# Explode a document into multiple documents by delimited text field

**URL:** <https://discuss.elastic.co/t/explode-a-document-into-multiple-documents-by-delimited-text-field/376141>\
**Category:** Elasticsearch\
**Tags:** runtime-fields\
**Created:** [March 19, 2025, 8:38pm UTC](https://discuss.elastic.co/t/explode-a-document-into-multiple-documents-by-delimited-text-field/376141 "2025-03-19T20:38:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wpm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wpm/32/110146_2.png) [@wpm](https://discuss.elastic.co/u/wpm)\
**Post date:** [March 19, 2025, 8:38pm UTC](https://discuss.elastic.co/t/explode-a-document-into-multiple-documents-by-delimited-text-field/376141/1 "2025-03-19T20:38:25Z")

</div>

I have the following index.

```auto
colors,value
"blue,red", 10
"red", 20
"green", 5
"blue,red", 15
"blue,green", 5

```

I want to aggregate `value` by `color` like so.

```auto
blue = 10, 15, 5
red = 10, 20, 15
green = 5, 5

```

The problem is that individual colors appear as comma-delimited elements of a single text field.

If I was working in pandas, I would do an [explode](https://pandas.pydata.org/docs/reference/api/pandas.DataFrame.explode.html) operation which would give me

```auto
blue, 10
red, 10
red, 20
green, 5
blue, 15
red, 15
blue, 5
green, 5

```

and I would do my aggregation on that.

I don't see an equivalent operation in Elasticsearch.

I don't want to modify the original index. Any explode and aggregate operations should occur at runtime.

What is the best way to do this?

---

<div class="post-metadata">

**Author:** ![wpm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wpm/32/110146_2.png) [@wpm](https://discuss.elastic.co/u/wpm)\
**Post date:** [March 20, 2025, 4:20pm UTC](https://discuss.elastic.co/t/explode-a-document-into-multiple-documents-by-delimited-text-field/376141/2 "2025-03-20T16:20:00Z")

</div>

I guess the splitting on delimiter part is easy enough, just use a [split processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/split-processor.html).

But the main question still applies: can I explode on an array field?

---

<div class="post-metadata">

**Author:** ![wpm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wpm/32/110146_2.png) [@wpm](https://discuss.elastic.co/u/wpm)\
**Post date:** [March 21, 2025, 10:46pm UTC](https://discuss.elastic.co/t/explode-a-document-into-multiple-documents-by-delimited-text-field/376141/3 "2025-03-21T22:46:00Z")

</div>

Is [this](https://discuss.elastic.co/t/split-document-into-multiple-documents/303305) the answer?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 21, 2025, 11:56pm UTC](https://discuss.elastic.co/t/explode-a-document-into-multiple-documents-by-delimited-text-field/376141/4 "2025-03-21T23:56:10Z")

</div>

No, this applies to Logstash.

Elasticsearch uses Ingest Pipelines, there is no equivalent to the Logstash `split` filter.

You cannot split an array into multiple documents using Ingest Pipelines, if you want to do that you need to parse your data in Logstash and then send it to Elasticsearch.
