# Split filter in Logstash gives NilClass error

**URL:** <https://discuss.elastic.co/t/split-filter-in-logstash-gives-nilclass-error/307498>\
**Category:** Logstash\
**Created:** [June 17, 2022, 10:48am UTC](https://discuss.elastic.co/t/split-filter-in-logstash-gives-nilclass-error/307498 "2022-06-17T10:48:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rick\_V](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rick_v/32/131683_2.png) [@Rick\_V](https://discuss.elastic.co/u/Rick_V)\
**Post date:** [June 17, 2022, 10:48am UTC](https://discuss.elastic.co/t/split-filter-in-logstash-gives-nilclass-error/307498/1 "2022-06-17T10:48:26Z")

</div>

Hello,

I'm trying to split JSON using the split filter in Logstash, but with no success.  
This data is coming straight from an API and then forwarded to the filter in Logstash.  
The structure of the JSON is the following:

```auto
"InfrastructureInfo": {
        "LastAnalyzedOn": "Timestamp"
    },
    "Applications": [
        {
            "GUID": "App_GUID",
            "Name": "App_Name",
            "LevelGUID": "Level_GUID",
            "Findings": [
                {
                    "CategoryGUID": "Cat_ID",
                    "PatternGUID": "Pat_ID",
                    "Count": 1
                }
            ],
            "Modules": [
                {
                    "GUID": "GUID",
                    "Name": "Name",
                    "LevelGUID": "Level_GUID",
                    "Findings": [
                        {
                            "CategoryGUID": "Cat_ID",
                            "PatternGUID": "Pat_ID",
                            "Count": 14
                        },
						{
                            "CategoryGUID": "Cat_ID",
                            "PatternGUID": "Pat_ID",
                            "Count": 13
                        }
                    ]
                },
                {
                    "GUID": "GUID",
                    "Name": "Name",
                    "LevelGUID": "Level_GUID",
                    "Findings": [
                        {
                            "CategoryGUID": "Cat_ID",
                            "PatternGUID": "Pat_ID",
                            "Count": 2
                        }
                    ]
                }
            ]
        },
		{
            "GUID": "Next_App_GUID",
            "Name": "Next_App_Name",
            "LevelGUID": "Next_Level_GUID",
			...
		}
	],
	,
    "Page": {
        "Limit": 200
	}

```

So, the JSON contains multiple Applications, each Application has one or more Modules, and every module has an array of one or more Findings.  
I would like the result to be someting like:

```auto
"Application_name": "App_Name",
"Module_name": "Mod_name",
"Finding_pattern": "Pat_ID"
"Finding_pattern_count": 1

```

Per found pattern in a module in an application.

I've tried about every post on here but can't get my Logstash to work, currently i have this as the Logstash filter configuration:

```auto
filter {
	
	  split { field => "[Applications]" }
	  split { field => "[Applications][Modules][Findings]" }
}

```

But it keeps giving me the message

> Only String and Array types are splittable. field:[Applications][Modules][Findings] is of type = NilClass

Can someone tell me what the issue is?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 17, 2022, 12:39pm UTC](https://discuss.elastic.co/t/split-filter-in-logstash-gives-nilclass-error/307498/2 "2022-06-17T12:39:16Z")

</div>

The field `[Applications][Modules]` is also an array, so `[Applications][Modules][Findings]` do not exist, you need to split in `[Applications][Modules]` before as well.

---

<div class="post-metadata">

**Author:** ![Rick\_V](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rick_v/32/131683_2.png) [@Rick\_V](https://discuss.elastic.co/u/Rick_V)\
**Post date:** [June 20, 2022, 7:41am UTC](https://discuss.elastic.co/t/split-filter-in-logstash-gives-nilclass-error/307498/3 "2022-06-20T07:41:25Z")

</div>

@leandrojmp Thank you very much Leandro! That was the solution

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2022, 7:41am UTC](https://discuss.elastic.co/t/split-filter-in-logstash-gives-nilclass-error/307498/4 "2022-07-18T07:41:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
