# How to split an array index in Kibana?

**URL:** <https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377>\
**Category:** Kibana\
**Created:** [September 16, 2021, 9:25am UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377 "2021-09-16T09:25:06Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![carlos\_gomez\_gomez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_gomez_gomez/32/89007_2.png) [@carlos\_gomez\_gomez](https://discuss.elastic.co/u/carlos_gomez_gomez)\
**Post date:** [September 16, 2021, 9:25am UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/1 "2021-09-16T09:25:06Z")

</div>

Hi everyone.

I have an index in my Kiabana that is an array. These index is an array becouse the length of this coud be diference each time. I need to split the array for use in the control visualization.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/2/325681080c445f5327c8a26f20d47d97f62c0181.png)

If I create a scripted field, the data in discover is no longer seen. I don't know why this happens.  
The script in painles I have created is this.

```auto
def x;
x = doc['tags.value'].value;
def y = x[2];
return y

```

Tags.value is the array of three elements.

Thank you so much.

---

<div class="post-metadata">

**Author:** ![tmp13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmp13/32/78005_2.png) [@tmp13](https://discuss.elastic.co/u/tmp13)\
**Post date:** [September 20, 2021, 8:12am UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/2 "2021-09-20T08:12:10Z")

</div>

Hi i think you must use:

```auto
def x;
def y;
x=params._source.tags;
if (doc['tags.keyword'].size()<=1)
{
    y='';
} else {
    y = x[1];
}
return y

```

Becouse If you use **tags.keyword** its sort your array and you will get unexpected result:  
you can check it like this:

```auto
def x='';
for (int i = 0; i < doc['tags.keyword'].length; ++i) {
    x += doc['tags.keyword'][i]
}
return x

```

For properly works my example you must enable have **\_source** field.

P.S I check on simple data like this:

```auto
PUT testscript_field/_doc/1
{
  "name": "lala",
  "tags": ["how", "are", "you"]
}

PUT testscript_field/_doc/2
{
  "name": "lala2",
  "tags": ["how" , "are"]
}

PUT testscript_field/_doc/3
{
  "name": "lala3",
  "tags": ["how"]
}

```

---

<div class="post-metadata">

**Author:** ![carlos\_gomez\_gomez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_gomez_gomez/32/89007_2.png) [@carlos\_gomez\_gomez](https://discuss.elastic.co/u/carlos_gomez_gomez)\
**Post date:** [September 20, 2021, 2:24pm UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/3 "2021-09-20T14:24:59Z")

</div>

Hello, thank you very much for answering.

I have tried the script but there is something wrong. I'm going to add more information to see if you can help me.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/3/83e0bbb8da8aa64922c08cf433f15b5d77d9650a.png)

I have an array like the following and I want to access the name. To be able to use it in the control element.

I don't have the tags.keyword element. Below I put a photo of the indexes created.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e43f0622bb5a559441c0d1caf78a41020fc8122.png)

If I use the second script you sent me, it returns the following:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4e726920647deb8b8d1c844b516023d495f47e50.png)

Finally I add the result of the following script:

```auto
def x = params._source.tags;
return x;

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/8/287209ca9e70251284f19b28cae626d4e6047a94.png)

Thank you very much. I hope you can help me.

---

<div class="post-metadata">

**Author:** ![tmp13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmp13/32/78005_2.png) [@tmp13](https://discuss.elastic.co/u/tmp13)\
**Post date:** [September 21, 2021, 10:11am UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/4 "2021-09-21T10:11:15Z")

</div>

I dont undestand...  
You already have tags.value.name why you need split?))

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e591d5d65551f5bd075f6a7cfca7cb2aedc47a5f.png)

> "To be able to use it in the control element."

What you mean as control element?

---

<div class="post-metadata">

**Author:** ![carlos\_gomez\_gomez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_gomez_gomez/32/89007_2.png) [@carlos\_gomez\_gomez](https://discuss.elastic.co/u/carlos_gomez_gomez)\
**Post date:** [September 21, 2021, 1:29pm UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/5 "2021-09-21T13:29:06Z")

</div>

Yes, because when access to discover section I can't see the index tags.value.name. I can access only to tags.type and tags.value that is an array compose by:

```auto
{
     tags.value.name
     tags.value.id
     tags.value.color
}

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/e/ee55c3c1f63c8e19fbf60546fcc4121a19d39104.png)

I need to access to tags.value.name because I want to filter my dashboard by the name of the tags.  
I mean for control element, the control visualization.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/a/da6ecd44e480db410dea344c747c2b5258fb77b6.png)

---

<div class="post-metadata">

**Author:** ![tmp13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmp13/32/78005_2.png) [@tmp13](https://discuss.elastic.co/u/tmp13)\
**Post date:** [September 21, 2021, 6:39pm UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/6 "2021-09-21T18:39:18Z")

</div>

Hmmm it must work... but you have exclamation mark on field tags.value  
Try refresh index pattern of your index in kibana. (from version 7.11 it`s automatically refreshed).

And check it`s available in Control Visualization.

(I check it in 7.13.4 ELK and all is ok)

---

<div class="post-metadata">

**Author:** ![carlos\_gomez\_gomez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carlos_gomez_gomez/32/89007_2.png) [@carlos\_gomez\_gomez](https://discuss.elastic.co/u/carlos_gomez_gomez)\
**Post date:** [September 22, 2021, 6:51am UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/7 "2021-09-22T06:51:41Z")

</div>

Yes the exclamation is these:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/8/38cf91730035e0115a22e84aa0f723ef07b10fb1.png)

---

<div class="post-metadata">

**Author:** ![tmp13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tmp13/32/78005_2.png) [@tmp13](https://discuss.elastic.co/u/tmp13)\
**Post date:** [September 22, 2021, 7:33am UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/8 "2021-09-22T07:33:19Z")

</div>

See this [Get "Objects in arrays are not well supported" with new schema in Kibana](https://discuss.elastic.co/t/get-objects-in-arrays-are-not-well-supported-with-new-schema-in-kibana/206905)  
Can you show mapping this index? What version ELK you using (i think you need update)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 20, 2021, 7:34am UTC](https://discuss.elastic.co/t/how-to-split-an-array-index-in-kibana/284377/9 "2021-10-20T07:34:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
