# Split a doc to multiple docs

**URL:** <https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531>\
**Category:** Logstash\
**Created:** [January 27, 2022, 1:15am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531 "2022-01-27T01:15:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris/32/101855_2.png) [@cris](https://discuss.elastic.co/u/cris)\
**Post date:** [January 27, 2022, 1:15am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531/1 "2022-01-27T01:15:25Z")

</div>

Hello friends. I am trying to reindex some data to another index but with a little differences.  
In the first index I have this kind of hit:

```auto
{
  "ENVA": {
    "Login": {
      "status": "passed"
    }
  },
  "ENVB": {
    "Login": {
      "status": "passed"
    }
  },
  "ENVC": {
    "Login": {
      "status": "passed"
    }
  },
  "ENVD": {
    "Login": {
      "status": "failed"
    }
  }
}

```

So I want to split each Env in other doc each one some like this:  
This is a hit with **ENVA** info:

```auto
{
  "ENV": {
    "Login": {
      "status": "passed"
    }
  }
}

```

This is a another with **ENVB** info:

```auto
{
  "ENV": {
    "Login": {
      "status": "passed"
    }
  }
}

```

So I was doing this with logstash but I failed because I get this error:  
` Only String and Array types are splittable. field:Login is of type = NilClass`  
This is my logstash configuration I do not know how I can split this doc in multiple docs:

```auto

input {
  elasticsearch {
    hosts => "localhost:9200"
    index => "logs-testing"
    size => 500
    scroll => "5m"
    docinfo => true 
  }
}
filter {
  split {
   field => "Login"
 }
}

output {

  elasticsearch {
    hosts => "localhost:9200"
    index => "logs-version2Testing"
    document_id => "%{[@metadata][_id]}"

  }

}

```

Please help I tried with multiple ways but I can not got it

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 27, 2022, 1:36am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531/2 "2022-01-27T01:36:52Z")

</div>

> [@cris](#):
>
> ```auto
> {
> "ENV": {
> "Login": {
> "status": "passed"
> }
> }
> }
> 
> ```

How are you going to know whether that is ENVA/ENVB/ENVC/ENVD?

---

<div class="post-metadata">

**Author:** ![cris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris/32/101855_2.png) [@cris](https://discuss.elastic.co/u/cris)\
**Post date:** [January 27, 2022, 1:45am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531/3 "2022-01-27T01:45:35Z")

</div>

I am only want to set it in only a field in this case "ENV", because I want to do a pie chart with the values, if is ENVA, ENVB, etc. could be ignored

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 27, 2022, 3:02am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531/4 "2022-01-27T03:02:28Z")

</div>

OK, so you have a hash with several key/value pairs, and all the values have the same structure, and you do not care about the keys. You did not mention what the name of the hash is. I would try something like

```
ruby {
    code => '
        f = event.get("someField") # Get the hash
        if f.is_a? Hash
            newF = []
            f.each { |k, v|
                newF << { "ENV": k }
            }
            event.set("someField", newF)
        end                    
    '
}
split { field => "someField" }
```

---

<div class="post-metadata">

**Author:** ![cris](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris/32/101855_2.png) [@cris](https://discuss.elastic.co/u/cris)\
**Post date:** [January 27, 2022, 3:44am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531/5 "2022-01-27T03:44:02Z")

</div>

A lot of thanks. Sorry what is the name of the hash?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 27, 2022, 3:51am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531/6 "2022-01-27T03:51:28Z")

</div>

> [@cris](#):
>
> Sorry what is the name of the hash?

You have to tell me that.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [January 27, 2022, 4:41am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531/7 "2022-01-27T04:41:44Z")

</div>

A little supplement. If ENVXs are top-level fields, use `event.to_hash` instead of `event.get("someField")` and add some filtering of its keys.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2022, 4:42am UTC](https://discuss.elastic.co/t/split-a-doc-to-multiple-docs/295531/8 "2022-02-24T04:42:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
