# Flatten the json array into field in filter of logstash

**URL:** <https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750>\
**Category:** Logstash\
**Created:** [June 13, 2018, 2:35pm UTC](https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750 "2018-06-13T14:35:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![5b0eafdfbfb313f6ed17](https://avatars.discourse-cdn.com/v4/letter/5/a587f6/32.png) [@5b0eafdfbfb313f6ed17](https://discuss.elastic.co/u/5b0eafdfbfb313f6ed17)\
**Post date:** [June 13, 2018, 2:35pm UTC](https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750/1 "2018-06-13T14:35:19Z")

</div>

Now I have the filed below in Kibana.

```
{ "steps": [
      {
        "stepName": " ****",
        "values": {
          "type": "**",
          "startTime": "**",
          "total": 0
        }
      },
      {
        "stepName": "**",
        "values": {
          "type": "***",
          "startTime": "**",
          "total": 1
        }
      },
      {
        "stepName": "**",
        "values": {
          "type": "**",
          "startTime": "**",
          "total": 0
        }
      }
    ]}

```

And i want to change the jsonarray format in kibana. I would like to split the array and show the array index in the field.

```
steps.0.stepName:"**"
steps.0.values.type:"**"
steps.0.values.startTime:"**"
step.0.values.total:"***"

step.1.stepName:"**"
steps.1.values.type:"**"
steps.1.values.startTime:"**"
step.1.values.total:"***"

```

I have trying to using split filter but no luck. Also I trying to use scripted field in Kibana, but it does not work. And now I have no idea how to achieve this. Can anyone help me about this?Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2018, 4:43pm UTC](https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750/2 "2018-06-13T16:43:54Z")

</div>

Well mutate+split creates an array from a string, and a split filter creates multiple events from an array in the current event. Neither of which matches what you want to do.

I think you have to do it in ruby. Do not use . in a field name, it will come back to bite you later. This should get you started:

```
ruby {
    code => '
        a = event.get("steps")
        a.each_index { |i|
             event.set("steps-#{i}-total", a[i]["values"]["total"])
        }
    '
}

```

Seems like an odd thing to want to do though!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2018, 4:43pm UTC](https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750/3 "2018-07-11T16:43:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
