# Split Filter Parse Failure

**URL:** https://discuss.elastic.co/t/split-filter-parse-failure/145958
**Category:** Logstash
**Created:** [August 24, 2018, 6:04pm UTC](https://discuss.elastic.co/t/split-filter-parse-failure/145958 "2018-08-24T18:04:32Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Rahul\_Javadekar](https://avatars.discourse-cdn.com/v4/letter/r/7cd45c/32.png) [@Rahul\_Javadekar](https://discuss.elastic.co/u/Rahul_Javadekar)
#### Post date: [August 24, 2018, 6:04pm UTC](https://discuss.elastic.co/t/split-filter-parse-failure/145958/1 "2018-08-24T18:04:32Z")

</div>

Hi, please help with splitting the following JSON at "value":

## {"count":3, "value":[{"id":232, "buildNumber":"20180706.7", "status":"completed"}, {"id":231, "buildNumber":"20180706.6", "status":"completed"}, {"id":229, "buildNumber":"20180706.4", "status":"completed"}]}

My Logstash Config File:

input {  
file {  
path =\> "C:\Users\Rahul J\Downloads\compressed.json"  
codec =\> "plain"  
sincedb\_path =\> "/dev/null"  
start\_position =\> "beginning"  
}

}

filter {  
split {field =\> "[value]"}

mutate {  
add\_field =\> {  
"id" =\> "This is new ID"  
"buildNumber" =\> "This was an experiment"  
"status" =\> "This was an experiment"  
}  
}  
}

## output { elasticsearch { action =\> "index" hosts =\> "localhost:9200" index =\> "rahul" workers =\> 1 } stdout { codec =\> rubydebug } }

Logstash Output:  
[2018-08-24T12:54:43,997][WARN][logstash.filters.split] Only String and Array types are splittable. field:[value] is of type = NilClass  
[2018-08-24T12:54:43,997][WARN][logstash.filters.split] Only String and Array types are splittable. field:[value] is of type = NilClass  
[2018-08-24T12:54:43,998][WARN][logstash.filters.split] Only String and Array types are splittable. field:[value] is of type = NilClass  
[2018-08-24T12:54:44,002][WARN][logstash.filters.split] Only String and Array types are splittable. field:[value] is of type = NilClass  
[2018-08-24T12:54:44,004][WARN][logstash.filters.split] Only String and Array types are splittable. field:[value] is of type = NilClass  
[2018-08-24T12:54:44,005][WARN][logstash.filters.split] Only String and Array types are splittable. field:[value] is of type = NilClass  
{  
"@timestamp" =\> 2018-08-24T17:54:43.842Z,  
"path" =\> "C:\Users\Rahul J\Downloads\compressed.json",  
"buildNumber" =\> "This was an experiment",  
"host" =\> "DESKTOP-9LJJQ4J",  
"message" =\> "{"count":3,\r",  
"tags" =\> [  
[0] "\_split\_type\_failure"  
],  
"@version" =\> "1",  
"status" =\> "This was an experiment",  
"id" =\> "This is new ID"  
}  
{  
"@timestamp" =\> 2018-08-24T17:54:43.879Z,  
"path" =\> "C:\Users\Rahul J\Downloads\compressed.json",  
"buildNumber" =\> "This was an experiment",  
"host" =\> "DESKTOP-9LJJQ4J",  
"message" =\> "\t{"id":229, "buildNumber":"20180706.4", "status":"completed"}\r",  
"tags" =\> [  
[0] "\_split\_type\_failure"  
],  
"@version" =\> "1",  
"status" =\> "This was an experiment",  
"id" =\> "This is new ID"  
}  
{  
"@timestamp" =\> 2018-08-24T17:54:43.879Z,  
"path" =\> "C:\Users\Rahul J\Downloads\compressed.json",  
"buildNumber" =\> "This was an experiment",  
"host" =\> "DESKTOP-9LJJQ4J",  
"message" =\> "\t{"id":231, "buildNumber":"20180706.6", "status":"completed"},\r",  
"tags" =\> [  
[0] "\_split\_type\_failure"  
],  
"@version" =\> "1",  
"status" =\> "This was an experiment",  
"id" =\> "This is new ID"  
}  
{  
"@timestamp" =\> 2018-08-24T17:54:43.877Z,  
"path" =\> "C:\Users\Rahul J\Downloads\compressed.json",  
"buildNumber" =\> "This was an experiment",  
"host" =\> "DESKTOP-9LJJQ4J",  
"message" =\> ""value":[\r",  
"tags" =\> [  
[0] "\_split\_type\_failure"  
],  
"@version" =\> "1",  
"status" =\> "This was an experiment",  
"id" =\> "This is new ID"  
}  
{  
"@timestamp" =\> 2018-08-24T17:54:43.879Z,  
"path" =\> "C:\Users\Rahul J\Downloads\compressed.json",  
"buildNumber" =\> "This was an experiment",  
"host" =\> "DESKTOP-9LJJQ4J",  
"message" =\> "]}\r",  
"tags" =\> [  
[0] "\_split\_type\_failure"  
],  
"@version" =\> "1",  
"status" =\> "This was an experiment",  
"id" =\> "This is new ID"  
}  
{  
"@timestamp" =\> 2018-08-24T17:54:43.878Z,  
"path" =\> "C:\Users\Rahul J\Downloads\compressed.json",  
"buildNumber" =\> "This was an experiment",  
"host" =\> "DESKTOP-9LJJQ4J",  
"message" =\> "\t{"id":232, "buildNumber":"20180706.7", "status":"completed"},\r",  
"tags" =\> [  
[0] "\_split\_type\_failure"  
],  
"@version" =\> "1",  
"status" =\> "This was an experiment",  
"id" =\> "This is new ID"  
}

* * *

I want to split the 'value' field that is a JSON array into multiple JSONs and then parse these individual JSONs to extract the value of keys: ID, buildNumber, status. The outcome will be appended to the event containing explicit id, buildNumber and status fields created by the Mutate filter.

Please guide. Thank you in advance.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 27, 2018, 12:55pm UTC](https://discuss.elastic.co/t/split-filter-parse-failure/145958/2 "2018-08-27T12:55:39Z")

</div>

The split filter fails because none of the events you've listed contains a `value` field. To slurp a multiline JSON file into a single event you need to use a multiline codec (and set its `auto_flush_interval` option to e.g. 5).

> sincedb\_path =\> "/dev/null"

On Windows use "nul", not "/dev/null".

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 24, 2018, 12:55pm UTC](https://discuss.elastic.co/t/split-filter-parse-failure/145958/3 "2018-09-24T12:55:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
