# Multiple split

**URL:** <https://discuss.elastic.co/t/multiple-split/276533>\
**Category:** Logstash\
**Created:** [June 21, 2021, 12:11pm UTC](https://discuss.elastic.co/t/multiple-split/276533 "2021-06-21T12:11:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![graaooor](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@graaooor](https://discuss.elastic.co/u/graaooor)\
**Post date:** [June 21, 2021, 12:11pm UTC](https://discuss.elastic.co/t/multiple-split/276533/1 "2021-06-21T12:11:32Z")

</div>

Hello,

I Have a csv file which have 3 fields  
field1 : ID  
field2 : Company Name  
field3 : Array of contacts (separator : | )  
Theis field can be :

- null (no contact)
- one or more contacts

But each contact is also an array with :

- firstname
- lastname
- email

Exemple :  
11111;Company 1;  
22222:Company [2;MARC,SMITH,marcsmith@company1.com](mailto:2;MARC,SMITH,marcsmith@company1.com)  
33333:Company 3;JOHN,LENNON,johnlennon@company2.com|RINGO,STARR,rstarr@company2.com

How can I load this csv file with logstash ?  
If I put this in my load.conf :  
mutate {  
split =\> { "contacts" =\> "|" }  
}  
But I want the firstname, lastname, and email in separate fields ...  
Thanks for your help

Sorry for my poor english.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 21, 2021, 4:52pm UTC](https://discuss.elastic.co/t/multiple-split/276533/2 "2021-06-21T16:52:03Z")

</div>

You could use

```
    mutate { gsub => ["message", ":", ";"] }
    csv { columns => ["column1", "column2", "contacts"] separator => ";" }
    mutate { split => { "contacts" => "|" } }
    ruby {
        code => '
            a = event.get("contacts")
            if a.is_a? Array
                newA = []
                a.each { |x|
                    x = x.split(",")
                    newA << { "lastName" => x[0], "firstName" => x[1], "email" => x[2] }
                }
                event.set("contacts", newA)
            end
        '
    }

```

to get

```
  "contacts" => [
    [0] {
         "lastName" => "JOHN",
            "email" => "johnlennon@company2.com",
        "firstName" => "LENNON"
    },
    [1] {
         "lastName" => "RINGO",
            "email" => "rstarr@company2.com",
        "firstName" => "STARR"
    }
],
```

---

<div class="post-metadata">

**Author:** ![graaooor](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@graaooor](https://discuss.elastic.co/u/graaooor)\
**Post date:** [June 21, 2021, 10:51pm UTC](https://discuss.elastic.co/t/multiple-split/276533/3 "2021-06-21T22:51:03Z")

</div>

Thank you for this solution !  
Very good. All is ok for me.

---

<div class="post-metadata">

**Author:** ![graaooor](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@graaooor](https://discuss.elastic.co/u/graaooor)\
**Post date:** [June 23, 2021, 7:55am UTC](https://discuss.elastic.co/t/multiple-split/276533/4 "2021-06-23T07:55:08Z")

</div>

I have another question with this example :  
For each company, I can have 0, 1 or many contacts  
How can I find the total contacts on my index, wich is different of the total of companies ?  
Thanks for your reply

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 21, 2021, 7:55am UTC](https://discuss.elastic.co/t/multiple-split/276533/5 "2021-07-21T07:55:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
