# HTTP Filter - Unnest Array

**URL:** <https://discuss.elastic.co/t/http-filter-unnest-array/277778>\
**Category:** Logstash\
**Created:** [July 5, 2021, 6:55am UTC](https://discuss.elastic.co/t/http-filter-unnest-array/277778 "2021-07-05T06:55:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RoteEdition](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roteedition/32/91103_2.png) [@RoteEdition](https://discuss.elastic.co/u/RoteEdition)\
**Post date:** [July 5, 2021, 6:55am UTC](https://discuss.elastic.co/t/http-filter-unnest-array/277778/1 "2021-07-05T06:55:16Z")

</div>

Hi there,  
I need to unnest an array (based on the workaround mentioned in this [previous thread](https://discuss.elastic.co/t/http-poller-url-from-another-field/277722)) into seperate documents.

I am calling an API and getting in return an array of results. Each of these results should preferably be seperated into its own document.

Currently all these results are stored inside a body field (see workaround, this seems to be the only option atm ). I assume that you could probably loop over each element in the array and then create a new document for each, with a ruby script. Unfortunanely I never wrote anything Ruby related let alone Ruby + Logstash.  
Maybe someone could point me to a good starting point and/or give me an example if possible.

Here is the current output as reference:

```auto
{
    "@timestamp" => 2021-07-05T06:25:43.321Z,
        "origin" => "XXX",
      "@version" => "1",
       "headers" => {
                             "date" => "Mon, 05 Jul 2021 06:25:44 GMT",
        "strict-transport-security" => "max-age=15724800; includeSubDomains",
                     "content-type" => "application/json",
                    "cache-control" => "max-age=0, private, must-revalidate",
                             "vary" => "Accept-Encoding",
                     "x-request-id" => "24e8d9f20bf78f24f586980a17d47cef",
                       "connection" => "keep-alive",
                "transfer-encoding" => "chunked",
                         "per-page" => "100",
                        "x-runtime" => "0.023585",
                            "total" => "9",
                             "etag" => "W/\"5f5dd0d16cda9863332b6bac2480dffb\""
    },
        "apiurl" => "XXX&date=2021-07-05",
          "body" => [
        [0] {
            "received_at" => "2021-07-05T07:39:47.000+02:00",
                 "length" => 4,
                 "amount" => 0.118,
             "answer_uri" => nil,
                     "to" => "XXX",
            "description" => "XXX ",
                   "from" => "XXX"
        },
        [1] {
            "received_at" => "2021-07-05T07:41:33.000+02:00",
                 "length" => 587,
                 "amount" => 1.18,
             "answer_uri" => nil,
                     "to" => "XXX",
            "description" => "XXX ",
                   "from" => "XXX"
        },
        [2] {
            "received_at" => "2021-07-05T07:42:38.000+02:00",
                 "length" => 132,
                 "amount" => 0.036,
             "answer_uri" => nil,
                     "to" => "XXX",
            "description" => "XXX",
                   "from" => "XXX"
        }
    ],
           "url" => "https://httpbin.org/get",
          "args" => {},
          "time" => "2021-07-05"
}

```

Thank you guys so much!  
Kind Regards  
Marvin

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 5, 2021, 12:46pm UTC](https://discuss.elastic.co/t/http-filter-unnest-array/277778/2 "2021-07-05T12:46:47Z")

</div>

You could use a [split](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html) filter.

---

<div class="post-metadata">

**Author:** ![RoteEdition](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roteedition/32/91103_2.png) [@RoteEdition](https://discuss.elastic.co/u/RoteEdition)\
**Post date:** [July 5, 2021, 2:22pm UTC](https://discuss.elastic.co/t/http-filter-unnest-array/277778/3 "2021-07-05T14:22:17Z")

</div>

Ah yes, i completely missed the split filter in the doc. Unfortunately I can't do further actions on the fields inside the body. (It's probably a similiar behaviour to the http-poller problem from my other thread). Therefore this ain't really a solution for my usecase.

I need to access the fields to rename them. At the moment I don't know if this is even possible (with or without the split filter). The "split" documentation didn't mention anything similiar.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2021, 2:22pm UTC](https://discuss.elastic.co/t/http-filter-unnest-array/277778/4 "2021-08-02T14:22:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
