# Flatten the json array into field in filter of logstash

**URL:** <https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750>\
**Category:** Logstash\
**Created:** [June 13, 2018, 2:35pm UTC](https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750 "2018-06-13T14:35:18Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2018, 4:43pm UTC](https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750/2 "2018-06-13T16:43:54Z")

</div>

Well mutate+split creates an array from a string, and a split filter creates multiple events from an array in the current event. Neither of which matches what you want to do.

I think you have to do it in ruby. Do not use . in a field name, it will come back to bite you later. This should get you started:

```
ruby {
    code => '
        a = event.get("steps")
        a.each_index { |i|
             event.set("steps-#{i}-total", a[i]["values"]["total"])
        }
    '
}

```

Seems like an odd thing to want to do though!

---

_[View the full topic](https://discuss.elastic.co/t/flatten-the-json-array-into-field-in-filter-of-logstash/135750)._
