# Add new field from message

**URL:** <https://discuss.elastic.co/t/add-new-field-from-message/195737>\
**Category:** Logstash\
**Created:** [August 19, 2019, 12:09pm UTC](https://discuss.elastic.co/t/add-new-field-from-message/195737 "2019-08-19T12:09:08Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cowensel](https://avatars.discourse-cdn.com/v4/letter/c/eb9ed0/32.png) [@cowensel](https://discuss.elastic.co/u/cowensel)\
**Post date:** [August 19, 2019, 12:09pm UTC](https://discuss.elastic.co/t/add-new-field-from-message/195737/1 "2019-08-19T12:09:08Z")

</div>

Hi,

I wonder if someone can help. I have looked online and I haven't found a solution. We have an event that passes a message like "error detected in request error code: [error code] please check"

Is there a way to be able to tell logstash to look for error detected and create a new field and populate with the name error code and the value of [error code].

Any assistance is appreciated

---

<div class="post-metadata">

**Author:** ![sveldhuisen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sveldhuisen/32/52509_2.png) [@sveldhuisen](https://discuss.elastic.co/u/sveldhuisen)\
**Post date:** [August 19, 2019, 12:42pm UTC](https://discuss.elastic.co/t/add-new-field-from-message/195737/2 "2019-08-19T12:42:07Z")

</div>

Hello Peter,

That is definately possible by using the Translate Filter: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html)

```
filter {
  translate {
    field => "[error_code]"
    destination => "[error_description]"
    dictionary => {
      "100" => "Continue"
      "101" => "Switching Protocols"
      "200" => "OK"
      "500" => "Server Error"
    }
    fallback => "I'm a teapot"
  }
}

```

You can also use a dictionary file. i.e.:

`dictionary_path => "/etc/logstash/dicts/translate-errorcode.yaml"`

Probably the most challenging is the extraction of the error code from your source data. I would suggest some testing with a good grok match pattern.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 19, 2019, 1:20pm UTC](https://discuss.elastic.co/t/add-new-field-from-message/195737/3 "2019-08-19T13:20:35Z")

</div>

```
grok { match => { "message" => "\[%{DATA:errorCode}\]" } }
```

---

<div class="post-metadata">

**Author:** ![cowensel](https://avatars.discourse-cdn.com/v4/letter/c/eb9ed0/32.png) [@cowensel](https://discuss.elastic.co/u/cowensel)\
**Post date:** [August 19, 2019, 10:56pm UTC](https://discuss.elastic.co/t/add-new-field-from-message/195737/4 "2019-08-19T22:56:59Z")

</div>

I have used the Dissect filter to split the message into different fields which has worked however the way the message has been written it reads

> Error : Client Id - 1 : Error Code - 2 : Description : Error has occurred : Employee ID - 1

When using the dissect I have the following mapping  
`"%{error}: %{company id} : %{Error Code} : %{Error Description}: %{Employee Id}"`  
is there a way to say for the company ID and error code I want the value after the - but in the Description i would like the value after the first : then a new field for employee id?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 20, 2019, 12:14pm UTC](https://discuss.elastic.co/t/add-new-field-from-message/195737/5 "2019-08-20T12:14:49Z")

</div>

> [@cowensel](#):
>
> Error : Client Id - 1 : Error Code - 2 : Description : Error has occurred : Employee ID - 1

```
dissect { mapping => { "message" => "%{f0} : %{f1} - %{f2} : %{f3} - %{f4} : %{f5} : %{f6} : %{f7} - %{f8}" } }

```

will get you

```
        "f0" => "Error",
        "f1" => "Client Id",
        "f2" => "1",
        "f3" => "Error Code",
        "f4" => "2",
        "f5" => "Description",
        "f6" => "Error has occurred",
        "f7" => "Employee ID",
        "f8" => "1",

```

You can merge fields and substitute constant strings however suites you.

---

<div class="post-metadata">

**Author:** ![cowensel](https://avatars.discourse-cdn.com/v4/letter/c/eb9ed0/32.png) [@cowensel](https://discuss.elastic.co/u/cowensel)\
**Post date:** [August 21, 2019, 6:51am UTC](https://discuss.elastic.co/t/add-new-field-from-message/195737/6 "2019-08-21T06:51:11Z")

</div>

That worked Badger thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2019, 6:51am UTC](https://discuss.elastic.co/t/add-new-field-from-message/195737/7 "2019-09-18T06:51:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
