# How to split JSON nested arrays?

**URL:** <https://discuss.elastic.co/t/how-to-split-json-nested-arrays/127976>\
**Category:** Logstash\
**Created:** [April 13, 2018, 1:05pm UTC](https://discuss.elastic.co/t/how-to-split-json-nested-arrays/127976 "2018-04-13T13:05:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MrFrost](https://avatars.discourse-cdn.com/v4/letter/m/ecc23a/32.png) [@MrFrost](https://discuss.elastic.co/u/MrFrost)\
**Post date:** [April 13, 2018, 1:05pm UTC](https://discuss.elastic.co/t/how-to-split-json-nested-arrays/127976/1 "2018-04-13T13:05:26Z")

</div>

Hello,

I have quite a problem in attempt to split tags below is what I have:

> message: {"fields":{"value":9936},"name":"sqlserver\_performance","tags":{"counter":"Log File(s) Size (KB)","host":"WIN","instance":"Total","object":"MSSQL$DB:Databases","sql\_instance":"WIN:DB"},"timestamp":1523617465000000000}

After parsing it with JSON in logstash by using:

```
json {
        source => "message"
    }

```

I get below results in elasticsearch:

```
{
  "_index": "logstash-sql-2018.04.13",
  "_type": "doc",
  "_id": "RuetvmIB7heNFYtXabpg",
  "_version": 1,
  "_score": null,
  "_source": {
    "offset": 1225848,
    "@timestamp": "2018-04-13T11:04:25.000Z",
    "fields": {
      "value": 9936
    },
    "tags": [
      [
        "host",
        "WIN"
      ],
      [
        "object",
        "MSSQL$DB:Databases"
      ],
      [
        "counter",
        "Log File(s) Size (KB)"
      ],
      [
        "instance",
        "Total"
      ],
      [
        "sql_instance",
        "WIN:DB"
      ]
    ],
    "beat": {
      "version": "6.2.3",
      "hostname": "WIN",
      "name": "WIN"
    },
    "name": "sqlserver_performance",
    "host": "WIN",
    "date": "1523617465000",
    "timestamp": 1523617465000000000,
    "@version": "1",
    "source": "c:\\temp\\sql\\sqlperf.out",
    "message": "{\"fields\":{\"value\":9936},\"name\":\"sqlserver_performance\",\"tags\":{\"counter\":\"Log File(s) Size (KB)\",\"host\":\"WIN\",\"instance\":\"Total\",\"object\":\"MSSQL$DB:Databases\",\"sql_instance\":\"WIN:DB\"},\"timestamp\":1523617465000000000}"
  },
  "fields": {
    "@timestamp": [
      "2018-04-13T11:04:25.000Z"
    ]
  },
  "sort": [
    1523617465000
  ]
}

```

Now this is almost perfect but I need to split tags array to separate fields with proper data types and I have no idea how to do it. Hopefully someone can help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 13, 2018, 4:37pm UTC](https://discuss.elastic.co/t/how-to-split-json-nested-arrays/127976/3 "2018-04-13T16:37:49Z")

</div>

This reminds me of what you get without force\_array =\> false in an xml filter 🙂

If I understand the ask correctly then you could do it with this:

```auto
ruby { code => ' event.set("tagsAsHash", event.get("tags").to_h) ' }

```

```
"tagsAsHash" => {
            "host" => "WIN",
        "instance" => "Total",
         "counter" => "Log File(s) Size (KB)",
          "object" => "MSSQL$DB:Databases",
    "sql_instance" => "WIN:DB"
},
```

---

<div class="post-metadata">

**Author:** ![MrFrost](https://avatars.discourse-cdn.com/v4/letter/m/ecc23a/32.png) [@MrFrost](https://discuss.elastic.co/u/MrFrost)\
**Post date:** [April 16, 2018, 7:15am UTC](https://discuss.elastic.co/t/how-to-split-json-nested-arrays/127976/4 "2018-04-16T07:15:47Z")

</div>

Really nice and such simple code, thank you a lot for help 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2018, 7:16am UTC](https://discuss.elastic.co/t/how-to-split-json-nested-arrays/127976/5 "2018-05-14T07:16:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
