# Add\_tag from fields than delete source fields

**URL:** <https://discuss.elastic.co/t/add-tag-from-fields-than-delete-source-fields/240730>\
**Category:** Logstash\
**Created:** [July 10, 2020, 5:02pm UTC](https://discuss.elastic.co/t/add-tag-from-fields-than-delete-source-fields/240730 "2020-07-10T17:02:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dikkini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dikkini/32/71958_2.png) [@dikkini](https://discuss.elastic.co/u/dikkini)\
**Post date:** [July 10, 2020, 5:02pm UTC](https://discuss.elastic.co/t/add-tag-from-fields-than-delete-source-fields/240730/1 "2020-07-10T17:02:37Z")

</div>

Hello!

I got JSON and there `tags` element which i want to use to add tags.  
I rename it to `telegraf_tags` [because of this topic](https://discuss.elastic.co/t/kafka-input-codec-json-parse-error/240726) and want to use them as source for ES tags.

JSON:

```auto
{"fields":{"created":1594396144981,"value":"{\"id\": 1, \"type\": \"exit\", \"num\": \"12\", \"other_num\": 2, \"name\": \"Ivan\", \"children\": [{\"name\": \"Julia\", \"age\": 1, \"sex\": true, \"birthtime\": \"09/07/2020 17:38:13\"}], \"birthtime\": \"09/07/2020 17:38:13\", \"created\": 1594316293296}"},"name":"generator_log","tags":{"host":"test.dev.map","path":"/opt/map/agents/generator.log","type":"generator"},"timestamp":1594396144}

```

logstash config:

```auto
filter {
	mutate {
      copy => {
        "[fields][created]" => "created"
        "[fields][value]" => "data"
      }
      rename => ["tags", "telegraf_tags"]
      add_tag => ["%{[telegraf_tags][type]}", "%{[telegraf_tags][host]}", "%{[telegraf_tags][path]}" ]
      remove_field => ["tags", "fields", "telegraf_tags"]
	}
}

```

with this logstash config in ES tags looks like this:`tags: %{[telegraf_tags][type]}, %{[telegraf_tags][host]}, %{[telegraf_tags][path]}`

But if i won't delete field `telegraf_tags` - it works:  
logstash config:

```auto
filter {
	mutate {
      copy => {
        "[fields][created]" => "created"
        "[fields][value]" => "data"
      }
      rename => ["tags", "telegraf_tags"]
      add_tag => ["%{[telegraf_tags][type]}", "%{[telegraf_tags][host]}", "%{[telegraf_tags][path]}" ]
      remove_field => ["tags", "fields"]
	}
}

```

but i have to delete it and add tags based on it

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 10, 2020, 5:43pm UTC](https://discuss.elastic.co/t/add-tag-from-fields-than-delete-source-fields/240730/2 "2020-07-10T17:43:23Z")

</div>

mutate does things in a fixed order, which is not always the order you want. Try dividing that into four different mutate filters.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 7, 2020, 5:43pm UTC](https://discuss.elastic.co/t/add-tag-from-fields-than-delete-source-fields/240730/3 "2020-08-07T17:43:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
