# Logstash parse json child element, format and insert into elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-parse-json-child-element-format-and-insert-into-elasticsearch/312230>\
**Category:** Logstash\
**Created:** [August 16, 2022, 11:05pm UTC](https://discuss.elastic.co/t/logstash-parse-json-child-element-format-and-insert-into-elasticsearch/312230 "2022-08-16T23:05:23Z")\
**Posts on this page:** 1\
**Showing post:** 7

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 17, 2022, 12:17am UTC](https://discuss.elastic.co/t/logstash-parse-json-child-element-format-and-insert-into-elasticsearch/312230/7 "2022-08-17T00:17:21Z")

</div>

Use a split filter to create a new event for each entry in the array....

```
split { field => "[fruits][fruit]" }

```

then use mutate+add\_field to move the items in the array entry to the top level using (or possibly use a [ruby](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2) filter), then use mutate+remove\_field to delete [fruits].

In the output section use a [sprintf reference](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf) ("%{id}") for the value of the document\_id option on the elasticsearch output.

@babuzrb To create [diffs] you could use this

```
    ruby {
        code => '
            d = ""
            for i in event.get("start").to_i .. event.get("end").to_i
                d += "#{i},"
            end

            event.set("diffs", d.chop)
        '
    }

```

I am sure there is some much prettier Ruby idiom that would work just as well

---

_[View the full topic](https://discuss.elastic.co/t/logstash-parse-json-child-element-format-and-insert-into-elasticsearch/312230)._
