# Add field from JSON / logstash filter

**URL:** <https://discuss.elastic.co/t/add-field-from-json-logstash-filter/69364>\
**Category:** Logstash\
**Created:** [December 18, 2016, 6:02pm UTC](https://discuss.elastic.co/t/add-field-from-json-logstash-filter/69364 "2016-12-18T18:02:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Makra](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@Makra](https://discuss.elastic.co/u/Makra)\
**Post date:** [December 18, 2016, 6:02pm UTC](https://discuss.elastic.co/t/add-field-from-json-logstash-filter/69364/1 "2016-12-18T18:02:42Z")

</div>

Hi  
I am trying to add a filed from the parsed JSON, but the logstash filter does not add the value of the filed, instead it just add the whole string from the add field section.

## test.conf

input {  
stdin { codec =\> json }

}

filter {  
json {  
source =\> "message"  
target =\> "parsedjson"  
}  
mutate {  
add\_field =\>  
{  
"Source\_IP" =\> "%{[parsedjson][SOURCEIP]}"  
# This source IP , i want add  
}  
}  
}

output { stdout { codec =\> rubydebug } }

The config test of the above-

$ echo '{ "\_index": "syslog-all-rq-2016.12.17", "\_type": "syslog-all", "\_id": "AVkNjl7jus\_W3GFgAZNi", "\_score": null, "\_source": { "TAGS": ".source.syslog\_tcp", "SOURCEIP": "172.19.10.220", "PROGRAM": "369", "PRIORITY": "notice", "MESSAGE": "\<14\>1 2016-12-17T17:12:29+01:00 TirougaII WinFileService - - [synolog@6574 synotype="WinFileService" ip="172.19.10.225" luser="pc" event="read" isdir="File" fsize="6.00 KB" fname="/DATA/800 ProductionTST/Thumbs.db"][meta sequenceId="62"] Event: read, Path: /DATA01/SOC/800 ProductionTST/Thumbs.db, File/Folder: File, Size: 6.00 KB, User: dtu, IP: 172.18.9.251", "LEGACY\_MSGHDR": "369 ", "HOST\_FROM": "172.19.10.220", "HOST": "172.19.10.220", "FACILITY": "user", "DATE": "Dec 17 17:12:29", "@version": "1", "@timestamp": "2016-12-17T16:12:29.507Z", "host": "127.0.0.1", "port": 35186, "type": "syslog-all", "tags": ["Syslog-All"] }, "fields": { "@timestamp": [1481991149507] }, "sort": [1481991149507] }' | /opt/logstash/bin/logstash -f test.conf  
Settings: Default pipeline workers: 2  
Pipeline main started  
{  
"\_index" =\> "syslog-all-rq-2016.12.17",  
"\_type" =\> "syslog-all",  
"\_id" =\> "AVkNjl7jus\_W3GFgAZNi",  
"\_score" =\> nil,  
"\_source" =\> {  
"TAGS" =\> ".source.syslog\_tcp",  
"SOURCEIP" =\> "172.19.10.220",  
"PROGRAM" =\> "369",  
"PRIORITY" =\> "notice",  
"MESSAGE" =\> "\<14\>1 2016-12-17T17:12:29+01:00 TirougaII WinFileService - - [synolog@6574 synotype="WinFileService" ip="172.19.10.225" luser="pc" event="read" isdir="File" fsize="6.00 KB" fname="/DATA/800 ProductionTST/Thumbs.db"][meta sequenceId="62"] Event: read, Path: /DATA01/SOC/800 ProductionTST/Thumbs.db, File/Folder: File, Size: 6.00 KB, User: dtu, IP: 172.18.9.251",  
"LEGACY\_MSGHDR" =\> "369 ",  
"HOST\_FROM" =\> "172.19.10.220",  
"HOST" =\> "172.19.10.220",  
"FACILITY" =\> "user",  
"DATE" =\> "Dec 17 17:12:29",  
"@version" =\> "1",  
"@timestamp" =\> "2016-12-17T16:12:29.507Z",  
"host" =\> "127.0.0.1",  
"port" =\> 35186,  
"type" =\> "syslog-all",  
"tags" =\> [  
[0] "Syslog-All"  
]  
},  
"fields" =\> {  
"@timestamp" =\> [  
[0] 1481991149507  
]  
},  
"sort" =\> [  
[0] 1481991149507  
],  
"@version" =\> "1",  
"@timestamp" =\> "2016-12-18T17:50:14.713Z",  
"host" =\> "pc-virtual-machine",  
**"Source\_IP" =\> "%{[parsedjson][SOURCEIP]}"**

}  
Pipeline main has been shutdown  
stopping pipeline {:id=\>"main"}

The value of source ip is not added instead all the parameters name in add\_filed has been added.

Like to know from the experts what am i doing wrong ?

Thanks

---

<div class="post-metadata">

**Author:** ![Makra](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@Makra](https://discuss.elastic.co/u/Makra)\
**Post date:** [December 18, 2016, 6:17pm UTC](https://discuss.elastic.co/t/add-field-from-json-logstash-filter/69364/2 "2016-12-18T18:17:15Z")

</div>

Hi  
The problem is here  
add\_field =\>  
{  
"Source\_IP" =\> "%{[\_source][SOURCEIP]}"  
}

I have overlooked the JSON structure, added the \_source array name and source ip is being added now.

---

<div class="post-metadata">

**Author:** ![Troy\_Axthelm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/troy_axthelm/32/18347_2.png) [@Troy\_Axthelm](https://discuss.elastic.co/u/Troy_Axthelm)\
**Post date:** [December 18, 2016, 6:21pm UTC](https://discuss.elastic.co/t/add-field-from-json-logstash-filter/69364/3 "2016-12-18T18:21:25Z")

</div>

Awesome, glad you figured it out Makra. I was just setting up a test instance in hopes of helping you.

Would you please add an update in our other post as well.

Best of luck on your ELK stack journey!

---

<div class="post-metadata">

**Author:** ![Makra](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@Makra](https://discuss.elastic.co/u/Makra)\
**Post date:** [December 18, 2016, 6:26pm UTC](https://discuss.elastic.co/t/add-field-from-json-logstash-filter/69364/4 "2016-12-18T18:26:02Z")

</div>

Hi  
Troy,  
Now the elastic search indexes are generated based on the IP. I will update the other post as well.  
Thanks for your valuable suggestions and time.😌

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2017, 6:26pm UTC](https://discuss.elastic.co/t/add-field-from-json-logstash-filter/69364/5 "2017-01-15T18:26:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
