# Add field to the message in logstash

**URL:** <https://discuss.elastic.co/t/add-field-to-the-message-in-logstash/49443>\
**Category:** Logstash\
**Created:** [May 6, 2016, 10:36pm UTC](https://discuss.elastic.co/t/add-field-to-the-message-in-logstash/49443 "2016-05-06T22:36:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stecino](https://avatars.discourse-cdn.com/v4/letter/s/ea666f/32.png) [@stecino](https://discuss.elastic.co/u/stecino)\
**Post date:** [May 6, 2016, 10:36pm UTC](https://discuss.elastic.co/t/add-field-to-the-message-in-logstash/49443/1 "2016-05-06T22:36:17Z")

</div>

Hello,

I have the following config:

input {  
udp {  
host =\> "0.0.0.0"  
port =\> 5544  
type =\> "f5-logs"

```
   }

```

udp {  
host =\> "0.0.0.0"  
port =\> 514  
type =\> "firewall-logs"  
}

```
  }

```

I want to be able to add firewall IP that sends the messages to message body

Here is the json

{  
"message" =\> "\<188\>May 06 2016 15:34:30: %ASA-4-106023: Deny tcp src Outside:xxxxxxxx/20126 dst DMZ:xxxxxxxx.183/80 by access-group "110" [0xe28ed867, 0xad5a89d]\n",  
"@version" =\> "1",  
"@timestamp" =\> "2016-05-06T22:34:30.894Z",  
"type" =\> "firewall-logs",  
"host" =\> "10.1.x.x"  
}

How should filter look like

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 7, 2016, 7:07am UTC](https://discuss.elastic.co/t/add-field-to-the-message-in-logstash/49443/2 "2016-05-07T07:07:48Z")

</div>

> [@stecino](#):
>
> I want to be able to add firewall IP that sends the messages to message body

If that IP is not in the original message, there's no way to add it. The UDP input doesn't track that sort of thing.

---

<div class="post-metadata">

**Author:** ![stecino](https://avatars.discourse-cdn.com/v4/letter/s/ea666f/32.png) [@stecino](https://discuss.elastic.co/u/stecino)\
**Post date:** [May 9, 2016, 9:32pm UTC](https://discuss.elastic.co/t/add-field-to-the-message-in-logstash/49443/3 "2016-05-09T21:32:48Z")

</div>

in my output section, i append the host in the beginning of the message to add to kafka

```
      codec => plain {
        format => "%{host}%{message}"
        charset => "CP1252"
      }

```

So then I updated my grok filter to properly address it, when reading from kafka input. It's working for me

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:58am UTC](https://discuss.elastic.co/t/add-field-to-the-message-in-logstash/49443/4 "2017-07-06T04:58:29Z")

</div>


