# Json split multiple event in Logstash Pipeline

**URL:** <https://discuss.elastic.co/t/json-split-multiple-event-in-logstash-pipeline/301080>\
**Category:** Logstash\
**Created:** [March 30, 2022, 11:56am UTC](https://discuss.elastic.co/t/json-split-multiple-event-in-logstash-pipeline/301080 "2022-03-30T11:56:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Purushottam22](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/purushottam22/32/92715_2.png) [@Purushottam22](https://discuss.elastic.co/u/Purushottam22)\
**Post date:** [March 30, 2022, 11:56am UTC](https://discuss.elastic.co/t/json-split-multiple-event-in-logstash-pipeline/301080/1 "2022-03-30T11:56:31Z")

</div>

Hi All,

I am trying to ingest the python script output using exec input plugin filter but i am facing issue while performing split operation on message. I am not sure how can I split into fields, below sample output which is receiving under message :  
**Output/Message field**  
{"required\_role":"OPERATOR","user\_role":"DESIGNER","accepted":true,"request\_url":"/catalog\_service\_settings","rest\_params":{},"original\_time":637841834485391604,"severity":"INFO","audit\_time":637841834485391604}  
{"required\_role":"OPERATOR","user\_role":"DESIGNER","accepted":true,"request\_url":"/catalog\_service\_settings","rest\_params":{},"original\_time":637841839892273074,"severity":"INFO","audit\_time":637841839892273074}  
{"required\_role":"OPERATOR","user\_role":"DESIGNER","accepted":true,"request\_url":"/catalog\_service\_settings","rest\_params":{},"original\_time":637841840485632613,"severity":"INFO","audit\_time":637841840485632613}  
{"required\_role":"OPERATOR","user\_role":"DESIGNER","accepted":true,"request\_url":"/catalog\_service\_settings","rest\_params":{},"original\_time":637841845977496183,"severity":"INFO","audit\_time":637841845977496183}  
{"required\_role":"OPERATOR","user\_role":"DESIGNER","accepted":true,"request\_url":"/catalog\_service\_settings","rest\_params":{},"original\_time":637841846485656787,"severity":"INFO","audit\_time":637841846485656787}

**Current Logstash Pipeline** :

input {  
exec {  
command =\> "python /usr/share/logstash/scripts/qlik\_2.py"  
interval =\> 30  
}  
}

filter {  
json {  
source =\> "message"  
skip\_on\_invalid\_json =\> true  
tag\_on\_failure =\> ["failed\_json"]  
}  
split {  
field =\> "message"  
}  
}

Could you please help me with the same.  
@Badger [@elastic\_team](https://discuss.elastic.co/groups/elastic_team) Kindly assist how can ingest data in respective fields in index.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 31, 2022, 2:38am UTC](https://discuss.elastic.co/t/json-split-multiple-event-in-logstash-pipeline/301080/2 "2022-03-31T02:38:35Z")

</div>

Hello,

Please do not ping people that are not part of the thread.

It is not clear what you want to do and what the issue is. What is your output?

If I understand correctly you want to create a new event for each one of the json documents in the output of the `exec` input plugin?

You should put the `split` filter before the `json` filter, try that and see if it works.

---

<div class="post-metadata">

**Author:** ![Purushottam22](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/purushottam22/32/92715_2.png) [@Purushottam22](https://discuss.elastic.co/u/Purushottam22)\
**Post date:** [March 31, 2022, 10:18am UTC](https://discuss.elastic.co/t/json-split-multiple-event-in-logstash-pipeline/301080/3 "2022-03-31T10:18:01Z")

</div>

Hello,

Now the output is getting split into new documents but Json filter is not working as I am not able to ingest log in key value format in kibana.

Can you please help me how can I resolved the same

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 31, 2022, 1:05pm UTC](https://discuss.elastic.co/t/json-split-multiple-event-in-logstash-pipeline/301080/4 "2022-03-31T13:05:40Z")

</div>

You need to share the output you are having, also share your updated pipeline config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2022, 1:05pm UTC](https://discuss.elastic.co/t/json-split-multiple-event-in-logstash-pipeline/301080/5 "2022-04-28T13:05:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
