# Split json fields of similar type in logstash

**URL:** <https://discuss.elastic.co/t/split-json-fields-of-similar-type-in-logstash/300133>\
**Category:** Logstash\
**Created:** [March 20, 2022, 1:26pm UTC](https://discuss.elastic.co/t/split-json-fields-of-similar-type-in-logstash/300133 "2022-03-20T13:26:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zubair\_aftab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zubair_aftab/32/103257_2.png) [@zubair\_aftab](https://discuss.elastic.co/u/zubair_aftab)\
**Post date:** [March 20, 2022, 1:26pm UTC](https://discuss.elastic.co/t/split-json-fields-of-similar-type-in-logstash/300133/1 "2022-03-20T13:26:31Z")

</div>

I have a json file converted from pcap using tshark. There are different layers inside the json and each layer has different fields. Some fields are repeating inside the same message for example "bicc\_bicc\_cic" as shown below.  
How i can separate them as unique so that i can search for the values in discover??

```
"layers":{
"bicc":[{
		"bicc_bicc_cic":"22240",
		"bicc_bicc_cic":"22763",
		"bicc_bicc_cic":"90"

```

i tried ruby code but it is not working

\<  
ruby {  
code =\> '  
val\_a = []  
event.get("[layers][bicc][bicc\_bicc\_cic]").each { |k, v|  
v["temp"] = k  
val\_a \<\< v  
}  
event.set("val\_a", val\_a)  
'  
}  
if [val\_a] {  
split {  
field =\> "val\_a"  
}

>

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 20, 2022, 1:48pm UTC](https://discuss.elastic.co/t/split-json-fields-of-similar-type-in-logstash/300133/2 "2022-03-20T13:48:40Z")

</div>

> [@zubair\_aftab](#):
>
> event.get("[layers][bicc][bicc\_bicc\_cic]").each

That should be `event.get("[layers][bicc][0]").each`. However, I do not think this will work.

JSON allows duplicate keys, although it is recommended not to do that. In both Java and Ruby the JSON will be parsed into a hash, and the duplicate keys will overwrite oneanother in the json codec/filter before it gets to the ruby filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2022, 1:48pm UTC](https://discuss.elastic.co/t/split-json-fields-of-similar-type-in-logstash/300133/3 "2022-04-17T13:48:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
