# Logstash problems with splitting on field value

**URL:** https://discuss.elastic.co/t/logstash-problems-with-splitting-on-field-value/305328
**Category:** Logstash
**Created:** [May 21, 2022, 10:10am UTC](https://discuss.elastic.co/t/logstash-problems-with-splitting-on-field-value/305328 "2022-05-21T10:10:02Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![edwardc](https://avatars.discourse-cdn.com/v4/letter/e/ec9cab/32.png) [@edwardc](https://discuss.elastic.co/u/edwardc)
#### Post date: [May 21, 2022, 10:10am UTC](https://discuss.elastic.co/t/logstash-problems-with-splitting-on-field-value/305328/1 "2022-05-21T10:10:02Z")

</div>

Hi All, i have a problem with the logstash split filter.  
Any advice or input is greatly appreciated. I have the input as such:

```auto
{"SONG_A":[
{
"MD5":"a",
"filename": "x.txt"
},
{
"MD5":"b",
"filename": "y.txt"
}
]
}

```

I am trying to split the first key into multiple events. The following code works:

```auto
filter{
json{
		source=>"message"
	}
split
	{
	field => "SONG_A"
	}}

```

Where i am getting the following results:

```auto
Event 1:
{
      "SONG_A" => {
        "filename" => "x.txt",
             "MD5" => "a"
    }
}
Event 2:
{
      "SONG_A" => {
        "filename" => "y.txt",
        "MD5" => "b"
    }
}

```

However, the key - in this case SONG\_A is subject to change, as such a grok filter was created and the value was stashed in the metadata field. However, i am unable to split the key into separate events. The code is as below:

```auto
filter{
	json{
		source=>"message"
	}
	grok {
	match => {"message" => "(?<[@metadata][SONG]>SONG[_A-Z]*)"}
	}
	split
	{
	field => "[@metadata][SONG]"
	}

```

However, i am getting the following output where the event is still a single event and not being split as above:

```auto
event 1:
{

    "@metadata" => {
        "SONG" => "SONG_A",
    },
     "SONG_A" => [
        [0] {
            "filename" => "x.txt",
                 "MD5" => "a"
        },
        [1] {
            "filename" => "y.txt",
                 "MD5" => "b"
        }
    ]
}

```

Why am i unable to split the event into two events?

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 21, 2022, 4:46pm UTC](https://discuss.elastic.co/t/logstash-problems-with-splitting-on-field-value/305328/2 "2022-05-21T16:46:42Z")

</div>

> [@edwardc](#):
>
> ```
> split { field => "[@metadata][SONG]" }
> 
> ```

[@metadata][SONG] is not an array, it is a string, so a split filter will split it into multiple lines if it contains them. "SONG\_A" is a single line, so the filter will be a no-op.

It looks like the field name [SONG\_A] is a variable, so you want to do the equivalent of

```
split { field => "%{[@metadata][SONG]}" }

```

however, the split filter does not support sprintf references in the field option, so that will not work. What you can do is

```
    grok { match => { "message" => "(?<[@metadata][SONG]>SONG[_A-Z]*)" } }
    json {
        source => "message"
        target => "[@metadata][data]"
        remove_field => ["message"]
    }
    ruby {
        code => '
            fieldName = event.get("[@metadata][SONG]")
            data = event.get("[@metadata][data][#{fieldName}]")
            event.set("[@metadata][dataArray]", data)
        '
    }
    split { field => "[@metadata][dataArray]" }
    ruby {
        code => '
            fieldName = event.get("[@metadata][SONG]")
            data = event.get("[@metadata][dataArray]")
            event.set(fieldName, data)
        '
    }

```

---

<div class="post-metadata">

### Author: ![edwardc](https://avatars.discourse-cdn.com/v4/letter/e/ec9cab/32.png) [@edwardc](https://discuss.elastic.co/u/edwardc)
#### Post date: [May 22, 2022, 4:14am UTC](https://discuss.elastic.co/t/logstash-problems-with-splitting-on-field-value/305328/3 "2022-05-22T04:14:17Z")

</div>

Thanks Badger, your explanation was clear, especially the following

> [@Badger](#):
>
> however, the split filter does not support sprintf references in the field option, so that will not work.

The code you provided also managed to rectify the problem i was facing.  
Thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 19, 2022, 4:14am UTC](https://discuss.elastic.co/t/logstash-problems-with-splitting-on-field-value/305328/4 "2022-06-19T04:14:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
