# Create documents from array field

**URL:** https://discuss.elastic.co/t/create-documents-from-array-field/216320
**Category:** Logstash
**Created:** [January 23, 2020, 9:08pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320 "2020-01-23T21:08:15Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![nino](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@nino](https://discuss.elastic.co/u/nino)
#### Post date: [January 23, 2020, 9:08pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320/1 "2020-01-23T21:08:15Z")

</div>

Hello all,

this is the output of my pipeline that process a file. I've succesfully extract the lines i want from the file, each file per day and n number of lines each day and split the lines into and array.

```
{
  "host" => "",
        "field1" => [
        [0] " 1/17/0 AA 3 MAR 20 SAB R-XXX 3801.00 EU",
        [1] " 1/17/0 BB 2 JAN 20 TER GCX 12.6000 US",
    ],
    "@timestamp" => 2020-01-23T20:36:42.037Z
}

```

What i need is create a document of each array element like this

```
{
  "field1" => "AA",
  "field2" => "3",
  "field3" => "MAR 20",
  "field4" => "SAB R-XXX",
  "field5" => "3000.00 EU",
  "@timestamp" => "2020-01-23T20:36:42.037Z"
}
{
  "field1" => "BB",
  "field2" => "2",
  "field3" => "JAN 20",
  "field4" => "TER GCX",
  "field5" => "12.6000 US",
  "@timestamp" => "2020-01-23T20:36:42.037Z"
}

```

Is it posible to achieve this?

Best regards

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 23, 2020, 9:16pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320/2 "2020-01-23T21:16:03Z")

</div>

You can use a split filter to split an array into multiple events, then use dissect. Something like

```
dissect { mapping => { "field1" => "%{} %{field1} %{field2} %{+field2} %{field3} %{+field3} %{field4} %{+field4} %{field5}" } }

```

Note that field1 is both an input and an output. I am unsure what the dissect filter will do there. You may end up with field1 as an array (again).

---

<div class="post-metadata">

### Author: ![nino](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@nino](https://discuss.elastic.co/u/nino)
#### Post date: [January 23, 2020, 9:37pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320/3 "2020-01-23T21:37:50Z")

</div>

Thank you Badger,

how is the split syntax?

```
split{
     split_in_documents => "field1"
}

```

Not working

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 23, 2020, 10:34pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320/4 "2020-01-23T22:34:58Z")

</div>

> [@nino](#):
>
> how is the split syntax?

See the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html).

```
split { field => "field1" }

```

Note that I misread your original post and thought the field was named "field", not "field1", so I have updated my previous post.

---

<div class="post-metadata">

### Author: ![nino](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@nino](https://discuss.elastic.co/u/nino)
#### Post date: [January 24, 2020, 3:48pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320/5 "2020-01-24T15:48:59Z")

</div>

> [@Badger](#):
>
> %{} %{field1} %{field2} %{+field2} %{field3} %{+field3} %{field4} %{+field4} %{field5}

Thank you so much Badger

---

<div class="post-metadata">

### Author: ![nino](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@nino](https://discuss.elastic.co/u/nino)
#### Post date: [January 24, 2020, 3:58pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320/6 "2020-01-24T15:58:55Z")

</div>

Badger,

split filter is working perfectly to split an array field in separate documents, i wonder why this is apearing in tags although is working.

```
"tags" => [
        [0] "_split_type_failure"
```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 24, 2020, 5:11pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320/7 "2020-01-24T17:11:15Z")

</div>

There should be a related error message in the logstash log.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 21, 2020, 5:11pm UTC](https://discuss.elastic.co/t/create-documents-from-array-field/216320/8 "2020-02-21T17:11:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
