# Split, get the order

**URL:** <https://discuss.elastic.co/t/split-get-the-order/152816>\
**Category:** Logstash\
**Created:** [October 17, 2018, 11:25am UTC](https://discuss.elastic.co/t/split-get-the-order/152816 "2018-10-17T11:25:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![TallGuru](https://avatars.discourse-cdn.com/v4/letter/t/a3d4f5/32.png) [@TallGuru](https://discuss.elastic.co/u/TallGuru)\
**Post date:** [October 17, 2018, 11:25am UTC](https://discuss.elastic.co/t/split-get-the-order/152816/1 "2018-10-17T11:25:32Z")

</div>

Hi

I'm successfully splitting a json with array into several events using "split". What I'm looking for is a way to enumerate the events from the order in the array.

Simplified example of the problem:

Original message:  
{"Messages":[  
"Message":"Hello",  
"Message":"and",  
"Message":"Goodbye"  
]}

What I want:  
{  
"Message": "Hello",  
"MessageNumber": "1"  
}  
{  
"Message": "and",  
"MessageNumber": "2"  
}  
{  
"Message": "Goodbye",  
"MessageNumber": "3"  
}

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [October 17, 2018, 2:37pm UTC](https://discuss.elastic.co/t/split-get-the-order/152816/2 "2018-10-17T14:37:23Z")

</div>

I was a little irritated by your example because the key "Message" is repeated multiple times in the original array, so my test file is a little different. But I guess you'll get the idea and be able to adjust it to fit your actual data. I'm adding the numbers before splitting the event and then I just assign them to the right field afterwards.

```
input {
  stdin{}
}
filter {
  mutate { replace => {"message" => "Hello"}}
  mutate { add_field => {"message" => "and"}}
  mutate { add_field => {"message" => "Goodbye"}}
  # Now my test data is ["Hello","and","Goodbye"]
  ruby {
    code => "
      i = 0
      while i < event.get('message').length do
        event.set('[message]['+i.to_s+']', [i+1,event.get('message')[i]])
        i += 1
      end
    "
  }
  # Now it's [[1,"Hello"],[2,"and"],[3,"Goodbye"]]
  split {
    field => "message"
  }
  # Now there are multiple events with "message" => [2, "and"] etc.
  mutate { copy => {"[message][0]" => "MessageNumber"}}
  mutate { add_field => {"Message" => "%{[message][1]}"} }
  mutate { remove_field => ["message"] }
  # Now everything is where it should be
}
output { stdout { codec => rubydebug } }
```

---

<div class="post-metadata">

**Author:** ![TallGuru](https://avatars.discourse-cdn.com/v4/letter/t/a3d4f5/32.png) [@TallGuru](https://discuss.elastic.co/u/TallGuru)\
**Post date:** [October 17, 2018, 3:24pm UTC](https://discuss.elastic.co/t/split-get-the-order/152816/3 "2018-10-17T15:24:05Z")

</div>

Thanks  
I didn’t really understand the _i.to\_s_ but will try it tomorrow.  
Sorry about the Json-missmatch, can be when I tried to simplify the complex original data to an example.  
/Karl

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [October 18, 2018, 9:08am UTC](https://discuss.elastic.co/t/split-get-the-order/152816/4 "2018-10-18T09:08:44Z")

</div>

I was just trying to create the keys "[message][0]", "[message][1]", etc. there by concatenation. Ruby likes to complain about type conversions, so I had to do an explicit conversion from Integer to String to include my counter variable.

---

<div class="post-metadata">

**Author:** ![TallGuru](https://avatars.discourse-cdn.com/v4/letter/t/a3d4f5/32.png) [@TallGuru](https://discuss.elastic.co/u/TallGuru)\
**Post date:** [October 18, 2018, 11:15am UTC](https://discuss.elastic.co/t/split-get-the-order/152816/5 "2018-10-18T11:15:44Z")

</div>

New to Ruby so the syntax were a bit confusing, now I understand the formula and it seems to work.

Thank you for helping  
/Karl

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2018, 11:15am UTC](https://discuss.elastic.co/t/split-get-the-order/152816/6 "2018-11-15T11:15:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
