# Split Processor:

**URL:** <https://discuss.elastic.co/t/split-processor/168773>\
**Category:** Elasticsearch\
**Created:** [February 18, 2019, 7:28am UTC](https://discuss.elastic.co/t/split-processor/168773 "2019-02-18T07:28:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sharad\_Ananth](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Sharad\_Ananth](https://discuss.elastic.co/u/Sharad_Ananth)\
**Post date:** [February 18, 2019, 7:28am UTC](https://discuss.elastic.co/t/split-processor/168773/1 "2019-02-18T07:28:22Z")

</div>

How do I split a field and put the split strings into multiple target fields using split processor in Elasticsearch ?  
For e.g, I have a logline [https://live-integration-msp-edge.connectcdn.net/mm/dash/live/7047/LIVESERVICE\_7001/TG\_STB\_HD.mpd?antid=VU5LTk9XTi1XSElURUxJU1Q%3D&i=1&ih=in&nwk=WIFI&pk=1&sid=46166966468451548893898&sst=main&uid=299105e2-604a-4306-a46e-5be86b9d684e](https://live-integration-msp-edge.connectcdn.net/mm/dash/live/7047/LIVESERVICE_7001/TG_STB_HD.mpd?antid=VU5LTk9XTi1XSElURUxJU1Q%3D&i=1&ih=in&nwk=WIFI&pk=1&sid=46166966468451548893898&sst=main&uid=299105e2-604a-4306-a46e-5be86b9d684e) http/1.1"" 404 246 404 246 0 0 512 487 614 474 0.093 0.017 DIRECT FIN FIN TCP\_MISS ""MOBI\_EXO2Player;Dalvik/2.1.0 (Linux; U; Android 7.1.2; AFTN Build/NS6258)"" eb89a6d9-2d77-4775-9d42-b7e7d608e615".

I ama using the grok  
"%{IP:source\_ip} %{GREEDYDATA} [%{HTTPDATE:request\_date}] "%{WORD:http\_method} %{URIPROTO:http\_proto}://%{URIHOST:uri\_host}%{URIPATH:uri\_path}%{GREEDYDATA:uri\_query} http/%{NUMBER:http\_version}" %{NUMBER:response\_code} %{NUMBER:bytes\_sent} %{NUMBER:origin\_response\_code} %{NUMBER:origin\_bytes\_sent} %{NUMBER:client\_req\_content\_length} %{NUMBER:proxy\_req\_length} %{NUMBER:client\_req\_header\_length} %{NUMBER:proxy\_resp\_header\_length} %{NUMBER:proxy\_req\_header\_length} %{NUMBER:origin\_header\_resp\_length} %{NUMBER:time\_to\_serve:} %{NUMBER:origin\_time\_to\_serve:} %{WORD:proxy\_hierarchy\_route} %{WORD:finish\_status\_client} %{WORD:finish\_status\_origin} %{WORD:cache\_result\_code} "%{GREEDYDATA:user\_agent}" %{GREEDYDATA:x\_play\_back\_session\_id}"

I want to keep this field as uri\_path and split it into multiple target fields using the separator "/" using split processor.

Here, uri\_path is mm/dash/live/7047/LIVESERVICE\_7001/TG\_STB\_HD.mpd

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [February 18, 2019, 3:49pm UTC](https://discuss.elastic.co/t/split-processor/168773/2 "2019-02-18T15:49:22Z")

</div>

If I understand correctly, your `uri_path` has an internal well defined structure. In this case you could use the [dissect processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/dissect-processor.html) on the URL field, and assign different parts of this field to your additional variables.

---

<div class="post-metadata">

**Author:** ![Sharad\_Ananth](https://avatars.discourse-cdn.com/v4/letter/s/e5b9ba/32.png) [@Sharad\_Ananth](https://discuss.elastic.co/u/Sharad_Ananth)\
**Post date:** [February 19, 2019, 5:02am UTC](https://discuss.elastic.co/t/split-processor/168773/4 "2019-02-19T05:02:59Z")

</div>

@Magnus_Kessler Thank you. It helped.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2019, 5:03am UTC](https://discuss.elastic.co/t/split-processor/168773/5 "2019-03-19T05:03:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
