# How to individualize the data that has an array objects

**URL:** <https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836>\
**Category:** Logstash\
**Created:** [May 12, 2021, 5:16pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836 "2021-05-12T17:16:00Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [May 12, 2021, 5:16pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/1 "2021-05-12T17:16:00Z")

</div>

I need to be able to extract the data that it brings me in logstash, to be able to graph I have to extract the metrics, but when it sends them to me to kibana I cannot graph because they are in an array, I need help as I cannot break that array and that it sends me the individual metrics each one.

I need to be able to get the data out of that array and I need to separate them all, whether they are individual metrics, please.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b9e9625f6f81f40b05dd42d5ebd27ae7f337b670.png)

```auto
{
  "_index": "radwareefecty",
  "_type": "_doc",
  "_id": "ird8YXkBQzzVpIqvFtvR",
  "_version": 1,
  "_score": null,
  "_source": {
    "@version": "1",
    "SlbStatLinkpfRServerTable": [
      {
        "TotBwPeak": 0,
        "IpAddr": "190.145.144.65",
        "State": 2,
        "DnBwTot": 0,
        "CurrSess": 0,
        "DnBwPeak": 0,
        "TotBwPeakTmSt": "N/A",
        "TotCurrUsage": "--",
        "UpBwPeak": 0,
        "DwBwUSage": "--",
        "DnBwPeakTmSt": "N/A",
        "DnBwPeakPer": "--",
        "UpBwTot": 0,
        "UpDnBwTot": 0,
        "UpBwPeakPer": "--",
        "LastTranfetTmSt": "N/A",
        "DwBwCurr": 0,
        "Index": "Claro-Internet4",
        "UpBwCurr": 0,
        "UpBwUsage": "--",
        "TotCurrbw": 0,
        "UpBwPeakTmSt": "N/A",
        "TotBwPeakPer": "--"
      },
      {
        "TotBwPeak": 0,
        "IpAddr": "190.242.127.16",
        "State": 2,
        "DnBwTot": 0,
        "CurrSess": 0,
        "DnBwPeak": 0,
        "TotBwPeakTmSt": "N/A",
        "TotCurrUsage": "--",
        "UpBwPeak": 0,
        "DwBwUSage": "--",
        "DnBwPeakTmSt": "N/A",
        "DnBwPeakPer": "--",
        "UpBwTot": 0,
        "UpDnBwTot": 0,
        "UpBwPeakPer": "--",
        "LastTranfetTmSt": "N/A",
        "DwBwCurr": 0,
        "Index": "Columbus-Internet5",
        "UpBwCurr": 0,
        "UpBwUsage": "--",
        "TotCurrbw": 0,
        "UpBwPeakTmSt": "N/A",
        "TotBwPeakPer": "--"
      },
      {
        "TotBwPeak": 1.5,
        "IpAddr": "190.143.70.35",
        "State": 2,
        "DnBwTot": 3,
        "CurrSess": 0,
        "DnBwPeak": 0.1,
        "TotBwPeakTmSt": "02:28:52 Sat May 1, 2021",
        "TotCurrUsage": "--",
        "UpBwPeak": 1.4,
        "DwBwUSage": "--",
        "DnBwPeakTmSt": "01:53:29 Sat May 1, 2021",
        "DnBwPeakPer": "--",
        "UpBwTot": 1617.9,
        "UpDnBwTot": 1620.9,
        "UpBwPeakPer": "--",
        "LastTranfetTmSt": "N/A",
        "DwBwCurr": 0,
        "Index": "Internet_Navegacion-Claro_1",
        "UpBwCurr": 0,
        "UpBwUsage": "--",
        "TotCurrbw": 0,
        "UpBwPeakTmSt": "02:28:52 Sat May 1, 2021",
        "TotBwPeakPer": "--"
      },
      {
        "TotBwPeak": 5.8,
        "IpAddr": "190.144.221.225",
        "State": 2,
        "DnBwTot": 5.3,
        "CurrSess": 0,
        "DnBwPeak": 0.3,
        "TotBwPeakTmSt": "01:52:18 Sat May 1, 2021",
        "TotCurrUsage": "--",
        "UpBwPeak": 5.4,
        "DwBwUSage": "--",
        "DnBwPeakTmSt": "01:52:18 Sat May 1, 2021",
        "DnBwPeakPer": "--",
        "UpBwTot": 125.7,
        "UpDnBwTot": 130.9,
        "UpBwPeakPer": "--",
        "LastTranfetTmSt": "N/A",
        "DwBwCurr": 0,
        "Index": "Internet_Navegacion-Claro_2",
        "UpBwCurr": 0,
        "UpBwUsage": "--",
        "TotCurrbw": 0,
        "UpBwPeakTmSt": "01:52:18 Sat May 1, 2021",
        "TotBwPeakPer": "--"
      },
      {
        "TotBwPeak": 0.1,
        "IpAddr": "200.122.229.81",
        "State": 2,
        "DnBwTot": 0,
        "CurrSess": 0,
        "DnBwPeak": 0,
        "TotBwPeakTmSt": "19:53:13 Wed Apr 14, 2021",
        "TotCurrUsage": "--",
        "UpBwPeak": 0,
        "DwBwUSage": "--",
        "DnBwPeakTmSt": "19:53:13 Wed Apr 14, 2021",
        "DnBwPeakPer": "--",
        "UpBwTot": 0.9,
        "UpDnBwTot": 1,
        "UpBwPeakPer": "--",
        "LastTranfetTmSt": "N/A",
        "DwBwCurr": 0,
        "Index": "Internet_Navegacion-UNE_1",
        "UpBwCurr": 0,
        "UpBwUsage": "--",
        "TotCurrbw": 0,
        "UpBwPeakTmSt": "19:53:13 Wed Apr 14, 2021",
        "TotBwPeakPer": "--"
      },
      {
        "TotBwPeak": 55,
        "IpAddr": "10.10.105.16",
        "State": 1,
        "DnBwTot": 0,
        "CurrSess": 0,
        "DnBwPeak": 0,
        "TotBwPeakTmSt": "01:53:34 Sat May 1, 2021",
        "TotCurrUsage": "--",
        "UpBwPeak": 55,
        "DwBwUSage": "--",
        "DnBwPeakTmSt": "N/A",
        "DnBwPeakPer": "--",
        "UpBwTot": 55.6,
        "UpDnBwTot": 55.6,
        "UpBwPeakPer": "--",
        "LastTranfetTmSt": "N/A",
        "DwBwCurr": 0,
        "Index": "L2L_Claro",
        "UpBwCurr": 0,
        "UpBwUsage": "--",
        "TotCurrbw": 0,
        "UpBwPeakTmSt": "01:53:34 Sat May 1, 2021",
        "TotBwPeakPer": "--"
      },
      {
        "TotBwPeak": 0.8,
        "IpAddr": "10.10.100.16",
        "State": 1,
        "DnBwTot": 0,
        "CurrSess": 0,
        "DnBwPeak": 0,
        "TotBwPeakTmSt": "01:52:38 Sat May 1, 2021",
        "TotCurrUsage": "--",
        "UpBwPeak": 0.8,
        "DwBwUSage": "--",
        "DnBwPeakTmSt": "N/A",
        "DnBwPeakPer": "--",
        "UpBwTot": 3.8,
        "UpDnBwTot": 3.8,
        "UpBwPeakPer": "--",
        "LastTranfetTmSt": "N/A",
        "DwBwCurr": 0,
        "Index": "L2L_CyW",
        "UpBwCurr": 0,
        "UpBwUsage": "--",
        "TotCurrbw": 0,
        "UpBwPeakTmSt": "01:52:38 Sat May 1, 2021",
        "TotBwPeakPer": "--"
      }
    ],
    "@timestamp": "2021-05-12T16:48:00.064Z"
  },
  "fields": {
    "@timestamp": [
      "2021-05-12T16:48:00.064Z"
    ]
  },
  "sort": [
    1620838080064
  ]
}

