# Separating HTTPJSON array to separate log entries

**URL:** <https://discuss.elastic.co/t/separating-httpjson-array-to-separate-log-entries/297030>\
**Category:** Elasticsearch\
**Created:** [February 12, 2022, 12:07am UTC](https://discuss.elastic.co/t/separating-httpjson-array-to-separate-log-entries/297030 "2022-02-12T00:07:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![isa\_slngr](https://avatars.discourse-cdn.com/v4/letter/i/bcef8e/32.png) [@isa\_slngr](https://discuss.elastic.co/u/isa_slngr)\
**Post date:** [February 12, 2022, 12:07am UTC](https://discuss.elastic.co/t/separating-httpjson-array-to-separate-log-entries/297030/1 "2022-02-12T00:07:28Z")

</div>

Good evening all,

Does anyone in the community know how I can create separate log entries using an ingest pipeline for JSON results pulled via the HTTPJSON integration?

We are pulling events via an API and the results come in JSON format with each event as an item in an array. I would just like to have each event as its own document/log in Elastic. Is this possible?

I came across a video ([here](https://www.youtube.com/watch?v=zjw6bCxG_j4&t=1424s)) that seems to show that is possible but I have only managed to reach the point where I am ingesting the logs and processing the JSON target field I want. However, for each entry that has multiple results in the target field, they are just showing up as comma separated values in the parsed fields. See image for example:

 ![Elastic _JSON_Log_Entry](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a461d50fac4d92be63491299e204799d98dcde24.jpeg)

I just need to have each entry as its own log entry in elastic (with searchable fields) and I'll be set. I would appreciate any help with this. Thanks!

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 12, 2022, 1:37pm UTC](https://discuss.elastic.co/t/separating-httpjson-array-to-separate-log-entries/297030/2 "2022-02-12T13:37:58Z")

</div>

How did you ingest that data to Elasticsearch?

I suppose using Logstash and [Split filter plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html) to split events in array could be a solution.

---

<div class="post-metadata">

**Author:** ![isa\_slngr](https://avatars.discourse-cdn.com/v4/letter/i/bcef8e/32.png) [@isa\_slngr](https://discuss.elastic.co/u/isa_slngr)\
**Post date:** [February 15, 2022, 9:12pm UTC](https://discuss.elastic.co/t/separating-httpjson-array-to-separate-log-entries/297030/3 "2022-02-15T21:12:43Z")

</div>

Good day Tomo! Thanks for responding! Currently the logs in question are being ingested via the HTTPJSON integration on a server running the Elastic agent. We currently don't use logstash since we use the agent for all ingest. I do see a split processor as an option when creating custom ingest pipelines though. Does that serve the same function?

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 16, 2022, 12:37am UTC](https://discuss.elastic.co/t/separating-httpjson-array-to-separate-log-entries/297030/4 "2022-02-16T00:37:33Z")

</div>

Sorry I'm not familiar with Agent yet. But I think so.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2022, 12:38am UTC](https://discuss.elastic.co/t/separating-httpjson-array-to-separate-log-entries/297030/5 "2022-03-16T00:38:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
