# Split string into array

**URL:** <https://discuss.elastic.co/t/split-string-into-array/123079>\
**Category:** Logstash\
**Created:** [March 8, 2018, 1:34pm UTC](https://discuss.elastic.co/t/split-string-into-array/123079 "2018-03-08T13:34:03Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lycan](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@Lycan](https://discuss.elastic.co/u/Lycan)\
**Post date:** [March 8, 2018, 1:34pm UTC](https://discuss.elastic.co/t/split-string-into-array/123079/1 "2018-03-08T13:34:03Z")

</div>

Hi.

What I'm trying to do is accessing a nested string in "doc" called "message" (doc.message?), and this string contains a couple of things, including a case specification. That specification is what I am trying to extract and create another object variable under "doc" with (as in "doc.case"). It is not always the same text inside the string of course, but neither is the case always in the same "section" of the string. I have tried to use `split{}`, both within and outside of `mutate{}`, and neither worked. The logfile itself is in xml formatting.

Here is the code:  
`input { beats { port => '5044' } } filter { xml { source => 'message' target => 'doc' } split { field => 'message' } mutate { remove_field => 'message' } } output { elasticsearch { hosts => 'http://localhost:9200' index => 'logfiles' document_type => 'commandusage' } }`

And here is the logfile itself:  
`"doc": { "AppDomain": "DefaultDomain [1]", "Message": """3D	OpenND	Mode: VRT	Images in stack: 211 (max limit: 2000)	Viewport size: (896, 1078)	Date: 20171022 14:13	Session GUID: a3bda1f1-d1f7-4fde-a3f0-7e8a926f9bfc	Server: Local Case:	5b44490f-202a-439f-a7f1-57f2be400ede""", "User": "User123", "Categories": "Cat1, Cat2", "Level": "Info", "Thread": "[1]", "Method": "Method.123", "Host": "Host1", "Time": "2018-03-04T10:10:59.3353115+00:00" },`

(Sorry about the looks, I can't seem to get the editing right)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 8, 2018, 1:48pm UTC](https://discuss.elastic.co/t/split-string-into-array/123079/2 "2018-03-08T13:48:05Z")

</div>

You're probably looking for `split { field => '[doc][message]' }`, see [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references).

---

<div class="post-metadata">

**Author:** ![Lycan](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@Lycan](https://discuss.elastic.co/u/Lycan)\
**Post date:** [March 8, 2018, 1:54pm UTC](https://discuss.elastic.co/t/split-string-into-array/123079/3 "2018-03-08T13:54:02Z")

</div>

Thank you for the quick answer.

Tried it, but it complained about the field being a "NilClass" type, which isn't splittable.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 8, 2018, 2:35pm UTC](https://discuss.elastic.co/t/split-string-into-array/123079/4 "2018-03-08T14:35:01Z")

</div>

That indicates that the field doesn't exist. Dump the raw event with a `stdout { codec => rubydebug }` output.

---

<div class="post-metadata">

**Author:** ![Lycan](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@Lycan](https://discuss.elastic.co/u/Lycan)\
**Post date:** [March 8, 2018, 2:46pm UTC](https://discuss.elastic.co/t/split-string-into-array/123079/5 "2018-03-08T14:46:41Z")

</div>

The field shows up in the dump, and a "\_split\_type\_failure" tag shows up on the files, along with the previous error message.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 8, 2018, 7:19pm UTC](https://discuss.elastic.co/t/split-string-into-array/123079/6 "2018-03-08T19:19:47Z")

</div>

> The field shows up in the dump

Well, please show it to us.

---

<div class="post-metadata">

**Author:** ![Lycan](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@Lycan](https://discuss.elastic.co/u/Lycan)\
**Post date:** [March 9, 2018, 8:10am UTC](https://discuss.elastic.co/t/split-string-into-array/123079/7 "2018-03-09T08:10:14Z")

</div>

Of course.

```
[2018-03-09T09:06:24,055][WARN][logstash.filters.split] Only String and Array types are splittable. field:[_source][doc][Message] is of type = NilClass

```

{  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied",  
[1] "\_split\_type\_failure"  
],  
"beat" =\> {  
"version" =\> "6.2.2",  
"hostname" =\> "LocalPC",  
"name" =\> "LocalPC"  
},  
"prospector" =\> {  
"type" =\> "log"  
},  
"host" =\> "LocalPC",  
"offset" =\> 386,  
"@timestamp" =\> 2018-03-09T08:06:22.293Z,  
"@version" =\> "1",  
"source" =\> "C:\log.slf",  
"doc" =\> {  
"Level" =\> "Info",  
"Host" =\> "Host1",  
"Method" =\> "Company.Utilities.DefaultLogs.CommandUsageLog::Info",  
"User" =\> "User",  
"Categories" =\> "client.performance.commands, common.assembly.utilities",  
"AppDomain" =\> "DefaultDomain [1]",  
"Message" =\> "c6411347-96cf-4330-b3e5-310d523adbba\tSave Image\t3D\tTime (ms):\t20\tCase:\t6e5e2d3a-ce1c-453c-93ff-4e9ce67936fe",  
"Thread" =\> "[1]",  
"Time" =\> "2018-01-16T19:00:24.6785488+00:00"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2018, 8:14am UTC](https://discuss.elastic.co/t/split-string-into-array/123079/8 "2018-03-09T08:14:46Z")

</div>

Field names are case sensitive so use `[doc][Message]`. I missed the uppercase M earlier, sorry.

---

<div class="post-metadata">

**Author:** ![Lycan](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@Lycan](https://discuss.elastic.co/u/Lycan)\
**Post date:** [March 9, 2018, 8:24am UTC](https://discuss.elastic.co/t/split-string-into-array/123079/9 "2018-03-09T08:24:01Z")

</div>

No worries. Despite trying that earlier, this time it worked. It doesn't give any error messages, but neither does it create the `[doc][Case]` I want either, of course. Any thoughts on that?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2018, 9:12am UTC](https://discuss.elastic.co/t/split-string-into-array/123079/10 "2018-03-09T09:12:55Z")

</div>

Splitting doesn't do that for you. I suggest you use a grok or dissect filter to process the string and extract the fields you want.

---

<div class="post-metadata">

**Author:** ![Lycan](https://avatars.discourse-cdn.com/v4/letter/l/7993a0/32.png) [@Lycan](https://discuss.elastic.co/u/Lycan)\
**Post date:** [March 9, 2018, 9:47am UTC](https://discuss.elastic.co/t/split-string-into-array/123079/11 "2018-03-09T09:47:07Z")

</div>

Right, thanks for the help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2018, 9:47am UTC](https://discuss.elastic.co/t/split-string-into-array/123079/12 "2018-04-06T09:47:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