```

**this is the configuration in logstash:**

```auto
input {
  http_poller {
    urls => {
      kvh => "https://Default_Generated_Alteon_BBI_Cert:443/config/SlbStatLinkpfRServerTable"
     }
# cacert => "/path/downloaded_cert.pem"
    truststore => "/path/downloaded_truststore.jks"
    user => "user"
    password => "secret"
    truststore_password => "secret"
    schedule => { cron => "* * * * * UTC"}
    codec => "json"
# ssl => true
 # ssl_certificate_verification => true
  }
}

filter {

 ruby {
        code => '
            def is_number? string
                true if Float(string) rescue false
            end

            t = event.get("SlbStatLinkpfRServerTable")
            if t
                newT = []
                t.each { |x|
                    newX = {}
                    x.each { |k, v|
                        if is_number? v
                            v = v.to_f
                        end
                        newX[k] = v
                    }
                    newT << newX
                }
                t = event.set("SlbStatLinkpfRServerTable", newT)
            end
        '
    }
}

output {
   stdout { codec => rubydebug }
 elasticsearch {
    hosts => ["https://425dc991b9ec443hgggddkkkqf3ef706bd675a.us-central1.gcp.cloud.es.io:9243"]
    user => "elastic"
    password => "secret"
    index => "radwareefecty"
   }

}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 12, 2021, 5:20pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/2 "2021-05-12T17:20:32Z")

</div>

If you want a separate event for each array entry you could use

