# Add\_field not working in date { } config

**URL:** https://discuss.elastic.co/t/add-field-not-working-in-date-config/25785
**Category:** Logstash
**Created:** [July 17, 2015, 10:14am UTC](https://discuss.elastic.co/t/add-field-not-working-in-date-config/25785 "2015-07-17T10:14:53Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Janet](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@Janet](https://discuss.elastic.co/u/Janet)
#### Post date: [July 17, 2015, 10:14am UTC](https://discuss.elastic.co/t/add-field-not-working-in-date-config/25785/1 "2015-07-17T10:14:53Z")

</div>

I use a friendly date format to display to my users, because @timestamp is a little ugly. This config adds a time field, which works as expected:

```
		date {
			add_field => ["time", "%{+MMM dd HH:mm:ss}"]
			match => ["syslog_timestamp", "yyyy MMM dd HH:mm:ss"]
			timezone => "UTC"
		}

```

However, the add\_field function fails to work in this config:

```
	date {
		add_field => ["time", "%{+MMM dd HH:mm:ss}"]
		match => ["%{@timestamp}", "ISO8601"]
		timezone => "UTC"
	}

```

I've even tried to add a static "test" field to the second date {} config, but add\_field just doesn't work. This one has me scratching my head.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 17, 2015, 10:21am UTC](https://discuss.elastic.co/t/add-field-not-working-in-date-config/25785/2 "2015-07-17T10:21:01Z")

</div>

> I use a friendly date format to display to my users, because @timestamp is a little ugly.

That sounds like something that should be fixed in the display layer, not by adding redundant data.

```
date {
  add_field => ["time", "%{+MMM dd HH:mm:ss}"]
  match => ["%{@timestamp}", "ISO8601"]
  timezone => "UTC"
}

```

The first argument of the list provided to `match` is the _name_ of a field as in your first example with `syslog_timestamp`. Here you're trying to expand the _value_ of the `@timestamp` field.

---

<div class="post-metadata">

### Author: ![Janet](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@Janet](https://discuss.elastic.co/u/Janet)
#### Post date: [July 17, 2015, 10:31am UTC](https://discuss.elastic.co/t/add-field-not-working-in-date-config/25785/3 "2015-07-17T10:31:42Z")

</div>

P.S. when I use a mutate to add a test field that's %{@timestamp} , I get this:

2015-07-17T10:25:00.000Z

So why doesn't ISO8601 match with %{@timestamp} in my second example. I'm assuming the add\_fields aren't getting processed because the match doesn't happen.

---

<div class="post-metadata">

### Author: ![Janet](https://avatars.discourse-cdn.com/v4/letter/j/5e9695/32.png) [@Janet](https://discuss.elastic.co/u/Janet)
#### Post date: [July 17, 2015, 10:33am UTC](https://discuss.elastic.co/t/add-field-not-working-in-date-config/25785/4 "2015-07-17T10:33:25Z")

</div>

P.P.S I didn't have this problem with 1.4.2

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 17, 2015, 10:36am UTC](https://discuss.elastic.co/t/add-field-not-working-in-date-config/25785/5 "2015-07-17T10:36:30Z")

</div>

Again, `match` is supposed to contain _the name of a field_. The `@timestamp` field is named `@timestamp` and not `%{@timestamp}`, so you should say this instead:

```
match => ["@timestamp", "ISO8601"]

```

And I still think you should avoid doing this and focus on fixing the problem in the right place.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:34am UTC](https://discuss.elastic.co/t/add-field-not-working-in-date-config/25785/6 "2017-07-06T05:34:22Z")

</div>


