# Logstash config for splitting array into new events

**URL:** <https://discuss.elastic.co/t/logstash-config-for-splitting-array-into-new-events/158184>\
**Category:** Logstash\
**Created:** [November 26, 2018, 1:17pm UTC](https://discuss.elastic.co/t/logstash-config-for-splitting-array-into-new-events/158184 "2018-11-26T13:17:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![00a45f9a00ca005db54c](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/00a45f9a00ca005db54c/32/38003_2.png) [@00a45f9a00ca005db54c](https://discuss.elastic.co/u/00a45f9a00ca005db54c)\
**Post date:** [November 26, 2018, 1:17pm UTC](https://discuss.elastic.co/t/logstash-config-for-splitting-array-into-new-events/158184/1 "2018-11-26T13:17:01Z")

</div>

Hi there. I'm trying to split array into separate log files. Input is a JSON like this

```
{
  "data": [
    {
      "field1": "val1",
      "field2": "val2"
    },
    {
      "field1": "val1",
      "field2": "val2"
    },
    ...
  ]
}

```

And i use conf like this:

```
    input {
      file {
        path => ["/usr/local/etc/logstash/multi/*.json"]
        start_position => "beginning"
        sincedb_path => "/dev/null"
        type => "kitlog-multi"
      }
    }
 
filter {
  json {
    source => "message"
    target => "message"
  }
  if [type] == "kitlog-multi"{
    split {
      field => "[data]"
    }
  }
}
 
output {
  if [type] == "kitlog-multi" {
    elasticsearch {
      hosts => ["127.0.0.1:9200"] 
      index => "kitlog-multi"
    }
  }
  
  stdout {}
}

```

But all objects from "data" are coming to ES as a single log anyways, they are just like comma-separated  
message.data.field1 = value1, value2, ....  
message.data.field2 = value1, value2, ...

Any ideas why it is not splitting correctly? Thanks in advance

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 26, 2018, 3:39pm UTC](https://discuss.elastic.co/t/logstash-config-for-splitting-array-into-new-events/158184/2 "2018-11-26T15:39:15Z")

</div>

I mean to me this is expected behaviour, in your example you have two fields with the same name in the same object? You have two message.data.field1 so how do you expect it to behave?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2018, 3:39pm UTC](https://discuss.elastic.co/t/logstash-config-for-splitting-array-into-new-events/158184/3 "2018-12-24T15:39:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
