# Logstash not writing to elasticsearch if split filter is used

**URL:** <https://discuss.elastic.co/t/logstash-not-writing-to-elasticsearch-if-split-filter-is-used/43693>\
**Category:** Logstash\
**Created:** [March 7, 2016, 7:11pm UTC](https://discuss.elastic.co/t/logstash-not-writing-to-elasticsearch-if-split-filter-is-used/43693 "2016-03-07T19:11:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Muaaz\_Saleem](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@Muaaz\_Saleem](https://discuss.elastic.co/u/Muaaz_Saleem)\
**Post date:** [March 7, 2016, 7:11pm UTC](https://discuss.elastic.co/t/logstash-not-writing-to-elasticsearch-if-split-filter-is-used/43693/1 "2016-03-07T19:11:44Z")

</div>

Hi Guys,

I'm trying to use the split filter. But Logstash doesn't write to elasticsearch if I do so. However, if I comment out the split filter it works like a charm. Would really appreciate the help, following is my conf file:

```
input {
    stdin {}
}

filter {
  #if [source] =~ "junitResult.xml" {
    multiline {
        pattern => ".*"
        what => "next"
    }

    #ruby {
    # code => "event['index'] = event['source'].match(/jobs\/(.*)\//)[1]
    # event['pipeline'] = event['source'].match(/jobs\/(.*)\/builds\//)[1]"
    #}
    ruby {
      code => "event['index'] = 1"
    }
    xml {
      source => "message"
      target => "parsed"
    }

  split {
    field => "[parsed][suites][suites][suite][suite][cases][cases][case]"
    add_field => {
      test_duration => "%{[parsed][suites][suites][suite][suite][cases][cases][case][duration]}"
      class_name => "%{[parsed][suites][suites][suite][suite][cases][cases][case][className]}"
      test_name => "%{[parsed][suites][suites][suite][suite][cases][cases][case][testName]}"
      skipped => "%{[parsed][suites][suites][suite][suite][cases][cases][case][skipped]}"
      result => "%{[parsed][suites][suites][suite][suite][cases][cases][case][errorDetails]}"
    }
  }

  if [result] !~ "Failed" {
    mutate {
      update => {
        "result" => "Success"
      }
    }
  }

    mutate {
      remove_field => ["message", "parsed"]
    }

  #}
}

output {
  elasticsearch {
   hosts => ["localhost:9200"]
   sniffing => true
   manage_template => false
   index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
   document_type => "%{[@metadata][type]}"
  }
  stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![Muaaz\_Saleem](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@Muaaz\_Saleem](https://discuss.elastic.co/u/Muaaz_Saleem)\
**Post date:** [March 8, 2016, 8:47am UTC](https://discuss.elastic.co/t/logstash-not-writing-to-elasticsearch-if-split-filter-is-used/43693/2 "2016-03-08T08:47:24Z")

</div>

ping : )

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2016, 10:15pm UTC](https://discuss.elastic.co/t/logstash-not-writing-to-elasticsearch-if-split-filter-is-used/43693/3 "2016-03-09T22:15:58Z")

</div>

Wild guess: The split filter doesn't include the `@metadata` field so the index and document\_type options won't get the values you expect?

Take ES out of the equation for now and just use the stdout output you already have (but change the rubydebug codec's option so it shows the contents of `@metadata`). When things look great there try again with the elasticsearch output enabled.

---

<div class="post-metadata">

**Author:** ![Muaaz\_Saleem](https://avatars.discourse-cdn.com/v4/letter/m/6de8d8/32.png) [@Muaaz\_Saleem](https://discuss.elastic.co/u/Muaaz_Saleem)\
**Post date:** [March 10, 2016, 5:11am UTC](https://discuss.elastic.co/t/logstash-not-writing-to-elasticsearch-if-split-filter-is-used/43693/4 "2016-03-10T05:11:16Z")

</div>

This worked like a charm! Thanks. I just hard-coded the index and document\_type fields to a static value.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:07am UTC](https://discuss.elastic.co/t/logstash-not-writing-to-elasticsearch-if-split-filter-is-used/43693/5 "2017-07-06T05:07:38Z")

</div>


