# Split on multiple fields logstash. Is it possible?

**URL:** <https://discuss.elastic.co/t/split-on-multiple-fields-logstash-is-it-possible/2428>\
**Category:** Logstash\
**Created:** [June 11, 2015, 9:23am UTC](https://discuss.elastic.co/t/split-on-multiple-fields-logstash-is-it-possible/2428 "2015-06-11T09:23:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Post date:** [June 11, 2015, 9:23am UTC](https://discuss.elastic.co/t/split-on-multiple-fields-logstash-is-it-possible/2428/1 "2015-06-11T09:23:51Z")

</div>

Fields are like:  
Time\_FV: [0, 200,300,400]  
Progess\_FV: [10, 20,30,40]

Time\_RV: [0, 200,300,400, 500]  
Progess\_RV: [10, 20,30,40, 90]

Can I use split {} for multiple fields? if not any possible way out.  
split { field =\> "Time\_FV" }  
split { field =\> "Progess\_FV" }  
split { field =\> "Time\_RV" }  
split { field =\> "Progess\_FV" }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2015, 10:24am UTC](https://discuss.elastic.co/t/split-on-multiple-fields-logstash-is-it-possible/2428/2 "2015-06-11T10:24:33Z")

</div>

Do you mean that you want the first value of Time\_FV, Progress\_FV, Time\_RV, and Progress\_RV to be split into one message, the second value of each list to become a second message, and so on? That's probably not possible.

---

<div class="post-metadata">

**Author:** ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Post date:** [June 11, 2015, 10:26am UTC](https://discuss.elastic.co/t/split-on-multiple-fields-logstash-is-it-possible/2428/3 "2015-06-11T10:26:14Z")

</div>

yes exactly! is there any workaround or other way to achieve that...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2015, 12:03pm UTC](https://discuss.elastic.co/t/split-on-multiple-fields-logstash-is-it-possible/2428/4 "2015-06-11T12:03:45Z")

</div>

You'll probably have to write a custom plugin.

---

<div class="post-metadata">

**Author:** ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)\
**Post date:** [June 11, 2015, 12:06pm UTC](https://discuss.elastic.co/t/split-on-multiple-fields-logstash-is-it-possible/2428/5 "2015-06-11T12:06:12Z")

</div>

I just read about Clone{} and also saw one example to split array without target....

> [@How to split array without a target?](https://discuss.elastic.co/t/how-to-split-array-without-a-target/1590):
>
> Hi, I'm trying to split a JSON array into multiple events. Here's a sample input: {"results" : [{"id": "a1", "name": "hello"}, {"id": "a2", "name": "logstash"}]} Here's my filter and output config: filter { split { field =\> "results" } } stdout { codec =\> "rubydebug" } This produces close to what I'm looking for: { "results" =\> { "id" =\> "a1", "name" =\> "hello…

do you think it would be helpful for my problem statement?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:37am UTC](https://discuss.elastic.co/t/split-on-multiple-fields-logstash-is-it-possible/2428/6 "2017-07-06T05:37:42Z")

</div>


