# Adding a field from existing ones

**URL:** <https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697>\
**Category:** Logstash\
**Created:** [March 7, 2017, 4:25pm UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697 "2017-03-07T16:25:34Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohamed](https://avatars.discourse-cdn.com/v4/letter/m/d78d45/32.png) [@Mohamed](https://discuss.elastic.co/u/Mohamed)\
**Post date:** [March 7, 2017, 4:25pm UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/1 "2017-03-07T16:25:34Z")

</div>

Hello,

I want to add a field composed of some other fields, like this:  
suppose we have fields  
"name": [  
"XX"  
],  
"adress": [  
"584"  
],

I want to add a field like that:  
"person" : [  
{"name": "XX"  
"adress":"584"}  
]

I've trayed that filter:  
mutate {  
add\_field =\> {"person"=\> [" "name":"%{name}",{"adress":"%{adress}"} "]}  
}

it doesn't work because it's not correct !

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [March 9, 2017, 1:56am UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/2 "2017-03-09T01:56:16Z")

</div>

The syntax is incorrect. Try the following:

```auto
mutate {
add_field => {"person"=> ["%{name}","%{adress}"]}
}

```

---

<div class="post-metadata">

**Author:** ![Mohamed](https://avatars.discourse-cdn.com/v4/letter/m/d78d45/32.png) [@Mohamed](https://discuss.elastic.co/u/Mohamed)\
**Post date:** [March 9, 2017, 8:18am UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/3 "2017-03-09T08:18:44Z")

</div>

Hello, thank you for the help. I've trayed this but it doesn't give the result I need.  
I want to create a complex object like this:

"person" : [  
{ "name" : "John",  
"adress" : "Doe"  
},

```
                 { "name" : "Mary",  
                   "adress" : "Smith"
                    }
             ]
```

---

<div class="post-metadata">

**Author:** ![Mohamed](https://avatars.discourse-cdn.com/v4/letter/m/d78d45/32.png) [@Mohamed](https://discuss.elastic.co/u/Mohamed)\
**Post date:** [March 9, 2017, 3:54pm UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/4 "2017-03-09T15:54:22Z")

</div>

@magnusbaeck

Is there any help please.

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [March 9, 2017, 5:10pm UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/5 "2017-03-09T17:10:57Z")

</div>

Please provide your information in a structured manner as I'm a bit confused.  
Let me know if this is what you mean.

1. I have a data file with the following data

Mary Smith  
John Lee

1. Trying to Import this thru Logstash and currently have the data structured as

```auto
"name" : "Mary"
"adress" "Smith"

```

1. While Importing the data I would like to add a person object that contains the data structure above.

```auto
"person" : [ 
{ "name" : "Mary",
"adress" : "Smith"
},

```

---

<div class="post-metadata">

**Author:** ![Mohamed](https://avatars.discourse-cdn.com/v4/letter/m/d78d45/32.png) [@Mohamed](https://discuss.elastic.co/u/Mohamed)\
**Post date:** [March 9, 2017, 5:15pm UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/6 "2017-03-09T17:15:37Z")

</div>

Yes, suppose we have created fields from an input file:

"name":"Mary" and "adress":"Smith"

I want to create a third field person which is composed of name and adress fields.

"person" : [  
{ "name" : "Mary",  
"adress" : "Smith"  
}]

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [March 9, 2017, 5:26pm UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/7 "2017-03-09T17:26:45Z")

</div>

There is an easier way. You can create the person object with the name and adress in one step. I would recommend doing that instead of creating them in two separate steps.

```auto
filter{
grok {
    match => ["message", "%{WORD:[person][name]} %{WORD:[person][adres]}" ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Mohamed](https://avatars.discourse-cdn.com/v4/letter/m/d78d45/32.png) [@Mohamed](https://discuss.elastic.co/u/Mohamed)\
**Post date:** [March 15, 2017, 8:12am UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/8 "2017-03-15T08:12:40Z")

</div>

as result of this filter:

"person": {  
"name" : "Mary",  
"adress" : "Smith"  
}

I want person be a list:

"person": [{  
"name" : "Mary",  
"adress" : "Smith"  
},  
{"name" : "XX",  
"adress" : "154"}]

---

<div class="post-metadata">

**Author:** ![jkuang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jkuang/32/72637_2.png) [@jkuang](https://discuss.elastic.co/u/jkuang)\
**Post date:** [March 15, 2017, 6:45pm UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/9 "2017-03-15T18:45:57Z")

</div>

My grok filter will create a person array list.

If you have Mary Smith and John Smith it will look like

```auto
"person": [{
"name" : "Mary",
"adress" : "Smith"
},
{"name" : "John",
"adress" : "Smith"}]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2017, 6:46pm UTC](https://discuss.elastic.co/t/adding-a-field-from-existing-ones/77697/10 "2017-04-12T18:46:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
