# Split not working as expected

**URL:** <https://discuss.elastic.co/t/split-not-working-as-expected/179373>\
**Category:** Logstash\
**Created:** [May 2, 2019, 1:29pm UTC](https://discuss.elastic.co/t/split-not-working-as-expected/179373 "2019-05-02T13:29:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ghost3h](https://avatars.discourse-cdn.com/v4/letter/g/bc8723/32.png) [@ghost3h](https://discuss.elastic.co/u/ghost3h)\
**Post date:** [May 2, 2019, 1:29pm UTC](https://discuss.elastic.co/t/split-not-working-as-expected/179373/1 "2019-05-02T13:29:49Z")

</div>

Hi All,

I'm having a issue with my split on a field that is comma deliminated. I've got the syntax for what I want from previous questions, but the output is not as I expected. I have seen different syntax used on the split / reference, so tried both and neither work. I have the alternative syntax commented out for example

My data is:

> HOSTALIAS:/subscriptions/41561-sadd-asdasd/resourceGroups/somethinghere/providers/Microsoft.Compute/virtualMachines/Somethinghere, DEMO Workload, UKblah123

mutate {  
split =\> ["HOSTALIAS", ", "]  
#split =\> {"HOSTALIAS" =\> ", " }

```
    add_field => {"ci_alias" => "%{HOSTALIAS[0]}"}
    add_field => {"blueprint-id" => "%{HOSTALIAS[1]}"}
    add_field => {"instance-id" => "%{HOSTALIAS[2]}"}

   # add_field => {"ci_alias" => "%{[HOSTALIAS][0]}"}
   # add_field => {"blueprint-id" => "%{[HOSTALIAS][1]}"}
   # add_field => {"instance-id" => "%{[HOSTALIAS][2]}"}

    }

```

The results are:

> "ci\_alias" =\> "/subscriptions/41561-sadd-asdasd/resourceGroups/somethinghere/providers/Microsoft.Compute/virtualMachines/Somethinghere,",  
> "blueprint-id" =\> "%{HOSTALIAS[1]}",  
> "instance-id" =\> "%{HOSTALIAS[2]}"

I've tried splitting on just "," and ", " and neither seem to work. What am I doing wrong?  
Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 2, 2019, 6:15pm UTC](https://discuss.elastic.co/t/split-not-working-as-expected/179373/2 "2019-05-02T18:15:21Z")

</div>

Not sure. This works just fine for me...

```
input { generator { count => 1 message => '' } }

filter {
    mutate { add_field => { "HOSTALIAS" => "/subscriptions/41561-sadd-asdasd/resourceGroups/somethinghere/providers/Microsoft.Compute/virtualMachines/Somethinghere, DEMO Workload, UKblah123" } }
    mutate {
        split => { "HOSTALIAS" => ", " }
        add_field => { "ci_alias" => "%{[HOSTALIAS][0]}" "blueprint-id" => "%{[HOSTALIAS][1]}" "instance-id" => "%{[HOSTALIAS][2]}" }
    }
}

```

That gets me

```
   "HOSTALIAS" => [
    [0] "/subscriptions/41561-sadd-asdasd/resourceGroups/somethinghere/providers/Microsoft.Compute/virtualMachines/Somethinghere",
    [1] "DEMO Workload",
    [2] "UKblah123"
],
"blueprint-id" => "DEMO Workload",
 "instance-id" => "UKblah123",
    "ci_alias" => "/subscriptions/41561-sadd-asdasd/resourceGroups/somethinghere/providers/Microsoft.Compute/virtualMachines/Somethinghere",
```

---

<div class="post-metadata">

**Author:** ![ghost3h](https://avatars.discourse-cdn.com/v4/letter/g/bc8723/32.png) [@ghost3h](https://discuss.elastic.co/u/ghost3h)\
**Post date:** [May 3, 2019, 12:05pm UTC](https://discuss.elastic.co/t/split-not-working-as-expected/179373/3 "2019-05-03T12:05:00Z")

</div>

So I tested it the same way as you, and it works ( bu defining my own value). So its something wrong with my kv filtering.

I'm very new to logstash filters, is there any online testing tools where I can very quickly make changes and see what results come out? I'm currently using stdout which is quick(ish) but a online tool would be ideal

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 3, 2019, 12:35pm UTC](https://discuss.elastic.co/t/split-not-working-as-expected/179373/4 "2019-05-03T12:35:42Z")

</div>

I use 2 windows. In one I edit a configuration file, in the other I run logstash with -r, so that it reloads the configuration every time I tell the editor to write out the file. This avoids the (very large) overhead of restarting logstash for every configuration change.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2019, 12:35pm UTC](https://discuss.elastic.co/t/split-not-working-as-expected/179373/5 "2019-05-31T12:35:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
