# Add\_field doesn't work

**URL:** <https://discuss.elastic.co/t/add-field-doesnt-work/149612>\
**Category:** Logstash\
**Created:** [September 24, 2018, 3:26am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612 "2018-09-24T03:26:46Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [September 24, 2018, 3:26am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/1 "2018-09-24T03:26:46Z")

</div>

Dear all,

I install metric beat on a window server to receive log. I tried to combine some of the field using add\_field but it cannot capture the old field value. Any idea?

> if "metricbeat" in [tags]{  
> mutate {  
> add\_field =\> {  
> "process.summary" =\> "%{system.process.username} %{system.process.name} %{system.process.cmdline}"  
> }  
> }  
> }

result

> process.summary %{system.process.username} %{system.process.name} %{system.process.cmdline}

Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2018, 6:21am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/2 "2018-09-24T06:21:08Z")

</div>

I think you are referencing nested fields incorrectly. This should probably be:

```auto
"process.summary" => "%{[system][process][username]} %{[system][process][name]} %{[system][process][cmdline]}"

```

---

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [September 24, 2018, 6:35am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/3 "2018-09-24T06:35:19Z")

</div>

But I really have field name which are "system.process.username", "system.process.name", "system.process.cmdline". And I want to combine these field so I use add\_field

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2018, 6:38am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/4 "2018-09-24T06:38:06Z")

</div>

The fact that the string contains your pattern typically indicates that the field you have specified does not exist or is incorrectly specified. Output the event using a stdout plugin with a rubydebug codec to troubleshoot this. Then you will see exactly what your event looks like.

---

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [September 24, 2018, 6:54am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/5 "2018-09-24T06:54:40Z")

</div>

I tried to use rubydebug codec as output but still fail

> if "metricbeat" in [tags]{  
> stdout { codec =\> rubydebug }  
> elasticsearch {  
> hosts =\> ["1.1.1.1:9200","2.2.2.2:9200"]  
> manage\_template =\> false  
> index =\> "metricbeat-%{+YYYY.MM}"  
> }  
> }

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2018, 6:58am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/6 "2018-09-24T06:58:36Z")

</div>

What does the output to stdout look like?

---

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [September 24, 2018, 7:02am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/7 "2018-09-24T07:02:15Z")

</div>

Here's the sample

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/8/d/8dd930c7946b4c372e2973220708ab186e9973e4.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2018, 7:02am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/8 "2018-09-24T07:02:48Z")

</div>

That is not the output from the stdout plugin. What does a full event look like when you look at it in Kibana?

---

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [September 24, 2018, 7:05am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/9 "2018-09-24T07:05:56Z")

</div>

Do you mean this one?

![Capture2](https://us1.discourse-cdn.com/elastic/original/3X/f/c/fcfbc11bffb337fc41f240fc1f07865861ad964a.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 24, 2018, 7:07am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/10 "2018-09-24T07:07:41Z")

</div>

As you can see your fields are nested. Did you even try the example I provided earlier?

---

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [September 26, 2018, 6:45am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/11 "2018-09-26T06:45:23Z")

</div>

Yes, I have tried but the result still same. May I know if any configuration wrong?

Filter

> if "metricbeat" in [tags]{  
> mutate {  
> add\_field =\> {  
> "process.summary" =\> "{system.process.username} {system.process.name}"  
> }  
> }  
> }

Output

> else if "metricbeat" in [tags]{  
> stdout { codec =\> rubydebug }  
> elasticsearch {  
> hosts =\> ["192.168.6.27:9200","192.168.6.28:9200"]  
> manage\_template =\> false  
> index =\> "metricbeat-%{+YYYY.MM}"  
> }  
> }

Result

 ![Capture3](https://us1.discourse-cdn.com/elastic/original/3X/8/1/81ecfc56d93f9c036fa22d5eb5466edce7a137bc.png)

Json Output

 ![Capture4](https://us1.discourse-cdn.com/elastic/original/3X/4/e/4ec2e8dbad181d8e205faf0da518c2f0eba55d6a.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 26, 2018, 6:54am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/12 "2018-09-26T06:54:00Z")

</div>

> [@peterch](#):
>
> if "metricbeat" in [tags]{  
> mutate {  
> add\_field =\> {  
> "process.summary" =\> "{system.process.username} {system.process.name}"  
> }  
> }  
> }

That is wrong as it is missing `%` ahead of the curly braces and also use the dot notation. Did you try this:

```auto
"process.summary" => "%{[system][process][username]} %{[system][process][name]} %{[system][process][cmdline]}"

```

If you did, please show us the output.

---

<div class="post-metadata">

**Author:** ![peterch](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@peterch](https://discuss.elastic.co/u/peterch)\
**Post date:** [September 26, 2018, 7:39am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/13 "2018-09-26T07:39:07Z")

</div>

I tried to change configuration and it works now. Thanks a lot!!!

![Capture7](https://us1.discourse-cdn.com/elastic/original/3X/5/0/50f1f32c41e63b8c41cfecfebbdb544de494c0f3.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2018, 7:39am UTC](https://discuss.elastic.co/t/add-field-doesnt-work/149612/14 "2018-10-24T07:39:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
