# Logstash split log and insert it separately into elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-split-log-and-insert-it-separately-into-elasticsearch/277694>\
**Category:** Logstash\
**Created:** [July 3, 2021, 4:05am UTC](https://discuss.elastic.co/t/logstash-split-log-and-insert-it-separately-into-elasticsearch/277694 "2021-07-03T04:05:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![shifenglim](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@shifenglim](https://discuss.elastic.co/u/shifenglim)\
**Post date:** [July 3, 2021, 4:05am UTC](https://discuss.elastic.co/t/logstash-split-log-and-insert-it-separately-into-elasticsearch/277694/1 "2021-07-03T04:05:28Z")

</div>

I am writing a logstash config file and a log I am receiving is giving me issues, the team sent me multiple logs merged into one eg.

message: [logitem(aaa=1, bbb=1, ccc=1), logitem(aaa=2, bbb=2, ccc=2), logitem(aaa=3, bbb=3, ccc=3)]

Would it be possible to split these log into 3 and insert them individually into elasticsearch? (3 records)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2021, 4:18pm UTC](https://discuss.elastic.co/t/logstash-split-log-and-insert-it-separately-into-elasticsearch/277694/2 "2021-07-03T16:18:56Z")

</div>

You can use a split filter to split an array into multiple events.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2021, 4:19pm UTC](https://discuss.elastic.co/t/logstash-split-log-and-insert-it-separately-into-elasticsearch/277694/3 "2021-07-31T16:19:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
