# How to parse an array of multi-line json objects as separate documents in ES?

**URL:** <https://discuss.elastic.co/t/how-to-parse-an-array-of-multi-line-json-objects-as-separate-documents-in-es/255230>\
**Category:** Logstash\
**Created:** [November 12, 2020, 2:49pm UTC](https://discuss.elastic.co/t/how-to-parse-an-array-of-multi-line-json-objects-as-separate-documents-in-es/255230 "2020-11-12T14:49:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![reillye](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@reillye](https://discuss.elastic.co/u/reillye)\
**Post date:** [November 12, 2020, 2:49pm UTC](https://discuss.elastic.co/t/how-to-parse-an-array-of-multi-line-json-objects-as-separate-documents-in-es/255230/1 "2020-11-12T14:49:04Z")

</div>

I have a use case where I am going to be receiving a new file every hour that is picked up by filebeat and then sent to logstash. The file will look like this:

```
[
	{
		"Results": {
			"StartWeekSec": [
				2000,
				198000.0
			],
			"ReportStartPeriod": "2019-01-15T07:00:00.000Z",
			"Constellation": "GPS",
			"ReferenceTime": [
				2000,
				31984.00
			],
			"Status": 0
		},
		"ForecastResults": [
			{
				"Point": [
					29.67,
					-7.5
				],
				"BestAccuracy": 10.98,
				"WorstAccuracy": 14.59				
			},
			{
				"Point": [
					55.37,
					54.1
				],
				"BestAccuracy": 20,
				"WorstAccuracy": 13.99		
			}
		]	
	},
	{
		"Results": {
			"StartWeekSec": [
				2000,
				198000.0
			],
			"ReportStartPeriod": "2019-01-15T07:00:00.000Z",
			"Constellation": "GPS",
			"ReferenceTime": [
				2000,
				31984.00
			],
			"Status": 0
		},
		"ForecastResults": [
			{
				"Point": [
					29.67,
					-7.5
				],
				"BestAccuracy": 10.98,
				"WorstAccuracy": 14.59				
			},
			{
				"Point": [
					55.37,
					54.1
				],
				"BestAccuracy": 20,
				"WorstAccuracy": 13.99		
			}
		]	
	}	
]

```

It is an array containing a number of json objects, some of which like "ForecastResults" can contain a number of nested objects within them.

I want to take each object in the array and convert it to a document in an Elasticsearch index that follows the above mapping. How can I achieve this using logstash? Could it be done with filebeat alone?

---

<div class="post-metadata">

**Author:** ![wangqinghuan](https://avatars.discourse-cdn.com/v4/letter/w/d26b3c/32.png) [@wangqinghuan](https://discuss.elastic.co/u/wangqinghuan)\
**Post date:** [November 14, 2020, 2:52pm UTC](https://discuss.elastic.co/t/how-to-parse-an-array-of-multi-line-json-objects-as-separate-documents-in-es/255230/2 "2020-11-14T14:52:25Z")

</div>

Hi,  
[Split filter plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html) can help you.

---

<div class="post-metadata">

**Author:** ![reillye](https://avatars.discourse-cdn.com/v4/letter/r/c6cbf5/32.png) [@reillye](https://discuss.elastic.co/u/reillye)\
**Post date:** [November 27, 2020, 10:23am UTC](https://discuss.elastic.co/t/how-to-parse-an-array-of-multi-line-json-objects-as-separate-documents-in-es/255230/3 "2020-11-27T10:23:30Z")

</div>

Thank you, this worked perfectly!

---

<div class="post-metadata">

**Author:** ![rahul.p](https://avatars.discourse-cdn.com/v4/letter/r/df788c/32.png) [@rahul.p](https://discuss.elastic.co/u/rahul.p)\
**Post date:** [December 7, 2020, 10:22pm UTC](https://discuss.elastic.co/t/how-to-parse-an-array-of-multi-line-json-objects-as-separate-documents-in-es/255230/4 "2020-12-07T22:22:41Z")

</div>

Hello @reillye, Can you please share your configuration file as I am having the same kind of scenario and have tried numerous things to achieve this but nothing seems working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2021, 10:22pm UTC](https://discuss.elastic.co/t/how-to-parse-an-array-of-multi-line-json-objects-as-separate-documents-in-es/255230/5 "2021-01-04T22:22:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
