# Splitting a string to json like results

**URL:** <https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503>\
**Category:** Logstash\
**Created:** [January 17, 2020, 6:39pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503 "2020-01-17T18:39:33Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Newtoelastic](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@Newtoelastic](https://discuss.elastic.co/u/Newtoelastic)\
**Post date:** [January 17, 2020, 6:39pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/1 "2020-01-17T18:39:33Z")

</div>

Hey there, I have my own logs coming into the logstash that are being created from my python script.

The format for the logs is: %{DATA:Sender}|%{DATA:Recipient}|%{DATA:Subject}|(%{DATA:Links})?$ So far so good.

Problem is I am getting multiple (unknown amount of links) in the last field. I would like to split these links so the end result will look something along the lines of:

links:{  
[http://link1.com](http://link1.com)  
[http://link2.com](http://link2.com)  
[http://link3](http://link3),com  
}

I am really new to Elastic so help is greatly appreciated. I need to know how do I exactly split this field.  
This is top priority for me as tomorrow evening I need to show this to my client

---

<div class="post-metadata">

**Author:** ![Newtoelastic](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@Newtoelastic](https://discuss.elastic.co/u/Newtoelastic)\
**Post date:** [January 17, 2020, 6:58pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/2 "2020-01-17T18:58:56Z")

</div>

I am attempting to use the split method that should in turn split my links to different values but for some reason the links is still arriving as an unknown field and not as a string even though I am mutating it.

What is wrong here?

filter {  
grok {  
match =\> {  
"message" =\> '%{DATA:Sender}|%{DATA:Recipient}|%{DATA:Subject}|(%{DATA:links})?$'  
}   
}  
mutate {  
convert =\> { "links" =\> "string"}  
}  
split{  
field =\> "links"  
terminator =\> "\s"  
}

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 17, 2020, 7:19pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/3 "2020-01-17T19:19:18Z")

</div>

If you use

```
output { stdout { codec => rubydebug } }

```

what does the links field look like?

---

<div class="post-metadata">

**Author:** ![Newtoelastic](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@Newtoelastic](https://discuss.elastic.co/u/Newtoelastic)\
**Post date:** [January 17, 2020, 7:23pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/4 "2020-01-17T19:23:27Z")

</div>

> [@Badger](#):
>
> stdout { codec =\> rubydebug }

Hey there Badger, thank you for the quick reply.

```
 "Recipient" => "something@gmail.com",
   "Subject" => "Bring Your Story to Life as a Creative Writer with These Courses",
  "@version" => "1",
"@timestamp" => 2020-01-17T19:21:33.785Z,
      "host" => {
    "name" => "XXX"
},
      "tags" => [
    [0] "beats_input_codec_plain_applied"
],
     "links" => "https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3Df81e9884ff&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3D4ffcd003e3&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3De55bdb63ec&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3D4c652e0f68&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3D3c72e77f27&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3D4a02f80752&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3D075ecee663&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3Daa90e866d4&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/track/click?u3D820c8324c8d125df5a73a0bb3&id3Dd0bb50405d&e3D50b9b0ed06 https://mailchi.mp/7eb4471c3c7c/good-websites-start-with-the-front-end-1434353?e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/profile?u3D820c8324c8d125df5a73a0bb3&id3D9dafc8b11e&e3D50b9b0ed06 https://stacksocial.us2.list-manage.com/unsubscribe?u3D820c8324c8d125df5a73a0bb3&id3D9dafc8b11e&e3D50b9b0ed06&c3Dc03a8cbf44 $"

```

I am hoping this is what you are reffering to

---

<div class="post-metadata">

**Author:** ![Newtoelastic](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@Newtoelastic](https://discuss.elastic.co/u/Newtoelastic)\
**Post date:** [January 17, 2020, 7:41pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/5 "2020-01-17T19:41:00Z")

</div>

Update:  
So I figured out my problem was with the "\s"  
seems that logstash didn't like it that much. So I replaced it and now I am getting the splitting done right in the CMD but in the Kibana it doesn't show that its being split as it should..  
Any ideas?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be530e7044321df975a86fa20f4dbf50d7e9913e.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/b/cb1bf836805119237dd4262d625d2e29eede7143.png)

I will note that on the Json format it does show right:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/1/0190f1d39ddf288fcffee6a817faed51ad6f2d9e.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 17, 2020, 7:47pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/6 "2020-01-17T19:47:14Z")

</div>

The format is right in logstash and elasticsearch but not in kinana? Is the JSON from the JSON tab in kibana or from elasticsearch?

---

<div class="post-metadata">

**Author:** ![Newtoelastic](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@Newtoelastic](https://discuss.elastic.co/u/Newtoelastic)\
**Post date:** [January 17, 2020, 7:50pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/7 "2020-01-17T19:50:03Z")

</div>

The json is from the Json tab in kibana so it should be sending the json right all the way.  
The problem is the screen pic above it which shows that the field (Which is unknown for some reason) is showing all the data at once and not separated as I thought it will.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 17, 2020, 7:50pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/8 "2020-01-17T19:50:58Z")

</div>

Does refreshing the index in kibana help?

---

<div class="post-metadata">

**Author:** ![Newtoelastic](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@Newtoelastic](https://discuss.elastic.co/u/Newtoelastic)\
**Post date:** [January 17, 2020, 7:56pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/9 "2020-01-17T19:56:00Z")

</div>

Sadly no..  
Now the field is recognized as string but still it shows it all as if its one string and not separate entries

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95e61ad99ea56a7c5bba14182ad054697f398a18.png)

Is my requested output even possible in Kibana?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 17, 2020, 8:03pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/10 "2020-01-17T20:03:40Z")

</div>

Not sure, I do not run kibana. Perhaps ask in the kibana forum.

---

<div class="post-metadata">

**Author:** ![Newtoelastic](https://avatars.discourse-cdn.com/v4/letter/n/8baadc/32.png) [@Newtoelastic](https://discuss.elastic.co/u/Newtoelastic)\
**Post date:** [January 17, 2020, 8:07pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/11 "2020-01-17T20:07:03Z")

</div>

I will. Thanks for that!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2020, 8:07pm UTC](https://discuss.elastic.co/t/splitting-a-string-to-json-like-results/215503/12 "2020-02-14T20:07:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
