Hello
I would to like to know why my "add_field" option doesn"t replace my "NEWFIELD" field ? :
if ([ID2] == "000003")
{
grok
{
match => { "DESCRIPTION" => [ "%{DATA:TEST}/%{WORD:NOM_BATCH}-%{BASE16NUM:DATE_BATCH}-%{GREEDYDATA:RESTE}" ] }
}
mutate
{
copy => { "DATE_BATCH" => "ESSAI" }
#DATE_BATCH is correctly copied because ESSAI = DATE_BATCH
}
}
else
{
mutate
{
add_field => { "NEWFIELD" => "%{[ESSAI]}" }
}
}
When I go to see my "NEWFIELD" field in Kibana :
... NEWFIELD = %{[ESSAI]}
Why it isn't replaced ??
Thx