# Add custom field for all records with a logged value

**URL:** <https://discuss.elastic.co/t/add-custom-field-for-all-records-with-a-logged-value/43122>\
**Category:** Logstash\
**Created:** [March 1, 2016, 1:33pm UTC](https://discuss.elastic.co/t/add-custom-field-for-all-records-with-a-logged-value/43122 "2016-03-01T13:33:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dmitry\_Reshetnik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmitry_reshetnik/32/88780_2.png) [@Dmitry\_Reshetnik](https://discuss.elastic.co/u/Dmitry_Reshetnik)\
**Post date:** [March 1, 2016, 1:33pm UTC](https://discuss.elastic.co/t/add-custom-field-for-all-records-with-a-logged-value/43122/1 "2016-03-01T13:33:08Z")

</div>

In my log file there is a line with "hash: "  
I need to parse this value and set to all records in this file (at least for all those which go right after this record).

> 01/03/2016: log init  
> 01/03/2016: hash = 452345  
> 01/03/2016: hello  
> 01/03/2016: from  
> 01/03/2016: logs

and this should be parsed to the:

> {  
> "title": log init",  
> "hash": "452345"  
> }  
> {  
> "title": hash = 452345",  
> "hash": "452345"  
> }  
> {  
> "title": hello",  
> "hash": "452345"  
> }  
> {  
> "title": "from",  
> "hash": "452345"  
> }  
> {  
> "title": "logs",  
> "hash": "452345"  
> }

at least that would be great to add this hash to all records after "hash = ..."

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/add-custom-field-for-all-records-with-a-logged-value/43122/2 "2017-07-06T05:09:07Z")

</div>


