# Split json object into multiple Events for ES

**URL:** https://discuss.elastic.co/t/split-json-object-into-multiple-events-for-es/204622
**Category:** Logstash
**Created:** [October 22, 2019, 10:03am UTC](https://discuss.elastic.co/t/split-json-object-into-multiple-events-for-es/204622 "2019-10-22T10:03:04Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)
#### Post date: [October 22, 2019, 10:03am UTC](https://discuss.elastic.co/t/split-json-object-into-multiple-events-for-es/204622/1 "2019-10-22T10:03:04Z")

</div>

Hi,

I need to theorise the below as it will take a while to complete through trial and error due to the speed at which these logs are sent from AWS.

Is it possible to split this json object into multiple events using the split filter - and how do I accomplish this? Something like the below:

```
filter {
  if [type] =~ /aws_cloudtrail/ {
      json {
        source => "message"
        target => "event_log"
       }

split {
field => "[event_log][Records]"
     }
  }
}

```

Each time we see the eventID field I want it to be a new event that is parsed into logstash?

```
"event_log": {
     "Records": [
      {
      "eventID": "d5e2af26-a54f-49b3-9389-93b5a5fff7b3",
      "awsRegion": "eu-west-2",
      "eventVersion": "1.05",
      "responseElements": null,
      "sourceIPAddress": "apigateway.amazonaws.com",
      "requestParameters": {
        "logGroupName": "API-Gateway-Execution-Logs_a5tmfqthd6/v1",
        "logStreamName": "xxx"
      },
    {
      "eventID": "ed1e96c2-6ea4-4aa4-9d5a-ecc92efcf372",
      "awsRegion": "eu-west-2",
      "eventVersion": "1.05",
      "responseElements": null,
      "sourceIPAddress": "apigateway.amazonaws.com",
      "requestParameters": {
        "logGroupName": "API-Gateway-Execution-Logs_a5tmfqthd6/v1",
        "logStreamName": "6d3c820e60869c8892d7caa4b72824bf"
      }
   ]
 }
```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [October 22, 2019, 2:32pm UTC](https://discuss.elastic.co/t/split-json-object-into-multiple-events-for-es/204622/2 "2019-10-22T14:32:06Z")

</div>

I would expect that to work.

---

<div class="post-metadata">

### Author: ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)
#### Post date: [October 22, 2019, 2:47pm UTC](https://discuss.elastic.co/t/split-json-object-into-multiple-events-for-es/204622/3 "2019-10-22T14:47:21Z")

</div>

@Badger I kept editing this, and realised eventually I came up with the solution.. Thanks

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 19, 2019, 2:47pm UTC](https://discuss.elastic.co/t/split-json-object-into-multiple-events-for-es/204622/4 "2019-11-19T14:47:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
