# Saving a specific array element in Logstash

**URL:** <https://discuss.elastic.co/t/saving-a-specific-array-element-in-logstash/273556>\
**Category:** Logstash\
**Created:** [May 20, 2021, 2:45pm UTC](https://discuss.elastic.co/t/saving-a-specific-array-element-in-logstash/273556 "2021-05-20T14:45:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tumbledwyer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tumbledwyer/32/89032_2.png) [@tumbledwyer](https://discuss.elastic.co/u/tumbledwyer)\
**Post date:** [May 20, 2021, 2:45pm UTC](https://discuss.elastic.co/t/saving-a-specific-array-element-in-logstash/273556/1 "2021-05-20T14:45:38Z")

</div>

Hi

I am receiving a JSON object with an array property. I would like to search the array and save only the element that matches my criteria. My input looks like this:

```auto
{
  "identifier": [
    { "system" : "Source1", "value" : "TheValueIDontWant"},
    { "system" : "Source2", "value" : "TheValueIWant"}
  ]
}

```

and I would like my output to look like this:

```auto
{
  "SourceID": "TheValueIWant"
}

```

So in this case, I want to search the identifier array for the element which has `Source2` as the system and save its corresponding value to my new property.

Is there a way to do this in Logstash?  
Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 20, 2021, 3:36pm UTC](https://discuss.elastic.co/t/saving-a-specific-array-element-in-logstash/273556/2 "2021-05-20T15:36:49Z")

</div>

You could try something like this (which I have not tested)

```
ruby {
    code => '
        ids = event.get("identifier")
        if ids.is_a? Array
            ids.each { |x|
                if x["system"] == "Source2"
                    event.set("SourceID", x["value"])
                end
            }
        end
    '
}
```

---

<div class="post-metadata">

**Author:** ![tumbledwyer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tumbledwyer/32/89032_2.png) [@tumbledwyer](https://discuss.elastic.co/u/tumbledwyer)\
**Post date:** [May 20, 2021, 4:47pm UTC](https://discuss.elastic.co/t/saving-a-specific-array-element-in-logstash/273556/3 "2021-05-20T16:47:12Z")

</div>

Thank you, that's exactly what I was looking for and the code didn't need any changes. I was battling to find a nice example for using ruby in the .conf and you've just given me one.

I owe you a beer!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2021, 4:47pm UTC](https://discuss.elastic.co/t/saving-a-specific-array-element-in-logstash/273556/4 "2021-06-17T16:47:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
