# HTTP JSON input with Split but keeping other fields

**URL:** <https://discuss.elastic.co/t/http-json-input-with-split-but-keeping-other-fields/288089>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 31, 2021, 11:31am UTC](https://discuss.elastic.co/t/http-json-input-with-split-but-keeping-other-fields/288089 "2021-10-31T11:31:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bitnapper](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bitnapper/32/96566_2.png) [@bitnapper](https://discuss.elastic.co/u/bitnapper)\
**Post date:** [October 31, 2021, 11:31am UTC](https://discuss.elastic.co/t/http-json-input-with-split-but-keeping-other-fields/288089/1 "2021-10-31T11:31:49Z")

</div>

Hi,

as a learning project I set up a ELK stack to read the status of my Hue Homeautomation installation. I only need to read the sensordata at the moment but I want to keep the association to the bridge. I use filebeat to read from the Hue API and `response.split.target: "body.sensors"` to get every sensor state as a singel event. Along with the sensor data come a config object wich I'd like to add to every one of these sensor evets to parse it later in the pipeline. But I'm not sure wether the http json input can do that or not. The JSON is like

```auto

{
  "lights": { "1": {}, "3": {} },
  "config": { "name": "xxx", "mac": "xx:xx:xx:xx:xx" },
  "sensors": { "5": {}, "2": {} }
}

```

The filebeat input looks like this:

```auto
filebeat.inputs:
- type: httpjson
  config_version: 2
  response.split.type: "map"
  response.split.target: "body.sensors"
  interval: 10s
  request.url: "http://192.168.1.44/api/xxx/"
  pipeline: "philips_hue"
  processors:
    - decode_json_fields:
        max_depth: 3
        fields: ["message"]
        target: "json"
    - fingerprint:
        fields: ["message"]
        target_field: "@metadata._id"

```

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [November 2, 2021, 5:27am UTC](https://discuss.elastic.co/t/http-json-input-with-split-but-keeping-other-fields/288089/2 "2021-11-02T05:27:35Z")

</div>

Hello Thorsten,

I have not tried it out myself but I guess you want to use `response.split.keep_parent` as described [here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-httpjson.html#_response_split_keep_parent):

> If set to true, the fields from the parent document (at the same level as `target` ) will be kept. Otherwise a new document will be created using `target` as the root. Default: `false` .

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2021, 7:27am UTC](https://discuss.elastic.co/t/http-json-input-with-split-but-keeping-other-fields/288089/3 "2021-11-30T07:27:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
