# Logstash Split input and save new event.original

**URL:** <https://discuss.elastic.co/t/logstash-split-input-and-save-new-event-original/308222>\
**Category:** Logstash\
**Created:** [June 27, 2022, 9:11am UTC](https://discuss.elastic.co/t/logstash-split-input-and-save-new-event-original/308222 "2022-06-27T09:11:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gosborne](https://avatars.discourse-cdn.com/v4/letter/g/8c91f0/32.png) [@Gosborne](https://discuss.elastic.co/u/Gosborne)\
**Post date:** [June 27, 2022, 9:11am UTC](https://discuss.elastic.co/t/logstash-split-input-and-save-new-event-original/308222/1 "2022-06-27T09:11:52Z")

</div>

Good Morning,

I am trying to split up some JSON logs that are collected from an Eventhub and i'm running into a few issues.

My logstash filter below works fine and splits the json based on a field called records, and then removes the records top level field.

```auto
	# Split results into individual events
	split {
		field => "records"
	}
	
	ruby {
		code => "
			event.get('records').each {|k, v|
			event.set(k, v)
			}
			event.remove('records')
		"
	}
	
	mutate {
		copy => {"[message]" => "[event][original]"} 
	}

```

The problem i have is now how do i place the true original log (i.e. split out without the records) into event.orginal?

Message still contains the full eventhub file, not my updated logs. Does anyone know how i now place this new formatted log into event.orginal so i can use it elsewhere?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2022, 9:12am UTC](https://discuss.elastic.co/t/logstash-split-input-and-save-new-event-original/308222/2 "2022-07-25T09:12:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
