# How does split filtered events processed?

**URL:** https://discuss.elastic.co/t/how-does-split-filtered-events-processed/248135
**Category:** Logstash
**Created:** [September 10, 2020, 8:52am UTC](https://discuss.elastic.co/t/how-does-split-filtered-events-processed/248135 "2020-09-10T08:52:05Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![sharma\_yash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharma_yash/32/61112_2.png) [@sharma\_yash](https://discuss.elastic.co/u/sharma_yash)
#### Post date: [September 10, 2020, 8:52am UTC](https://discuss.elastic.co/t/how-does-split-filtered-events-processed/248135/1 "2020-09-10T08:52:05Z")

</div>

Hi,

I am new to this community and come to know about splitting the events into multiple events. Got to know split filter plugin is the answer. I didn't understand the flow of pipeline when using this plugin.

For ex:-

if I have

```auto
filter {
    split{}

   mutate{}

   split{}

  mutate{}

}

```

Will the multiple events cloned from first split will start again from the start i.e. first split or will they continue processing from first mutate call and then further the process again for each filter.

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [September 10, 2020, 1:27pm UTC](https://discuss.elastic.co/t/how-does-split-filtered-events-processed/248135/2 "2020-09-10T13:27:42Z")

</div>

The events created from your `split` filter will enter your pipeline just after the split filter, so the following mutate and all the following filters will process the splitted events.

So if your first `split` filter split the original event into two new events, the following mutate filter will process those two new events, if your second `split` filter splits those two new events into another two events each, you will have four events that will be processed by the next mutate in the pipeline.

Logstash is sequential, all the changes from a filter will be available for the next filters in the line.

---

<div class="post-metadata">

### Author: ![sharma\_yash](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sharma_yash/32/61112_2.png) [@sharma\_yash](https://discuss.elastic.co/u/sharma_yash)
#### Post date: [September 10, 2020, 9:30pm UTC](https://discuss.elastic.co/t/how-does-split-filtered-events-processed/248135/3 "2020-09-10T21:30:02Z")

</div>

Thank you so much for the response.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 8, 2020, 9:30pm UTC](https://discuss.elastic.co/t/how-does-split-filtered-events-processed/248135/4 "2020-10-08T21:30:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
