# Add two value from two record

**URL:** <https://discuss.elastic.co/t/add-two-value-from-two-record/243126>\
**Category:** Logstash\
**Created:** [July 29, 2020, 9:12pm UTC](https://discuss.elastic.co/t/add-two-value-from-two-record/243126 "2020-07-29T21:12:21Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 29, 2020, 9:33pm UTC](https://discuss.elastic.co/t/add-two-value-from-two-record/243126/2 "2020-07-29T21:33:55Z")

</div>

> [@elasticforme](#):
>
> is it even possible?

Pretty much anything is possible in logstash. You could do this in an aggregate filter. There are a couple of approaches, but in both you will have to save the name and code1 values in the map, then event.cancel those events. Once you receive the code2 value, create an array that contains both records you want in elasticsearch and then use a split filter to convert it to two events. You may then need to [move](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2) fields to the top level.

Note, you will need a task\_id on the events to combine them. That can be a constant.

```
mutate { add_field => { "myTaskId" => "1" } }

```

If it is literally always name/code1/code2 you could do something like [example 1](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-example1) in the documentation. map\_action would be create for 'name', update for 'code1' and 'code2', and end\_of\_task would be set for 'code2'.

Alternatively, use something like example 3, where you set push\_map\_as\_event\_on\_timeout to true.

---

_[View the full topic](https://discuss.elastic.co/t/add-two-value-from-two-record/243126)._
