# Add field not fetching the value from target, instead printing as a string

**URL:** <https://discuss.elastic.co/t/add-field-not-fetching-the-value-from-target-instead-printing-as-a-string/87209>\
**Category:** Logstash\
**Created:** [May 26, 2017, 7:00am UTC](https://discuss.elastic.co/t/add-field-not-fetching-the-value-from-target-instead-printing-as-a-string/87209 "2017-05-26T07:00:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gopi\_K1](https://avatars.discourse-cdn.com/v4/letter/g/9e8a1a/32.png) [@Gopi\_K1](https://discuss.elastic.co/u/Gopi_K1)\
**Post date:** [May 26, 2017, 7:00am UTC](https://discuss.elastic.co/t/add-field-not-fetching-the-value-from-target-instead-printing-as-a-string/87209/1 "2017-05-26T07:00:34Z")

</div>

my conf:

[root@ci-000c294400e8 conf.d]# cat sample\_test.conf  
input  
{  
file  
{  
codec =\> multiline  
{  
pattern =\> '^\s\s\s\s}'  
negate =\> true  
what =\> previous  
max\_lines =\> 20000  
}

```
    path => ["/ci/data/cirrus/report/*/status.json"]
    start_position => "beginning"
    sincedb_path => "/ci/data/cirrus/sincedb_path/status.db"
    ignore_older => 0
    type => 'test'
}

```

}  
#Filter plugin performs intermediary processing on an event using "Ruby code" as filter plugin  
filter  
{  
if [type] == "test"  
{  
grok  
{  
match =\> ["message", "%{GREEDYDATA:msg}"]  
}  
if "\_jsonparsefailure" in [tags]  
{  
drop{}  
}  
ruby  
{  
code =\> "  
filename = event['path'].split('/')[5];  
event['jobID'] = filename  
"  
}  
mutate  
{  
gsub =\> ["message", "\n", ""]  
gsub =\> ["message", "\s", ""]  
}  
json  
{  
source =\> "message"  
target =\> "doc"  
}  
mutate  
{  
add\_field =\>{ "status" =\> "%{[doc][status]}" }  
#remove\_field =\> ["msg", "message","results"]  
}  
}  
}  
#output  
output {  
if [type] == "test"  
{  
stdout  
{  
codec =\> rubydebug  
}  
#elasticsearch

# {

```
      # hosts => "localhost:9200"
      # index => "cirrus"
      # document_type => "testinfo"
      # document_id => '{"jobID":"%{jobID}"}'

```

# }

```
}

```

}

my json:  
{  
"status": "fail",  
"time\_start": 1494320678.8123009,  
"agent\_pid": 26286,  
"cirrus\_id": "ci-000c294400e8\_administrator\_1",  
"time\_queued": 1494320660.5887389,  
"time\_end": 1494320700.427644,  
"message": "1 stage(s) failed",  
"stages": {  
"RoboGalaxy": {  
"status": "fail",  
"code": 2,  
"time\_start": 1494320683.109,  
"signal": 0,  
"time\_end": 1494320695.464,  
"message": "2 RG tests failed, only first failure shown -- fail: Setup failed:\nKeyError: u'sys\_os', Test: UC1 GirishRun:ILOREST Testing; "  
}  
}  
}

after running the conf file:

OUPTUT:

{  
"@timestamp" =\> "2017-05-26T07:33:10.730Z",  
"message" =\> "{"status":"fail","time\_start":1494916910.0355501,"agent\_pid":22528,"cirrus\_id":"ci-000c294400e8\_administrator\_4","time\_queued":1494916894.9371409,"time\_end":1494916943.763562,"message":"1stage(s)failed","stages":{"copyspplogs":{"status":"pass","code":0,"time\_start":1494916930.109,"signal":0,"time\_end":1494916933.26,"message":""},"notify":{"status":"pass","code":0,"time\_start":1494916940.508316,"signal":0,"time\_end":1494916943.763181,"message":""},"RoboGalaxy":{"status":"fail","code":1,"time\_start":1494916912.109,"signal":0,"time\_end":1494916924.76,"message":"1RGtestfailed--fail:Setupfailed:\nKeyError:u'sys\_os',Test:UC9RemoteScripted:ILORESTTesting;"}",  
"@version" =\> "1",  
"tags" =\> [  
[0] "multiline",  
[1] "\_jsonparsefailure"  
],  
"path" =\> "/ci/data/cirrus/report/ci-000c294400e8\_administrator\_4/status.json",  
"host" =\> "ci-000c294400e8",  
"type" =\> "test",  
"msg" =\> "{\n "status": "fail", \n "time\_start": 1494916910.0355501, \n "agent\_pid": 22528, \n "cirrus\_id": "ci-000c294400e8\_administrator\_4", \n "time\_queued": 1494916894.9371409, \n "time\_end": 1494916943.763562, \n "message": "1 stage(s) failed", \n "stages": {\n "copy spp logs": {\n "status": "pass", \n "code": 0, \n "time\_start": 1494916930.109, \n "signal": 0, \n "time\_end": 1494916933.26, \n "message": ""\n }, \n "notify": {\n "status": "pass", \n "code": 0, \n "time\_start": 1494916940.508316, \n "signal": 0, \n "time\_end": 1494916943.763181, \n "message": ""\n }, \n "RoboGalaxy": {\n "status": "fail", \n "code": 1, \n "time\_start": 1494916912.109, \n "signal": 0, \n "time\_end": 1494916924.76, \n "message": "1 RG test failed -- fail: Setup failed:\nKeyError: u'sys\_os', Test: UC9 RemoteScripted:ILOREST Testing; "\n }",  
"jobID" =\> "ci-000c294400e8\_administrator\_4",  
**"status" =\> "%{[doc][status]}",**  
}

In the last line of the output i am getting status as a string instead of getting the value, we can see the message is  
coming well, even i have set a target to doc, but still i am unable to get the result. can someone pls help me.

what is the correct way to write the add field syntax to fetch the status: fail

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2017, 7:00am UTC](https://discuss.elastic.co/t/add-field-not-fetching-the-value-from-target-instead-printing-as-a-string/87209/2 "2017-06-23T07:00:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
