# Multiple values in field json parser

**URL:** <https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530>\
**Category:** Logstash\
**Created:** [November 30, 2021, 9:21am UTC](https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530 "2021-11-30T09:21:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![svenvg93](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@svenvg93](https://discuss.elastic.co/u/svenvg93)\
**Post date:** [November 30, 2021, 9:21am UTC](https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530/1 "2021-11-30T09:21:45Z")

</div>

In order to learn more about ELK, I try to combine it with fun stuff to build 🙂 .

On of the things I try to make is dashboard with Formula 1 data.  
Im able to get the data in Elasticsearch by curl an json api.

Now the problem is the data is the same for every driver. So its combines the fields. Whichs makes it impossible to create visualizations.

Using this logstash input to get the data.

```auto
input {
    exec {
        command => "curl --location --request GET 'http://ergast.com/api/f1/2021/1/results.json'"
        type => "curl"
        interval => 3600
        tags => ["f1"]
    }
}
filter {
        json {
            source => "message"
        }
        mutate {
            remove_field => ["command"]
            remove_field => ["type"]
            remove_field => ["host"]
            remove_field => ["@version"]
            remove_field => ["message"]
        }
}
output {
        elasticsearch {
                hosts => "localhost:9200"
                ecs_compatibility => disabled
                index => "f1.tracks-%{+YYYY.MM.dd}"
        }
}

```

Data output can be vieuw here: [http://ergast.com/api/f1/2021/1/results.json](http://ergast.com/api/f1/2021/1/results.json)

Some fields are used for every driver like "permanentNumber". This is now combined in one field separed by a comma instead of multiple field so it can be used in a visualizations, if im correct.

Is there a way to get the data in multiple fields or any other way to it can be used in visualizations.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 30, 2021, 6:10pm UTC](https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530/2 "2021-11-30T18:10:09Z")

</div>

I am not sure that it answers your question, but if you want each race and car to be a separate event you can use

```
    json { source => "message" }
    mutate { remove_field => ["command", "type", "host", "@version", "message"] }
    split { field => "[MRData][RaceTable][Races]" }
    split { field => "[MRData][RaceTable][Races][Results]" }

```

Also an http\_poller may be more efficient that an exec

```
input { http_poller { urls => { "first" => "http://ergast.com/api/f1/2021/1/results.json" } schedule => { cron => "0 0 * * * *" } } }
```

---

<div class="post-metadata">

**Author:** ![svenvg93](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@svenvg93](https://discuss.elastic.co/u/svenvg93)\
**Post date:** [December 16, 2021, 1:34pm UTC](https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530/3 "2021-12-16T13:34:05Z")

</div>

Sorry for the late reply!

Thanks for the solution that works!

One last question; Since the data will be "imported" once is there a way to remove the date and time of the even. Or should I just set the time range in Kibana to every long.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 16, 2021, 4:12pm UTC](https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530/4 "2021-12-16T16:12:17Z")

</div>

I do not think @timestamp is optional in Elasticsearch, just set the kibana time range to All Time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 13, 2022, 4:12pm UTC](https://discuss.elastic.co/t/multiple-values-in-field-json-parser/290530/5 "2022-01-13T16:12:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
