# Iteration in Logstash

**URL:** <https://discuss.elastic.co/t/iteration-in-logstash/26123>\
**Category:** Logstash\
**Created:** [July 23, 2015, 4:10am UTC](https://discuss.elastic.co/t/iteration-in-logstash/26123 "2015-07-23T04:10:29Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jasonct05](https://avatars.discourse-cdn.com/v4/letter/j/ecb155/32.png) [@jasonct05](https://discuss.elastic.co/u/jasonct05)\
**Post date:** [July 23, 2015, 4:10am UTC](https://discuss.elastic.co/t/iteration-in-logstash/26123/1 "2015-07-23T04:10:29Z")

</div>

I have a string data in Logstash that has been parsed as that looks like

```
"id": "0,3,10"
"value": "100,200,300"

```

I would like to match the individual "id" to the corresponding "value" with respect to their order in the string.

I want the field to look like

```
"id0": "100"
"id3": "200"
"id10": "300"

```

As of now, I have used the mutate field to separate the array into its individual values. I used the following code:

```
mutate {
   add_field => {"id%{[id][0]}" => "%{[value][0]}"}
   add_field => {"id%{[id][1]}" => "%{[value][1]}"}
   add_field => {"id%{[id][2]}" => "%{[value][2]}"}
}

```

This code works fine fine. However, there are a varying number of values in the "id" field. Ie, some "id" field does not have id3, but some have an additional id4. However, for each id, there will definitely be a corresponding value in the "value" field. It will be difficult for me to make multiple if statements to fully separate all the possible combinations of different "id" values and its corresponding "value" values.

I heard that if I want make loop in Logstash, I have to use ruby filter. Unfortunately I'm not familiar with ruby

Thanks for any help. I really appreciate it.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 23, 2015, 10:02am UTC](https://discuss.elastic.co/t/iteration-in-logstash/26123/2 "2015-07-23T10:02:36Z")

</div>

```
filter {
  ruby {
    code => '
      ids = event["id"].split(",")
      values = event["value"].split(",")
      if ids.length == values.length
        ids.each_index { |i| event["id#{ids[i]}"] = values[i] }
      end
    '
  }
}
```

---

<div class="post-metadata">

**Author:** ![jasonct05](https://avatars.discourse-cdn.com/v4/letter/j/ecb155/32.png) [@jasonct05](https://discuss.elastic.co/u/jasonct05)\
**Post date:** [July 24, 2015, 2:11am UTC](https://discuss.elastic.co/t/iteration-in-logstash/26123/3 "2015-07-24T02:11:11Z")

</div>

Your code solved it! Thanks so much for your help 😄

---

<div class="post-metadata">

**Author:** ![Grigory\_Shamov](https://avatars.discourse-cdn.com/v4/letter/g/ec9cab/32.png) [@Grigory\_Shamov](https://discuss.elastic.co/u/Grigory_Shamov)\
**Post date:** [April 6, 2017, 7:40pm UTC](https://discuss.elastic.co/t/iteration-in-logstash/26123/4 "2017-04-06T19:40:18Z")

</div>

Hi Magnus,

Is there a way to iterate over event fields with new LS5 event syntax in the similar way?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 7, 2017, 5:02am UTC](https://discuss.elastic.co/t/iteration-in-logstash/26123/5 "2017-04-07T05:02:07Z")

</div>

> Is there a way to iterate over event fields with new LS5 event syntax in the similar way?

Should work the same, just use `event.get('foo')` instead of `event['foo']`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/iteration-in-logstash/26123/6 "2017-07-06T04:27:17Z")

</div>


