# Best way to split json input to multiple events for elasticsearch

**URL:** https://discuss.elastic.co/t/best-way-to-split-json-input-to-multiple-events-for-elasticsearch/60537
**Category:** Logstash
**Created:** [September 14, 2016, 6:34pm UTC](https://discuss.elastic.co/t/best-way-to-split-json-input-to-multiple-events-for-elasticsearch/60537 "2016-09-14T18:34:02Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Skippy](https://avatars.discourse-cdn.com/v4/letter/s/bcef8e/32.png) [@Skippy](https://discuss.elastic.co/u/Skippy)
#### Post date: [September 14, 2016, 6:34pm UTC](https://discuss.elastic.co/t/best-way-to-split-json-input-to-multiple-events-for-elasticsearch/60537/1 "2016-09-14T18:34:02Z")

</div>

First of all, my apologies. I am new to ELK and I can find most of my way around with googling what I need. I absolutely love ELK so far, but I could not find any answers to a very simple question (Which leads me to believe I might not have the right question.

I have json input that looks something like this:  
{  
"value": {  
"USQueue": {  
"QueueSize": 0,  
"Name": "USQueue"  
},  
"IndiaQueue": {  
"QueueSize": 0,  
"Name": "IndiaQueue"  
}  
}  
}

Right now, I see my fields in elasticsearch get created as a single event with the following:  
value.USQueue.QueueSize = 0  
[value.USQueue.Name](http://value.USQueue.Name) = USQueue  
value.IndiaQueue.QueueSize=0  
value.IndiaQueue.Name=IndiaQueue

What I want to do is split this into two events.  
{  
"QueueSize": 0,  
"Name": "USQueue"  
}  
and  
{  
"QueueSize": 0,  
"Name": "IndiaQueue"  
}

Where I can use Kibana to easily create a bar chart of all queuesizes and split the bars with Name field.

How would I go about this? I played with split, but that did not work as it is a hash, not an array.

I am very sorry for my terminology, as I am still new, but hopefully the gist is understood. Thank you very much for your time!

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 15, 2016, 6:11pm UTC](https://discuss.elastic.co/t/best-way-to-split-json-input-to-multiple-events-for-elasticsearch/60537/2 "2016-09-15T18:11:44Z")

</div>

I think you have to use a ruby filter that converts the hash into an array. Something like

```nohighlight
ruby {
  code => "
    event['arrayvalue'] = []
    event['value'].each_pair { |k, v|
      event['arrayvalue'] << { 'Name' => k, 'QueueSize' => v['QueueSize'] }
    }
  "
}

```

might work. Then you can use the split filter on the resulting event.

---

<div class="post-metadata">

### Author: ![Skippy](https://avatars.discourse-cdn.com/v4/letter/s/bcef8e/32.png) [@Skippy](https://discuss.elastic.co/u/Skippy)
#### Post date: [September 16, 2016, 7:33pm UTC](https://discuss.elastic.co/t/best-way-to-split-json-input-to-multiple-events-for-elasticsearch/60537/3 "2016-09-16T19:33:40Z")

</div>

Thank you so much Magnus. I did a variation of what you had to my environment (My example was not really accurate) and it worked like a charm! Thank you!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:38am UTC](https://discuss.elastic.co/t/best-way-to-split-json-input-to-multiple-events-for-elasticsearch/60537/4 "2017-07-06T04:38:08Z")

</div>


