# Array field doesn't get split

**URL:** https://discuss.elastic.co/t/array-field-doesnt-get-split/381332
**Category:** Logstash
**Created:** [August 26, 2025, 4:43am UTC](https://discuss.elastic.co/t/array-field-doesnt-get-split/381332 "2025-08-26T04:43:09Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)
#### Post date: [August 26, 2025, 4:43am UTC](https://discuss.elastic.co/t/array-field-doesnt-get-split/381332/1 "2025-08-26T04:43:09Z")

</div>

hi there,

i’m facing a strange issue right now. In my Logstash pipeline, I applied a Grok filter to the raw message and generated a field named responseBody from it.

the second filter, I use a JSON filter to parse responseBody. from this parse, there is an array field named “data”. The value format of this field was like `data:[{…},{…}]`

The third filter uses the split filter with an if condition to check if the field is actually an array. from this filter, there is a field generated named `data.endpoint`

```auto
if [data] and [data][0] {
  split {
    field => "data"
  }
}

```

the problem is, the value of `data.endpoint` always the same on each document in prod. because in `data` array, each element has its own endpoint. That’s why this has become a problem

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/a/ea1d67b6484c8393d8a3d8ec959b4d9de7b2079e.png)

while I tested on my environment, using the same filter and the same order, it gave me the correct output. all values of `data.endpoint` field was different

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1acb879205034d168937f879424dd2a14cd052b4.png)

This is the filter I used on DEV. The order of the filter was the same as prod. The only difference is in the grok pattern

```auto
grok {
 match => ["message", "%{GREEDYDATA:responseBody}"]
}

json {
  source => "responseBody"
  skip_on_invalid_json => true
 }

if [data] and [data][0] {
  split {
    field => "data"
  }
 }

if [data] =~ "\A\{.+\}\z" {
json {
  source => "data"
  target => "data"
  skip_on_invalid_json => true
 }
}

```

What did I do wrong?

thanks

---

<div class="post-metadata">

### Author: ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)
#### Post date: [August 26, 2025, 4:46am UTC](https://discuss.elastic.co/t/array-field-doesnt-get-split/381332/2 "2025-08-26T04:46:33Z")

</div>

> [@yuswanul](#):
>
> ```auto
> if [data] =~ "\A\{.+\}\z" {
> json {
> source => "data"
> target => "data"
> skip_on_invalid_json => true
> }
> }
> 
> ```

if you think this is the problem. No, it’s not. i tried to change the target to `dawa` to see if it’s applied to the log or not. and the result is the field name remains the same (`data.endpoint`)

it means that the last JSON filter with that if condition will not touch or modify the log

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 26, 2025, 12:22pm UTC](https://discuss.elastic.co/t/array-field-doesnt-get-split/381332/3 "2025-08-26T12:22:33Z")

</div>

You would need to provide more context, what is the pipeline that it is working and what is the pipeline that is not working? You mention that the only difference is the grok pattern, but what is the difference?

Also, the grok filter you shared is unnecessary, you are just matching everything from a field and storing in another field, a simple rename or copy would work.

Can you share a sample of your message a well so this can be replicated?

---

<div class="post-metadata">

### Author: ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)
#### Post date: [September 2, 2025, 7:19am UTC](https://discuss.elastic.co/t/array-field-doesnt-get-split/381332/4 "2025-09-02T07:19:08Z")

</div>

> [@leandrojmp](#):
>
> Also, the grok filter you shared is unnecessary, you are just matching everything from a field and storing in another field, a simple rename or copy would work.

yes, because it’s in DEV, so I was trying to get straight to the point. but fortunately, I found the core issue. The issue is with document\_id in the output section. since the pipeline has a split filter in it, it only splits the array element into separate documents. The problem is, I configured the pipeline to use a custom\_id made by the filebeat processor, and after the split filter, that custom\_id remains the same. That’s why in production, I got the same `[data][endpoint]` for all documents. It’s because they just got replaced by other documents from the split filter.

then I chose to use a fingerprint filter to modify custom\_id value
