# Reindex API for split a field

**URL:** <https://discuss.elastic.co/t/reindex-api-for-split-a-field/274012>\
**Category:** Elasticsearch\
**Tags:** reindex\
**Created:** [May 26, 2021, 6:17am UTC](https://discuss.elastic.co/t/reindex-api-for-split-a-field/274012 "2021-05-26T06:17:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [May 26, 2021, 6:17am UTC](https://discuss.elastic.co/t/reindex-api-for-split-a-field/274012/1 "2021-05-26T06:17:55Z")

</div>

Hi  
I've created an **index template** , and now trying to reindex my logs according to that index template.  
This is a log just for instance:

```auto
  "_score": null,
  "_source": {
    "@timestamp": "2021-05-25T08:38:36",
    "host": "172.18.20.22",
    "Level": "Debug",
    "events": [
      "MessageTemplate": "{TimeoutTransactionLogsCount} transactions have timed-out.",
      "Properties": {
        "MachineName": "Monitoring",
        "Source": "NOC",
        "ProcessName": "LogService",
        "SourceContext": "LogSvc.TimeoutManager",
        "ThreadId": 10,
        "TimeoutTransactionLogsCount": 0
      }],
    "Level": "Debug",
    "Timestamp": "2021-05-25T13:07:40.7495940+04:30"
    },

```

As you see, the `events` field is an array and all content bellow it is [0]  
I want to write a reindex API script to specify the `source` and `dest` and also split the `events` field into **document** not an array. For example this is what I need:

```auto
  "_score": null,
  "_source": {
    "@timestamp": "2021-05-25T08:38:36",
    "host": "172.18.20.22",
    "Level": "Debug",
    "events": {
      "MessageTemplate": "{TimeoutTransactionLogsCount} transactions have timed-out.",
      "Properties": {
        "MachineName": "Monitoring",
        "Source": "NOC",
        "ProcessName": "LogService",
        "SourceContext": "LogSvc.TimeoutManager",
        "ThreadId": 10,
        "TimeoutTransactionLogsCount": 0
      }},
    "Level": "Debug",
    "Timestamp": "2021-05-25T13:07:40.7495940+04:30"
    },

```

How can I write the script in the dev tools?

```auto
POST _reindex
{
  "source": {
    "index":"testlog-2020.05.03"
  },
  "dest": {
    "index": "testlog-2020.05.03-reindexed"
  },
  "script": {
    "lang": "painless", 
    "source": "a script for changing `events` array to document..."
  }
}

```

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [May 26, 2021, 9:55am UTC](https://discuss.elastic.co/t/reindex-api-for-split-a-field/274012/3 "2021-05-26T09:55:13Z")

</div>

The problem solved...

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 26, 2021, 11:12pm UTC](https://discuss.elastic.co/t/reindex-api-for-split-a-field/274012/4 "2021-05-26T23:12:33Z")

</div>

Please share the solution in the thread, it might help someone in future 🙂

---

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [May 30, 2021, 6:29am UTC](https://discuss.elastic.co/t/reindex-api-for-split-a-field/274012/5 "2021-05-30T06:29:15Z")

</div>

Sure

The script will be:

```auto
POST _reindex
{
  "source": {
    "index":"testlog-2020.05.03-new"
  },
  "dest": {
    "index": "testlog-2020.05.03-reindexed"
  },
  "script": {
    "lang": "painless",
    "source": "if (ctx._source.events != null) { ctx._source.events = ctx._source.events[0];}"
  }
}

```

Thank you so much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2021, 6:29am UTC](https://discuss.elastic.co/t/reindex-api-for-split-a-field/274012/6 "2021-06-27T06:29:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
