# Add\_tag

**URL:** <https://discuss.elastic.co/t/add-tag/61837>\
**Category:** Logstash\
**Created:** [September 29, 2016, 5:22pm UTC](https://discuss.elastic.co/t/add-tag/61837 "2016-09-29T17:22:41Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![13koushik](https://avatars.discourse-cdn.com/v4/letter/1/13edae/32.png) [@13koushik](https://discuss.elastic.co/u/13koushik)\
**Post date:** [September 29, 2016, 5:22pm UTC](https://discuss.elastic.co/t/add-tag/61837/1 "2016-09-29T17:22:41Z")

</div>

Is there any way one could rename a tag. When I'm using add\_tag of mutate and assigning it an array, the name of the tag is "tags" by default. I would like to rename it. Could someone help me out?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 29, 2016, 7:17pm UTC](https://discuss.elastic.co/t/add-tag/61837/2 "2016-09-29T19:17:46Z")

</div>

`add_tag` always adds the string to an array in the field named `tags`. The name of the `tags` field isn't configurable.

---

<div class="post-metadata">

**Author:** ![13koushik](https://avatars.discourse-cdn.com/v4/letter/1/13edae/32.png) [@13koushik](https://discuss.elastic.co/u/13koushik)\
**Post date:** [September 29, 2016, 10:02pm UTC](https://discuss.elastic.co/t/add-tag/61837/3 "2016-09-29T22:02:50Z")

</div>

Thanks Magnus. I'm am trying to create a field which takes an array as it's value. I need to give it a specific name. Any suggestion would be really helpful.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 30, 2016, 5:28am UTC](https://discuss.elastic.co/t/add-tag/61837/4 "2016-09-30T05:28:39Z")

</div>

Why not use `add_field`?

---

<div class="post-metadata">

**Author:** ![13koushik](https://avatars.discourse-cdn.com/v4/letter/1/13edae/32.png) [@13koushik](https://discuss.elastic.co/u/13koushik)\
**Post date:** [September 30, 2016, 12:24pm UTC](https://discuss.elastic.co/t/add-tag/61837/5 "2016-09-30T12:24:31Z")

</div>

Tried the add\_field Magnus.

filter {  
json {  
source =\> "message"  
target =\> "msg"  
}  
mutate {  
add\_field =\> {  
"IP-Address" =\> "%{[msg][message][IP-Address]}"  
"Name" =\> "HostName"  
}  
}  
This is giving me two fields "IP-Address" and "Name" with their respective values. I'm not sure how to create a field which takes an array as it's value.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 30, 2016, 12:58pm UTC](https://discuss.elastic.co/t/add-tag/61837/6 "2016-09-30T12:58:35Z")

</div>

If you use `add_field` more than once on the same field you'll get an array. I'm not sure if you can create a one-element array.

---

<div class="post-metadata">

**Author:** ![13koushik](https://avatars.discourse-cdn.com/v4/letter/1/13edae/32.png) [@13koushik](https://discuss.elastic.co/u/13koushik)\
**Post date:** [September 30, 2016, 1:07pm UTC](https://discuss.elastic.co/t/add-tag/61837/7 "2016-09-30T13:07:36Z")

</div>

Thanks a lot Magnus. That worked.

---

<div class="post-metadata">

**Author:** ![13koushik](https://avatars.discourse-cdn.com/v4/letter/1/13edae/32.png) [@13koushik](https://discuss.elastic.co/u/13koushik)\
**Post date:** [October 11, 2016, 2:35pm UTC](https://discuss.elastic.co/t/add-tag/61837/8 "2016-10-11T14:35:16Z")

</div>

Magnus, I have a question. I have logs which as the name of the user in the field "UserName" and logs which has it in "User-Name". Is there a possibility to use OR in an add\_field ?  
mutate{  
add\_field =\> { "msg\_relations" =\> "%{[msg][message][Username OR User-Name]}" }  
}

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 11, 2016, 2:52pm UTC](https://discuss.elastic.co/t/add-tag/61837/9 "2016-10-11T14:52:36Z")

</div>

Not like that but you can have a conditional:

```nohighlight
if [msg][message][Username] {
  mutate {
    add_field => {
      "msg_relations" => "%{[msg][message][Username]}"
    }
  }
} else if [msg][message][User-Name] {
  mutate {
    add_field => {
      "msg_relations" => "%{[msg][message][User-Name]}"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![13koushik](https://avatars.discourse-cdn.com/v4/letter/1/13edae/32.png) [@13koushik](https://discuss.elastic.co/u/13koushik)\
**Post date:** [October 11, 2016, 2:56pm UTC](https://discuss.elastic.co/t/add-tag/61837/10 "2016-10-11T14:56:43Z")

</div>

Got it. Thanks a lot Magnus.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:34am UTC](https://discuss.elastic.co/t/add-tag/61837/11 "2017-07-06T04:34:43Z")

</div>


