# Kv split into next row

**URL:** <https://discuss.elastic.co/t/kv-split-into-next-row/241024>\
**Category:** Logstash\
**Created:** [July 13, 2020, 6:21pm UTC](https://discuss.elastic.co/t/kv-split-into-next-row/241024 "2020-07-13T18:21:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Puneeth\_S\_B\_Gowda1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/puneeth_s_b_gowda1/32/68544_2.png) [@Puneeth\_S\_B\_Gowda1](https://discuss.elastic.co/u/Puneeth_S_B_Gowda1)\
**Post date:** [July 13, 2020, 6:21pm UTC](https://discuss.elastic.co/t/kv-split-into-next-row/241024/1 "2020-07-13T18:21:20Z")

</div>

input { beats { port =\> 5044 } }  
filter {  
kv {field\_split =\> "message"  
}  
kv {  
source =\> "n id"  
field\_split =\> ","  
}}  
output { elasticsearch { hosts =\> ["[http://localhost:9200](http://localhost:9200/)"] index =\> "atpidev1" } }

[11:44](https://elasticstack.slack.com/archives/CNKF2D325/p1594664065186100)

is it correct config to split each n id to different row

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/0/708b6d821afbb31830ec4f7bf66d643621376412.png)

getting result like above image

it should show as like showing in below image

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/e/3ecebbdca47a4bbb477c4821b934020c8c0c50a3.png)

---

<div class="post-metadata">

**Author:** ![Puneeth\_S\_B\_Gowda1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/puneeth_s_b_gowda1/32/68544_2.png) [@Puneeth\_S\_B\_Gowda1](https://discuss.elastic.co/u/Puneeth_S_B_Gowda1)\
**Post date:** [August 3, 2020, 11:08am UTC](https://discuss.elastic.co/t/kv-split-into-next-row/241024/2 "2020-08-03T11:08:18Z")

</div>

Able to achieve requirement with following conf

input { beats { port =\> 5044 } }

filter {  
mutate {  
split =\> { "message" =\> "@$@" }}

mutate {  
add\_field =\> { "response" =\> "%{[message][1]}" "request" =\> "%{[message][0]}" } }

xml { store\_xml =\> "false" source =\> "response" target =\> "xmldata"

xpath =\>[  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan[1]/@id","ratePlanid",  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan[1]/roomDetails/roomTypeCode/text()","roomTypeCode",  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan[1]/roomDetails/hhRoomType/text()","hhRoomType",  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan[1]/roomDetails/hhBedTypes/hhBedType/text()","hhBedTypes",  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan[1]/rateDetails/rateTypeCode/text()","rateTypeCode",  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan[1]/rateDetails/breakfastIncluded/text()","breakfastincluded",  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan[1]/rateDetails/nonRefundable/text()","nonRefundable",  
"/propertyAvailability/hotelRates/hotel/bookingChannel/ratePlan[1]/roomRateDetails/roomRateCode/text()","roomRateCode",  
"/propertyAvailability/hotelRates/hotel/bookingChannel/@type","bookingChannel" ]  
}

split {field =\> "bookingChannel"}  
split {field =\> "ratePlanid"}  
split {field =\> "roomTypeCode"}  
split {field =\> "hhRoomType"}  
split {field =\> "hhBedTypes"}  
split {field =\> "rateTypeCode"}  
split {field =\> "breakfastincluded"}  
split {field =\> "nonRefundable"}  
split {field =\> "roomRateCode"}

}

output { elasticsearch { hosts =\> ["[http://localhost:9200](http://localhost:9200/)"] index =\> "atpidev07jul2020-432" } }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2020, 11:08am UTC](https://discuss.elastic.co/t/kv-split-into-next-row/241024/3 "2020-08-31T11:08:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
