# How to split array field in json and send it as separate event

**URL:** <https://discuss.elastic.co/t/how-to-split-array-field-in-json-and-send-it-as-separate-event/198227>\
**Category:** Logstash\
**Created:** [September 5, 2019, 10:45am UTC](https://discuss.elastic.co/t/how-to-split-array-field-in-json-and-send-it-as-separate-event/198227 "2019-09-05T10:45:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![uma\_rengasamy](https://avatars.discourse-cdn.com/v4/letter/u/e56c9b/32.png) [@uma\_rengasamy](https://discuss.elastic.co/u/uma_rengasamy)\
**Post date:** [September 5, 2019, 10:45am UTC](https://discuss.elastic.co/t/how-to-split-array-field-in-json-and-send-it-as-separate-event/198227/1 "2019-09-05T10:45:19Z")

</div>

Please find the debug o/p , We want each logEvents as separate event in kibana, since logEvents will be huge in count and it takes time to load in kibana

{  
"logEvents" =\> [  
[0] {  
"message" =\>  
"id" =\>  
"timestamp" =\>  
"extractedFields" =\>  
"dstport" =\>  
"bytes" =\>  
"srcport" =\>  
"version" =\>  
"log\_status" =\>  
"action" =\>  
"packets" =\>  
"protocol" =\>  
"end" =\>  
"account\_id" =\>  
"interface\_id" =\>  
"start" =\>  
"srcadent" =\>  
"dstadent" =\>  
}  
},  
[1] {  
"message" =\>  
"id" =\>  
"timestamp" =\>  
"extractedFields" =\>  
"dstport" =\>  
"bytes" =\>  
"srcport" =\>  
"version" =\>  
"log\_status" =\>  
"action" =\>  
"packets" =\>  
"protocol" =\>  
"end" =\>  
"account\_id" =\>  
"interface\_id" =\>  
"start" =\>  
"srcadent" =\>  
"dstadent" =\>  
}  
},  
"messageType" =\> "",  
"@version" =\> "1",  
"@timestamp" =\> 2019-09-05T07:42:13.612Z,  
"subscriptionFilters" =\> [  
[0] "vpc"  
],  
"logGroup" =\> "",  
"s3Path" =\> "",  
"owner" =\> "",  
"logStream" =\> ""  
"type" =\> ""  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 5, 2019, 11:57am UTC](https://discuss.elastic.co/t/how-to-split-array-field-in-json-and-send-it-as-separate-event/198227/2 "2019-09-05T11:57:26Z")

</div>

Use a [split](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html) filter.

---

<div class="post-metadata">

**Author:** ![uma\_rengasamy](https://avatars.discourse-cdn.com/v4/letter/u/e56c9b/32.png) [@uma\_rengasamy](https://discuss.elastic.co/u/uma_rengasamy)\
**Post date:** [September 5, 2019, 12:13pm UTC](https://discuss.elastic.co/t/how-to-split-array-field-in-json-and-send-it-as-separate-event/198227/3 "2019-09-05T12:13:08Z")

</div>

It didn't work. No events were shipped to ES , when we use "split"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2019, 12:14pm UTC](https://discuss.elastic.co/t/how-to-split-array-field-in-json-and-send-it-as-separate-event/198227/4 "2019-10-03T12:14:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
