# Adding an array of events even if there is only one

**URL:** <https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567>\
**Category:** Elasticsearch\
**Created:** [January 22, 2024, 5:27pm UTC](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567 "2024-01-22T17:27:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ylevaill](https://avatars.discourse-cdn.com/v4/letter/y/8e7dd6/32.png) [@ylevaill](https://discuss.elastic.co/u/ylevaill)\
**Post date:** [January 22, 2024, 5:27pm UTC](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567/1 "2024-01-22T17:27:11Z")

</div>

Hello,

I use this filter :

```auto
json {
      source => "message"
      add_field => { "[events][id]" => "%{_id}" }
      add_field => { "[events][nom]" => "%{eventName}" }
      add_field => { "[events][timestamp]" => "%{timestamp}" }
      add_field => { "[events][typeEv]" => "RESSOURCE" }
   }

```

And I get :  
"events" =\> {  
"nom" =\> " ACCESS-OUTCOME ",  
"typeEv" =\> "RESSOURCE",  
"timestamp" =\> "2024-01-22T10:02:04.713Z ",  
"id" =\> " e3ee9f3a-e2444"  
},  
But what i want is that :  
"events" =\> [ {  
"nom" =\> "ACCESS-OUTCOME ",  
"typeEv" =\> "RESSOURCE",  
"timestamp" =\> "2024-01-22T10:02:04.713Z ",  
"id" =\> " e3ee9f3a-e244"  
} ],  
Have you an idea how to get this ?

---

<div class="post-metadata">

**Author:** ![strawgate](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/strawgate/32/131008_2.png) [@strawgate](https://discuss.elastic.co/u/strawgate)\
**Post date:** [January 23, 2024, 12:07am UTC](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567/2 "2024-01-23T00:07:38Z")

</div>

This was asked in the elasticsearch section but that config looks like a logstash config.

There was a similar question asked a couple of years ago and I believe the recommendation was to drop down to a Ruby filter to achieve this behavior

> [@Add an array using Mutate's add\_field](https://discuss.elastic.co/t/add-an-array-using-mutates-add-field/200946):
>
> Hi Guys, I have a logstash pipeline where I am receiving a JSON file as HTTP input and forwarding it to output plugin. I want to introduce below structure to input JSON : "parentField": { "field0": "value0", "arrayName": [{ "field1": "value1", "field2": "value2" }] } To achieve that I am trying to use below filter :: filter { mutate { add\_field =\> { "[parentField][field0]" =\> "value0" } add\_field =\> { "[parentField][arrayName][0][field1]" =\> "value1" } add\_field =\> { "[parentF…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2024, 12:07am UTC](https://discuss.elastic.co/t/adding-an-array-of-events-even-if-there-is-only-one/351567/3 "2024-02-20T00:07:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
