# How to fetch out the array values

**URL:** <https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001>\
**Category:** Logstash\
**Created:** [February 8, 2023, 10:43am UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001 "2023-02-08T10:43:06Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![prashant1](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Post date:** [February 8, 2023, 10:43am UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001/1 "2023-02-08T10:43:06Z")

</div>

Hi,  
I have below sample data

```auto
{
   "logtype":"demo" ,"operation":"demoStatus",
   "Stats":[
      { "apiName":"a", "failedCount":0, "successCount":0 },
      { "apiName":"b", "failedCount":0, "successCount":0 },  
      { "apiName":"c", "failedCount":25, "successCount":344 },
      { "apiName":"d", "failedCount":0, "successCount":0 }
   ]
}

```

I want to fetch out the values from the array. So that the output result should be like  
expected output of array

```auto
Stats.apiNamea : a
Stats.failedCounta : 0
Stats.successCounta : 0

Stats.apiNameb[Stats.apiName(apiName value)] : b 
Stats.failedCountb : 0
Stats.successCountb : 0

```

Could someone please help us ?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 8, 2023, 3:27pm UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001/2 "2023-02-08T15:27:46Z")

</div>

[Stats][0][apiNamea] for a  
[Stats][0][failedCount] for 0  
[Stats][0][successCount] 0  
[Stats][1]... for 2nd element

If you want a loop, use Ruby.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 8, 2023, 3:44pm UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001/3 "2023-02-08T15:44:37Z")

</div>

Wouldn't be better to have each item on the array as a different document? This is normally the approach when you have arrays like this.

In this case, from the sample document you shared, you would end up with 4 documents:

```auto
 { "logtype":"demo" ,"operation":"demoStatus","Stats": { "apiName":"a", "failedCount":0, "successCount":0 } }
 { "logtype":"demo" ,"operation":"demoStatus","Stats": { "apiName":"b", "failedCount":0, "successCount":0 } }
 { "logtype":"demo" ,"operation":"demoStatus","Stats": { "apiName":"c", "failedCount":25, "successCount":344 } }
 { "logtype":"demo" ,"operation":"demoStatus","Stats": { "apiName":"d", "failedCount":0, "successCount":0 } }

```

You can do that using the [split](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html) filter.

---

<div class="post-metadata">

**Author:** ![prashant1](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Post date:** [February 8, 2023, 5:14pm UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001/4 "2023-02-08T17:14:43Z")

</div>

Thanks @leandrojmp for the reply

But if the number of elements in array are more in that case there are so many different documents. So having different logs is not suitable for the usecase. In this case the hits should be more for the single logs that might affect the result on the kibana.

Instead if the same log can be processed and we are able to store all those key values in the same log.

As key name is same I am thinking to use to iterate through the loop and append it with name of key with the value.

If it can be possible that will be good for my usecase.  
Or if there is any another approch which I can try please suggest.

---

<div class="post-metadata">

**Author:** ![prashant1](https://avatars.discourse-cdn.com/v4/letter/p/bc8723/32.png) [@prashant1](https://discuss.elastic.co/u/prashant1)\
**Post date:** [February 8, 2023, 5:15pm UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001/5 "2023-02-08T17:15:51Z")

</div>

Thanks @Rios  
I will try this and update.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [February 8, 2023, 5:23pm UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001/6 "2023-02-08T17:23:48Z")

</div>

It's better to use split as Leandro suggested. It's not came to my mind.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 8, 2023, 6:01pm UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001/7 "2023-02-08T18:01:49Z")

</div>

> [@prashant1](#):
>
> As key name is same I am thinking to use to iterate through the loop and append it with name of key with the value.

This could lead to having a lot of fields in your index which may have impact in performance.

Also, how are you planning to use this data? For example, if you append the name of the key to the fields of `failedCount` and `successCount` you won't be able to plot a graphic comparing which API has more fails or success because the field name is different.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2023, 6:02pm UTC](https://discuss.elastic.co/t/how-to-fetch-out-the-array-values/325001/8 "2023-03-08T18:02:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
