# How to split an event to multiple events?

**URL:** https://discuss.elastic.co/t/how-to-split-an-event-to-multiple-events/162406
**Category:** Logstash
**Created:** [December 29, 2018, 10:22am UTC](https://discuss.elastic.co/t/how-to-split-an-event-to-multiple-events/162406 "2018-12-29T10:22:15Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![michaelhe](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@michaelhe](https://discuss.elastic.co/u/michaelhe)
#### Post date: [December 29, 2018, 10:22am UTC](https://discuss.elastic.co/t/how-to-split-an-event-to-multiple-events/162406/1 "2018-12-29T10:22:16Z")

</div>

I'm trying to parse zookeeper wchc output using logstash:

0x167892507c74d32  
/zookeeper/cluster\_name/stores/31/alive  
/zookeeper/cluster\_name/stores/24/alive  
/zookeeper/cluster\_name/stores/32/alive

for each session id ( 0x0x167892507c74d32 ) there are multiple watches (/zookeeper/cluster\_name/stores/xx/xxxx )listed below, each starting with a few spaces, and I wish to split this single event into multiple events, each with the following fields:

session\_id="0x167892507c74d32" watch="/zookeeper/cluster\_name/stores/24/alive"  
session\_id="0x167892507c74d32" watch="/zookeeper/cluster\_name/stores/31/alive"  
session\_id="0x167892507c74d32" watch="/zookeeper/cluster\_name/stores/31/alive"

I'm aware there is a "split" plugin in logstash which could help, but I don't know how to do it ,could anyone please offer a simple example of how to do this? any suggestion would be greatly appreciated!

---

<div class="post-metadata">

### Author: ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)
#### Post date: [January 3, 2019, 3:18pm UTC](https://discuss.elastic.co/t/how-to-split-an-event-to-multiple-events/162406/2 "2019-01-03T15:18:59Z")

</div>

I don't think split is the filter you should be looking to use here.  
You may have to use an aggregate or multiline plugin instead that uses the session id as the start event and then you can a timeout for the last event.  
The end results would be a single event but it would contain the session id and all of the corresponding watches for that session id.

---

<div class="post-metadata">

### Author: ![michaelhe](https://avatars.discourse-cdn.com/v4/letter/m/53a042/32.png) [@michaelhe](https://discuss.elastic.co/u/michaelhe)
#### Post date: [January 4, 2019, 7:08am UTC](https://discuss.elastic.co/t/how-to-split-an-event-to-multiple-events/162406/3 "2019-01-04T07:08:09Z")

</div>

Thank you for your reply !  
After some digging into documentation I finally found the solution. Here is how I did it:

```auto
    grok {
      match => {
        message => "%{DATA:session_id}\n(?<watch>^(\s+.*)+$)"
      }
    }
    mutate {
      gsub => ["watch", "\n", ","]
      gsub => ["watch", "\s", ""]
      split => ["watch", ","]
    }
    split {
      field => "watch"
    }

```

After the first grok the event is like:

```auto
session_id=0x167892507c74d32
watch="/zookeeper/cluster_name/stores/31/alive \n/zookeeper/cluster_name/stores/24/alive \n/zookeeper/cluster_name/stores/32/alive"

```

Then I used mutate-gsub to replace "\n" to "," for the latter mutate-split,and to remove all spaces in the "watch" field, after mutate-split the event is like:

```auto
session_id=0x167892507c74d32
watch=["/zookeeper/cluster_name/stores/31/alive","/zookeeper/cluster_name/stores/24/alive","/zookeeper/cluster_name/stores/32/alive"]

```

Now I can use the split filter plugin to split this single event into multiple events:

```auto
event1:
session_id="0x167892507c74d32" watch="/zookeeper/cluster_name/stores/24/alive"

event2:
session_id="0x167892507c74d32" watch="/zookeeper/cluster_name/stores/31/alive"

event3:
session_id="0x167892507c74d32" watch="/zookeeper/cluster_name/stores/31/alive"

```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 1, 2019, 7:08am UTC](https://discuss.elastic.co/t/how-to-split-an-event-to-multiple-events/162406/4 "2019-02-01T07:08:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
