> '='):key // key: uppercase letters and underscores, up to the '='
'=' // separator
DQS:value // value: a double-quoted string
(' ' | EOS) // pair ends with a space or end of input
}{1,}:result
result (record)
{
"APP_ENV": "abc",
"APP_NAME": "dt",
"HTTP_METHOD": "POST",
"HTTP_STATUS_CODE": "200"
}
See how to use in DQL
data record(input = """[2024-10-31T14:59:48.200+0000] [] [INFO] [] [DEP-ACCESS-LOG] [tid: 125] [timeMillis: 1730386788200] [levelValue: 800] APP_ENV="abc" APP_NAME="dt" HTTP_METHOD="POST" HTTP_STATUS_CODE="200"""")
| parse input, """LD KVP{
([A-Z'_']* >> '='):key // key: uppercase letters and underscores, up to the '='
'=' // separator
DQS:value // value: a double-quoted string
(' ' | EOS) // pair ends with a space or end of input
}{1,}:result"""
Example 3: Parse values containing URLs and spaces using an alternation terminator

Given the following input:

Log Message Record(a=12345, b=https://example.com, c=word, d=Multiple word value)

Use the following expression to extract the value:

LD 'Record('
KVP{
[a-z]:key // key: single lowercase letter
'=' // separator
LD:value // value: any data up to the next terminator
( ')' | (',' SPACE) ) // last pair ends with ')', all others with ', '
}:result
EOF
result (record)
{
"a": "12345",
"b": "https://example.com",
"c": "word",
"d": "Multiple word value"
}
See how to use in DQL
data record(input = "Log Message Record(a=12345, b=https://example.com, c=word, d=Multiple word value)")
| parse input, """LD 'Record('
KVP{
[a-z]:key // key: single lowercase letter
'=' // separator
LD:value // value: any data up to the next terminator
( ')' | (',' SPACE) ) // last pair ends with ')', all others with ', '
}:result
EOF"""
| fieldsFlatten result
| fieldsRemove result
Example 4: Parse the same record using a lookahead key and quantifier

Given the following input:

Log Message Record(a=12345, b=https://example.com, c=word, d=Multiple word value)

Use the following expression to extract the value:

LD KVP{
([A-Za-z'_']* >> '='):key // key: letters and underscores, up to the '='
'=' // separator
LD:value // value: any data up to the next terminator
(', ' | ')') // pair ends with ', ', last pair ends with ')'
}{1,}:result
result (record)
{
"a": "12345",
"b": "https://example.com",
"c": "word",
"d": "Multiple word value"
}
See how to use in DQL
data record(input = "Log Message Record(a=12345, b=https://example.com, c=word, d=Multiple word value)")
| parse input, """LD KVP{
([A-Za-z'_']* >> '='):key // key: letters and underscores, up to the '='
'=' // separator
LD:value // value: any data up to the next terminator
(', ' | ')') // pair ends with ', ', last pair ends with ')'
}{1,}:result"""
Example 5: Parse key-value pairs from a structured log using lookahead

Given the following input:

[1] - svc=api-router - traceId=a1b2c3d4e5f6 - spanId=f1e2d3c4 - INFO - index region=us-east-2 - accept-language=en-CA httpCode=200 timeTaken=1606

Use the following expression to extract the value:

LD KVP{
SPACE [a-zA-Z_-]+:key // key: letters, hyphens, and underscores after a space
'=' // separator
LD:value // value: any data up to the lookahead terminator
(' -' | (' - ' WORD ' - ' WORD))? // optional noise between pairs, for example " - INFO - index"
>>((SPACE [a-zA-Z_-]+ '=') | EOF) // stop the value at the next " key=" or end of input
}:result
result (record)
{
"svc": "api-router",
"traceId": "a1b2c3d4e5f6",
"spanId": "f1e2d3c4",
"region": "us-east-2",
"accept-language": "en-CA",
"httpCode": "200",
"timeTaken": "1606"
}
See how to use in DQL
data record(input = "[1] - svc=api-router - traceId=a1b2c3d4e5f6 - spanId=f1e2d3c4 - INFO - index region=us-east-2 - accept-language=en-CA httpCode=200 timeTaken=1606")
| parse input, """LD KVP{
SPACE [a-zA-Z_-]+:key // key: letters, hyphens, and underscores after a space
'=' // separator
LD:value // value: any data up to the lookahead terminator
(' -' | (' - ' WORD ' - ' WORD))? // optional noise between pairs, for example " - INFO - index"
>>((SPACE [a-zA-Z_-]+ '=') | EOF) // stop the value at the next " key=" or end of input
}:result"""
Example 6: Parse key-value pairs with complex values using a negated character class

Given the following input:

product record =Product(_id=null, vendorName=example USA INC, vendorId=789659, baseImageUrl=https://www.example.com/productimages/sku/1234567-main-zoom.jpg?imwidth=2000, swName=null, swOrder=30)

Use the following expression to extract the value:

LD 'Product('
KVP{
[a-zA-Z_]+:key // key: letters and underscores
'='
[^,)]+:value // value: any character except ',' and ')'
( ')' | (',' SPACE) ) // last pair ends with ')', all others with ', '
}:result
EOF
result (record)
{
"_id": "null",
"vendorName": "example USA INC",
"vendorId": "789659",
"baseImageUrl": "https://www.example.com/productimages/sku/1234567-main-zoom.jpg?imwidth=2000",
"swName": "null",
"swOrder": "30"
}
See how to use in DQL
data record(input = "product record =Product(_id=null, vendorName=example USA INC, vendorId=789659, baseImageUrl=https://www.example.com/productimages/sku/1234567-main-zoom.jpg?imwidth=2000, swName=null, swOrder=30)")
| parse input, """LD 'Product('
KVP{
[a-zA-Z_]+:key // key: letters and underscores
'='
[^,)]+:value // value: any character except ',' and ')'
( ')' | (',' SPACE) ) // last pair ends with ')', all others with ', '
}:result
EOF"""
| fieldsFlatten result
| fieldsRemove result
Related tags
Dynatrace Platform