# Split json array and apply filter

**URL:** https://discuss.elastic.co/t/split-json-array-and-apply-filter/1064
**Category:** Logstash
**Created:** [May 21, 2015, 7:56am UTC](https://discuss.elastic.co/t/split-json-array-and-apply-filter/1064 "2015-05-21T07:56:58Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![michaelT](https://avatars.discourse-cdn.com/v4/letter/m/91b2a8/32.png) [@michaelT](https://discuss.elastic.co/u/michaelT)
#### Post date: [May 21, 2015, 7:56am UTC](https://discuss.elastic.co/t/split-json-array-and-apply-filter/1064/1 "2015-05-21T07:56:58Z")

</div>

Hi,

I'm retrieving a Json Array as Input and would like to know how it would be possible to split it using the split filter in order to send each new item as a single output ?  
In addition, the other filters should be applied to the new event raised, would it be possible to do it only by properly ordering the filter block ?

Example : Assuming I have the following input :

> { "results" : [  
> {"res1" : { "min": 1, "max": 2}},  
> {"res2" : { "min": 0, "max": 8}},  
> {"res3" : { "min": 4, "max": 6}},  
> {"res4" : { "min": 6, "max": 9}}  
> ] }

The goal would be to split the results array into single output. But before that I would like to add to each resX a new filed (e.g. timestamp) using mutate and add\_filed filters.

Apparently the pull request [logstash-filter-split](https://github.com/logstash-plugins/logstash-filter-split/pull/1), should enable split of array but I didn't found the syntax to make it work. Also as described in the [issue 2131](https://github.com/elastic/logstash/issues/2131), the workaround is to use a ruby filter works but in this case the other filter are not applied to the split items.

---

<div class="post-metadata">

### Author: ![michaelT](https://avatars.discourse-cdn.com/v4/letter/m/91b2a8/32.png) [@michaelT](https://discuss.elastic.co/u/michaelT)
#### Post date: [May 21, 2015, 1:40pm UTC](https://discuss.elastic.co/t/split-json-array-and-apply-filter/1064/2 "2015-05-21T13:40:35Z")

</div>

found the solution :

- using the split plugin to split the array :

> split {  
> field =\> "results"  
> }

- with the newly released 1.5.0, the filter are automatically applied to the split item automatically (wether this is due to filter order or internal filtering schedule, I don't know)

---

<div class="post-metadata">

### Author: ![aiden](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@aiden](https://discuss.elastic.co/u/aiden)
#### Post date: [May 30, 2015, 6:12am UTC](https://discuss.elastic.co/t/split-json-array-and-apply-filter/1064/3 "2015-05-30T06:12:16Z")

</div>

Michael, thanks for the answer! I'm experiencing the same problem. Can you please clarify the second point?

> [@michaelT](#):
>
> with the newly released 1.5.0, the filter are automatically applied to the split item automatically (wether this is due to filter order or internal filtering schedule, I don't know)

What do you mean by "the filter are automatically applied to the split item automatically"?  
Which filters, exactly, are applied to the split item automatically?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/split-json-array-and-apply-filter/1064/4 "2017-07-06T05:39:01Z")

</div>


