# Transforming data array to multiple event copies

**URL:** <https://discuss.elastic.co/t/transforming-data-array-to-multiple-event-copies/207929>\
**Category:** Logstash\
**Created:** [November 14, 2019, 3:59pm UTC](https://discuss.elastic.co/t/transforming-data-array-to-multiple-event-copies/207929 "2019-11-14T15:59:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![clasyc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clasyc/32/57703_2.png) [@clasyc](https://discuss.elastic.co/u/clasyc)\
**Post date:** [November 14, 2019, 3:59pm UTC](https://discuss.elastic.co/t/transforming-data-array-to-multiple-event-copies/207929/1 "2019-11-14T15:59:04Z")

</div>

Hello there, I'm new with all elasticsearch stack so it may sound easy and simple task, but I can't find information on how to achieve what I want.

I'm using SQS input to the Logstash and output to the elasticsearch.

So there is an example of what do I expect.

Input:

```
{
     "contacts": ["1", "2", "3", "4"],
     "property": "something",
     "data": "15489",
     "code": "871111"
}

```

Output (4 separate documents with all fields cloned expect "contacts" changes to -\> "contact" per each value in array):

```
{
     "contact": "1",
     "property": "something",
     "data": "15489",
     "code": "871111"
}
{
     "contact": "2",
     "property": "something",
     "data": "15489",
     "code": "871111"
}
{
     "contact": "3",
     "property": "something",
     "data": "15489",
     "code": "871111"
}
{
     "contact": "4",
     "property": "something",
     "data": "15489",
     "code": "871111"
}

```

Any ideas? Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 14, 2019, 5:45pm UTC](https://discuss.elastic.co/t/transforming-data-array-to-multiple-event-copies/207929/2 "2019-11-14T17:45:53Z")

</div>

You can split an array into multiple events using a [split](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html) filter.

---

<div class="post-metadata">

**Author:** ![clasyc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/clasyc/32/57703_2.png) [@clasyc](https://discuss.elastic.co/u/clasyc)\
**Post date:** [November 15, 2019, 7:53am UTC](https://discuss.elastic.co/t/transforming-data-array-to-multiple-event-copies/207929/3 "2019-11-15T07:53:08Z")

</div>

Thanks @Badger!

Yes it worked, should have researched better on this one.

There is a solution:

```
filter {
        split {
                field => "contacts"
                target => "contact"
                remove_field => ["contacts"]
        }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2019, 7:53am UTC](https://discuss.elastic.co/t/transforming-data-array-to-multiple-event-copies/207929/4 "2019-12-13T07:53:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
