# Breaking json array into granular events using filebeat script processor

**URL:** <https://discuss.elastic.co/t/breaking-json-array-into-granular-events-using-filebeat-script-processor/232686>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 14, 2020, 4:30pm UTC](https://discuss.elastic.co/t/breaking-json-array-into-granular-events-using-filebeat-script-processor/232686 "2020-05-14T16:30:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![karthiknpy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karthiknpy/32/53587_2.png) [@karthiknpy](https://discuss.elastic.co/u/karthiknpy)\
**Post date:** [May 14, 2020, 4:30pm UTC](https://discuss.elastic.co/t/breaking-json-array-into-granular-events-using-filebeat-script-processor/232686/1 "2020-05-14T16:30:05Z")

</div>

Hi Team,

I got a crazy thought to split JSON array which filebeat read from redis list input.  
Then filebeat script processor splits it into granular events and writes to elastic.

I know I should be using logstash json split filter for this. But I'm keen to know if script processor can help me for this.

Can anyone please guide me to achieve this?

Regards  
Karthik.K

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [May 14, 2020, 5:21pm UTC](https://discuss.elastic.co/t/breaking-json-array-into-granular-events-using-filebeat-script-processor/232686/2 "2020-05-14T17:21:31Z")

</div>

No, processors in Beats are limited in that they cannot produce new events. It's one event in and at most, one event out.

---

<div class="post-metadata">

**Author:** ![karthiknpy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karthiknpy/32/53587_2.png) [@karthiknpy](https://discuss.elastic.co/u/karthiknpy)\
**Post date:** [May 15, 2020, 6:23am UTC](https://discuss.elastic.co/t/breaking-json-array-into-granular-events-using-filebeat-script-processor/232686/3 "2020-05-15T06:23:59Z")

</div>

Hi Andrew,

Logstash is slow and its too heavy application. I created a 8GB server for one logstash instance and it uses 90% above of the CPU. Is there any alternatives to logstash you can suggest ?

I dont deny that it contains support plugins for almost everything under the sun.

Regards  
Karthik.K

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2020, 6:23am UTC](https://discuss.elastic.co/t/breaking-json-array-into-granular-events-using-filebeat-script-processor/232686/4 "2020-06-12T06:23:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
