# Help to handle the nested JSON array

**URL:** <https://discuss.elastic.co/t/help-to-handle-the-nested-json-array/195469>\
**Category:** Logstash\
**Created:** [August 16, 2019, 10:05am UTC](https://discuss.elastic.co/t/help-to-handle-the-nested-json-array/195469 "2019-08-16T10:05:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robin\_Guo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_guo/32/42297_2.png) [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Post date:** [August 16, 2019, 10:05am UTC](https://discuss.elastic.co/t/help-to-handle-the-nested-json-array/195469/1 "2019-08-16T10:05:29Z")

</div>

Dear Elastic folks,

We have a complex JSON data with multiple nested JSON arrays need to send to elastic search, Basically, we want to split the JSON array.  
In short, we want to split a single big event with multiple arrays/lists to the separate events equal to numbers of arrays /lists, and also need to then split those each separate event.

Could you please provide a Logastsh pipeline to fulfill my request?

**Raw JSON file**

```auto
{
  "Components": {
    "msgprocessors": [
      {
        "processor": "eshop-retryOrder-fail-processor",
        "active": true
      },
      {
        "processor": "eshop-order-processor",
        "active": true
      },
      {
        "processor": "ch-retry-outbound-sampling",
        "active": true
      },
      {
        "processor": "pt-retry-outbound-sampling",
        "active": true
      },
      {
        "processor": "be-biometrics-inbox-processor",
        "active": true
      },
      {
        "processor": "pt-biometrics-inbox-processor",
        "active": true
      },
      {
        "processor": "ch-biometrics-inbox-processor",
        "active": true
      },
      {
        "processor": "uk-biometrics-inbox-processor",
        "active": true
      },
      {
        "processor": "eshop-retryAppointment-fail-processor",
        "active": true
      },
      {
        "processor": "be-retry-outbound-sampling",
        "active": true
      },
      {
        "processor": "uk-retry-outbound-sampling",
        "active": true
      },
      {
        "processor": "eshop-appointment-processor",
        "active": true
      },
      {
        "processor": "uk-priority-retry-outbound-sampling",
        "active": true
      }
    ],
    "endpoints": [
      {
        "endpoint": "activeprocessor-admin-serviceEP",
        "active": true
      },
      {
        "endpoint": "api-admin-serviceEP",
        "active": true
      },
      {
        "endpoint": "be-filedecrypt-service-endpoint",
        "active": true
      },
      {
        "endpoint": "ch-filedecrypt-service-endpoint",
        "active": true
      },
      {
        "endpoint": "drools_antifraud",
        "active": true
      },
      {
        "endpoint": "drools_appointment_lateness",
        "active": true
      },
      {
        "endpoint": "drools_bioqueue",
        "active": true
      },
      {
        "endpoint": "drools_dynamic_endpoint",
        "active": true
      },
      {
        "endpoint": "endpoint-admin-serviceEP",
        "active": true
      },
      {
        "endpoint": "eshop-out-appointment-endpoint",
        "active": true
      },
      {
        "endpoint": "eshop-out-order-endpoint",
        "active": true
      },
      {
        "endpoint": "eshop_token_endpoint",
        "active": true
      },
      {
        "endpoint": "lb-be-encrypt-endpoint",
        "active": true
      },
      {
        "endpoint": "msgprocessor-admin-serviceEP",
        "active": true
      },
      {
        "endpoint": "pt-filedecrypt-service-endpoint",
        "active": true
      },
      {
        "endpoint": "queue-admin-serviceEP",
        "active": true
      },
      {
        "endpoint": "servicegroup-admin-serviceEP",
        "active": true
      },
      {
        "endpoint": "tlsconnect_appointment_endpoint",
        "active": true
      },
      {
        "endpoint": "tlsconnect_order_endpoint",
        "active": true
      },
      {
        "endpoint": "tlsconnect_tma",
        "active": true
      },
      {
        "endpoint": "uk-filedecrypt-service-endpoint",
        "active": true
      },
      {
        "endpoint": "uk-hone1adapter-outbound-endpoint",
        "active": true
      }
    ],
    "services": [
      {
        "service": "pt-filedecrypt-service",
        "active": true
      },
      {
        "service": "uk-file-processor-service",
        "active": true
      },
      {
        "service": "uk-filedecrypt-service",
        "active": true
      },
      {
        "service": "uk-hone1adapter-outbound-service",
        "active": true
      },
      {
        "service": "Version",
        "active": true
      }
    ],
    "apis": [
      {
        "api": "appointmentLateness",
        "active": true
      },
      {
        "api": "bioqueue",
        "active": true
      },
      {
        "api": "pt-emetrics_TLS2PortugalAPI",
        "active": true
      },
      {
        "api": "order",
        "active": true
      },
      {
        "api": "be_token",
        "active": true
      },
      {
        "api": "GenericRulesEngineAPI",
        "active": true
      },
      {
        "api": "tma",
        "active": true
      },
      {
        "api": "sre",
        "active": true
      },
      {
        "api": "esbHealthCheckAPI",
        "active": true
      }
    ]
  }
}

```

First, we want to split up four separate events for this single event above I posted.

we have 4 nested arrays/lists (maybe it's dynamically )for this case, they're :

```auto
[Components][msgprocessors]
[Components][services]
[Components][apis]
[Components][endpoints]

```

​after that, we want to split each array event to have separate events.

The results we want to have:

**Array: [Components][msgprocessors]**

```auto
{"Components": {"msgprocessors":{"processor":"eshop-retryOrder-fail-processor","active": true}}
{"Components": {"msgprocessors":{"processor":"eshop-order-processor","active": true}}
...................

```

**Array: [Components][services]**

```auto
{"Components": {"services":{"service":"pt-filedecrypt-service","active": true}}
{"Components": {"services":{"service":"uk-file-processor-service","active": true}}
...................

```

**Array:[Components][apis]**

```auto
{"Components": {"apis":{"api":"appointmentLateness","active": true}}
{"Components": {"apis":{"api":"bioqueue","active": true}}
................

```

**Array:[Components][endpoints]**

```auto
{"Components": {"endpoints":{"endpoint":"tlsconnect_appointment_endpoint","active": true}}
{"Components": {"endpoints":{"endpoint":"tlsconnect_order_endpoint","active": true}}
................

```

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [August 16, 2019, 10:48am UTC](https://discuss.elastic.co/t/help-to-handle-the-nested-json-array/195469/2 "2019-08-16T10:48:38Z")

</div>

You may need to combine [split](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html) and [clone](https://www.elastic.co/guide/en/logstash/current/plugins-filters-clone.html) filter

---

<div class="post-metadata">

**Author:** ![Robin\_Guo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_guo/32/42297_2.png) [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Post date:** [August 16, 2019, 11:29am UTC](https://discuss.elastic.co/t/help-to-handle-the-nested-json-array/195469/3 "2019-08-16T11:29:34Z")

</div>

I do my best, i couldn't implement it.  
Would you please help me out?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Robin\_Guo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robin_guo/32/42297_2.png) [@Robin\_Guo](https://discuss.elastic.co/u/Robin_Guo)\
**Post date:** [August 16, 2019, 2:54pm UTC](https://discuss.elastic.co/t/help-to-handle-the-nested-json-array/195469/4 "2019-08-16T14:54:57Z")

</div>

Any updates?  
by the way we're using logstash 6.4.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2019, 2:54pm UTC](https://discuss.elastic.co/t/help-to-handle-the-nested-json-array/195469/5 "2019-09-13T14:54:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