```
split { field => "SlbStatLinkpfRServerTable" }
```

---

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [May 12, 2021, 5:28pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/3 "2021-05-12T17:28:07Z")

</div>

I need to extract the data contained in the array, i.e. extract each field that the array contains. take this data and extract it from the array:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/79e84a59bb723c6109ca8841b3eb9f6f42ad880b.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 12, 2021, 5:40pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/4 "2021-05-12T17:40:09Z")

</div>

> [@Juan\_David\_Jaramillo](#):
>
> I need to extract the data contained in the array, i.e. extract each field that the array contains. take this data and extract it from the array:

What do you want the \_source field to look like?

---

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [May 12, 2021, 5:42pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/5 "2021-05-12T17:42:47Z")

</div>

I want them to be outside the array, I mean individual metrics of the array.

---

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [May 12, 2021, 5:43pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/6 "2021-05-12T17:43:16Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/6/9/69c58a6086f816ade4f70122cb487ea6262c53ce.png)

---

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [May 12, 2021, 5:54pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/7 "2021-05-12T17:54:29Z")

</div>

I mean, take each metric from the array and put it in individual

---

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [May 12, 2021, 6:05pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/8 "2021-05-12T18:05:57Z")

</div>

this appears, when using the 'split:

```auto
{

                     "@version" => "1",
                   "@timestamp" => 2021-05-12T18:00:00.599Z,
    "SlbStatLinkpfRServerTable" => [
        [0] {
            "UpBwPeak" => nil,
                 "0.0" => nil
        },
        [1] {
            "Claro-Internet4" => nil,
                      "Index" => nil
        },
        [2] {
            "TotCurrUsage" => nil,
                      "--" => nil
        },
        [3] {
            "DwBwCurr" => nil,
                 "0.0" => nil
        },
        [4] {
                  "0.0" => nil,
            "TotCurrbw" => nil
        },
        [5] {
            "DwBwUSage" => nil,
                   "--" => nil
        },
        [6] {
            "State" => nil,
                "2" => nil
        },
        [7] {
                        "N/A" => nil,
            "LastTranfetTmSt" => nil
        },
        [8] {
            "DnBwPeakPer" => nil,
                     "--" => nil
        },
        [9] {
            "DnBwTot" => nil,
                "0.0" => nil
        },
        [10] {
            "DnBwPeakTmSt" => nil,
                     "N/A" => nil
        },
        [11] {
                     "N/A" => nil,
            "UpBwPeakTmSt" => nil
        },
        [12] {
            "TotBwPeakPer" => nil,
                      "--" => nil
        },
        [13] {
                  "0.0" => nil,
            "TotBwPeak" => nil

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 12, 2021, 7:13pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/9 "2021-05-12T19:13:37Z")

</div>

I cannot conceive how a split filter would do that.

---

<div class="post-metadata">

**Author:** ![face0b1101](https://avatars.discourse-cdn.com/v4/letter/f/eb8c5e/32.png) [@face0b1101](https://discuss.elastic.co/u/face0b1101)\
**Post date:** [May 14, 2021, 6:29am UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/10 "2021-05-14T06:29:56Z")

</div>

Where's the data coming from? Are you able to adjust the source to output friendlier json?

Otherwise, if the array is the same everytime you could just copy out the values to new fields?

---

<div class="post-metadata">

**Author:** ![Juan\_David\_Jaramillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juan_david_jaramillo/32/76831_2.png) [@Juan\_David\_Jaramillo](https://discuss.elastic.co/u/Juan_David_Jaramillo)\
**Post date:** [May 14, 2021, 7:30pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/11 "2021-05-14T19:30:07Z")

</div>

come through the api that this calling, the data are in a web in radware that are compiled in arrays, when calling them through the api to send them from logstash to elastic, I suppose that from the configuration of the file in logstash must see some script that goes through the array and I can take the data and separate them so that they do not remain as tables.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2021, 7:30pm UTC](https://discuss.elastic.co/t/how-to-individualize-the-data-that-has-an-array-objects/272836/12 "2021-06-11T19:30:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
