# How to split nested fields into separate events?

**URL:** <https://discuss.elastic.co/t/how-to-split-nested-fields-into-separate-events/55219>\
**Category:** Logstash\
**Created:** [July 11, 2016, 5:58pm UTC](https://discuss.elastic.co/t/how-to-split-nested-fields-into-separate-events/55219 "2016-07-11T17:58:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pixelrebel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixelrebel/32/14056_2.png) [@pixelrebel](https://discuss.elastic.co/u/pixelrebel)\
**Post date:** [July 11, 2016, 5:58pm UTC](https://discuss.elastic.co/t/how-to-split-nested-fields-into-separate-events/55219/1 "2016-07-11T17:58:51Z")

</div>

Example of incoming nested data below.  
Ultimately, I want logstash to submit 9 events for this single object. 1 of type `storage` 2 of type `volume` 3 of type `share` and 3 of type `client`  
I'm looking for something like the `split` filter, but that works on arrays of objects.

```auto
{
    '@metadata': {"type": "storage"},
    "type": "storage",
    "name": "chassis3",
    "location": "Chicago",
    "total_files": 2000000,
    "total_capacity": 300,
    "volumes": [
        {
            "name": "vol1",
            "available": 50, 
            "capacity": 150, 
            "free": 65, 
            "reserved":100, 
            "used":85
        },
        {
            "name": "vol2", 
            "available": 100, 
            "capacity": 150, 
            "free": 110, 
            "reserved":50,
            "used":40
        }
    ],
    "shares": [
        {
            "name": "share1",
            "volume": "vol1",
            "capacity": 75, 
            "free": 10, 
            "used": 65,
            "files": 100000
        },
        {
            "name": "share2",
            "volume": "vol1",
            "capacity": 25, 
            "free": 5, 
            "used": 20,
            "files": 25000
        },
        {
            "name": "share3",
            "volume": "vol2",
            "capacity": 50, 
            "free": 10, 
            "used": 40,
            "files": 75000
        }
    ],
    "clients": [
        {
            "user": "bob",
            "read": 100,
            "write": 5
        },
        {
            "user": "alice",
            "read": 4,
            "write": 100
        },
        {
            "user": "eve",
            "read": 0,
            "write": 0
        }
    ]
}

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 11, 2016, 8:10pm UTC](https://discuss.elastic.co/t/how-to-split-nested-fields-into-separate-events/55219/2 "2016-07-11T20:10:35Z")

</div>

AFAICT the split filter supports arrays of objects. Please explain why it doesn't work for you, preferably with an example.

```nohighlight
$ cat test.config
input { stdin { codec => json } }
output { stdout { codec => rubydebug } }
filter { split { } }
$ echo '{"message": [{"foo": "bar"}, {"foo": "baz"}]}' | /opt/logstash/bin/logstash -f test.config
Settings: Default pipeline workers: 2
Pipeline main started
{
       "message" => {
        "foo" => "bar"
    },
      "@version" => "1",
    "@timestamp" => "2016-07-11T20:10:11.562Z",
          "host" => "hallonet"
}
{
       "message" => {
        "foo" => "baz"
    },
      "@version" => "1",
    "@timestamp" => "2016-07-11T20:10:11.562Z",
          "host" => "hallonet"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixelrebel/32/14056_2.png) [@pixelrebel](https://discuss.elastic.co/u/pixelrebel)\
**Post date:** [July 11, 2016, 8:31pm UTC](https://discuss.elastic.co/t/how-to-split-nested-fields-into-separate-events/55219/3 "2016-07-11T20:31:59Z")

</div>

Thanks @magnusbaeck, I see this now. The documentation says "string" for the `field` datatype, so I was a bit confused.

Followup question, if you don't mind. Using a clone, then split gets me what I need, but the field names for example are `clients.read` `clients.write` etc. Is there a way to get the field to collapse to the last child objects, i.e. `read` and `write`?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:48am UTC](https://discuss.elastic.co/t/how-to-split-nested-fields-into-separate-events/55219/4 "2017-07-06T04:48:35Z")

</div>


