# Processor -\> split -\> set array.element?

**URL:** <https://discuss.elastic.co/t/processor-split-set-array-element/83941>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 27, 2017, 9:22pm UTC](https://discuss.elastic.co/t/processor-split-set-array-element/83941 "2017-04-27T21:22:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zachary\_Buckholz](https://avatars.discourse-cdn.com/v4/letter/z/f1d935/32.png) [@Zachary\_Buckholz](https://discuss.elastic.co/u/Zachary_Buckholz)\
**Post date:** [April 27, 2017, 9:22pm UTC](https://discuss.elastic.co/t/processor-split-set-array-element/83941/1 "2017-04-27T21:22:17Z")

</div>

I posted a similar question to the elasticsearch forum since it appeared to be more of an intrinsic ES problem. But I am not sure.

I have the following filebeat yaml.

Basically I am attempting to split based on \t (tab) then assign the array output via set.  
Just testing the first field right now. But it ends up in ES as an empty "" value.  
Is this possible? How do I reference the elements of the array after 'message' is passed to the split processor?

Thanks

{  
"description": "OpenAM Authentication Access Logging",  
"processors": [{  
"set" : {  
"field": "type",  
"value": "amAuthentication.access\_pipeline"  
},  
"split": {  
"field": "message",  
"separator": "\t"  
},  
"set": {  
"field": "openam.data",  
"value": "{{message[1]}}"  
}  
}  
],  
"on\_failure": [  
{  
"set": {  
"field": "error",  
"value": "{{ \_ingest.on\_failure\_message }}"  
}  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [April 28, 2017, 10:39am UTC](https://discuss.elastic.co/t/processor-split-set-array-element/83941/2 "2017-04-28T10:39:18Z")

</div>

For testing/developing an ingest pipeline in Elasticsearch I find the simulate API super helpful: [https://www.elastic.co/guide/en/elasticsearch/reference/current/simulate-pipeline-api.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/simulate-pipeline-api.html)

From Kibana developer console you can test your pipeline via:

```auto
POST _ingest/pipeline/_simulate
{
  "docs": [
    {
      "_source": {
        "message": ...
      }
    },
    ... // more samples
  ],
  "pipeline": {
    "description": "",
    "processors": [
      ...
    ]
  }
}

```

By changing the URL to `_ingest/pipeline/_simulate?verbose` you will get the result for each intermediary processor.

---

<div class="post-metadata">

**Author:** ![Zachary\_Buckholz](https://avatars.discourse-cdn.com/v4/letter/z/f1d935/32.png) [@Zachary\_Buckholz](https://discuss.elastic.co/u/Zachary_Buckholz)\
**Post date:** [April 28, 2017, 1:53pm UTC](https://discuss.elastic.co/t/processor-split-set-array-element/83941/3 "2017-04-28T13:53:14Z")

</div>

Thanks, I missed the verbose option. Going to try that this morning.

Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2017, 1:58pm UTC](https://discuss.elastic.co/t/processor-split-set-array-element/83941/4 "2017-05-26T13:58:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
