# Adding a new field in logstash

**URL:** <https://discuss.elastic.co/t/adding-a-new-field-in-logstash/380333>\
**Category:** Logstash\
**Created:** [July 22, 2025, 9:19am UTC](https://discuss.elastic.co/t/adding-a-new-field-in-logstash/380333 "2025-07-22T09:19:44Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![DOkuwa](https://avatars.discourse-cdn.com/v4/letter/d/90db22/32.png) [@DOkuwa](https://discuss.elastic.co/u/DOkuwa)\
**Post date:** [July 22, 2025, 9:19am UTC](https://discuss.elastic.co/t/adding-a-new-field-in-logstash/380333/1 "2025-07-22T09:19:44Z")

</div>

Hi,

I have this input file sending data to logstash and want to add a new field name as seen below  
I dont want to use  
filter {  
mutate {  
add\_field =\> { "new\_field\_name" =\> "new\_field\_value" }  
}  
}  
such as  
add\_field =\> { "name " =\> "GigabitEthernet0/0" }  
as this can change to GigabitEthernet0/1 or 2  
e.g  
Is there any way

``openconfig-interfaces:interfaces/interface/state/counters,host=ibcinmnrffd1v,name=GigabitEthernet0/0,path=openconfig-interfaces:interfaces/interface/state/counters,source=hclab043-gnmic,subscription=140 in\_octets=3522806333i 1753175837837000000  
openconfig-interfaces:interfaces/interface/state/counters,host=ibcinmnrffd1v,name=GigabitEthernet0/0,path=openconfig-interfaces:interfaces/interface/state/counters,source=hclab043-gnmic,subscription=140 in\_octets=3522829569i 1753175867837000000

```auto

```

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [July 22, 2025, 11:39am UTC](https://discuss.elastic.co/t/adding-a-new-field-in-logstash/380333/2 "2025-07-22T11:39:50Z")

</div>

It's maybe obvious to you what you want to do here, but all you've really written is what you _don't_ want to do?

I am presuming we are talking about _only_ the `name=GigabitEthernet0/0` bits?

Whats the range of values here, and what part of it do you want to distinguish? Is it always GigabitEthernetX/Y, X and Y always being positive integers, and both X and Y are always present? And you want to just drop the "/Y"? Or you want to drop "X/Y"?

e.g. what is the value for the `name` field that you desire for following inputs:

```auto
name=GigabitEthernet0/0
name=GigabitEthernet0/1
name=GigabitEthernet0/2
name=GigabitEthernet1/0
name=GigabitEthernet1/1
name=GigabitEthernet23/4
name=GigabitEthernet4/23
name=GigabitEthernet2
name=SomethingElse0/0
name=SomethingElse0/1
name=SomethingElse1/0
name=SomethingElse0
...

```

---

<div class="post-metadata">

**Author:** ![DOkuwa](https://avatars.discourse-cdn.com/v4/letter/d/90db22/32.png) [@DOkuwa](https://discuss.elastic.co/u/DOkuwa)\
**Post date:** [July 22, 2025, 4:08pm UTC](https://discuss.elastic.co/t/adding-a-new-field-in-logstash/380333/3 "2025-07-22T16:08:22Z")

</div>

Maybe I should explain

I want where I can have any interface or maybe Gi0/0,0/1 having different in-octets and how this will be in kibana

I have this working with this config

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/b/db4248bc5f4fffbae4f681a2f95e6b79360e50f6.png)

And output is like this

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7a653daaf54bf49357c9877a011b55b701de3773.png)

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [July 22, 2025, 6:37pm UTC](https://discuss.elastic.co/t/adding-a-new-field-in-logstash/380333/4 "2025-07-22T18:37:15Z")

</div>

thanks for quick answer. Sadly I'm now even more confused than I was before, so I hope someone else is able to interpret your problem from the 2 descriptions, and can help you reach your goal.

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [July 23, 2025, 7:01am UTC](https://discuss.elastic.co/t/adding-a-new-field-in-logstash/380333/5 "2025-07-23T07:01:04Z")

</div>

Hello @DOkuwa

If i understand this below is your sample message/log lines :

**message :**

```auto
openconfig-interfaces:interfaces/interface/state/counters,host=ibcinmnrffd1v,name=GigabitEthernet0/0,path=openconfig-interfaces:interfaces/interface/state/counters,source=hclab043-gnmic,subscription=140 in_octets=3522806333i 1753175837837000000
openconfig-interfaces:interfaces/interface/state/counters,host=ibcinmnrffd1v,name=GigabitEthernet0/0,path=openconfig-interfaces:interfaces/interface/state/counters,source=hclab043-gnmic,subscription=140 in_octets=3522829569i 1753175867837000000

```

In current scenario you are adding a static field where name is "interface" & value is "GigabitEthernet0/0" for all records

`add_field => { "interface" => "GigabitEthernet0/0" }`

Currently in kibana for each record this value is added :

```auto
{
  "other_fields" : "values",
  "interface": "GigabitEthernet0/0", // Static value added to every record
  "message": "openconfig-interfaces:interfaces/interface/state/counters,host=ibcinmnrffd1v,name=GigabitEthernet0/0,path=openconfig-interfaces:interfaces/interface/state/counters,source=hclab043-gnmic,subscription=140 in_octets=3522806333i 1753175837837000000"
}

```

But you do not want this to be static as the value will change & this should be extracted from the message/log file where field is "name"

name=GigabitEthernet0/0

I am not sure if you are looking for below where it will extract the data dynamically :

```auto
input {
  tcp {
    port => 5085
    codec => json {}
  }
}
filter {
   mutate {
    remove_field => ["_tags"]
    remove_field => ["tags"]
    remove_field => ["timestamp"]
    add_field => { "source" => "hclab043.zz.db.com" }
  }
  # Extract the `interface` value dynamically from the `message` field
  grok {
    match => { "message" => ".*name=%{DATA:interface},.*" }
  }
    mutate {
    rename => { "[fields][in_octets]" => "[in_octets]" }
  }
}

```

For sample below record in log file , i see this entry in Kibana

`openconfig-interfaces:interfaces/interface/state/counters,host=ibcinmnrffd1v,name=GigabitEthernet2/1,path=openconfig-interfaces:interfaces/interface/state/counters,source=hclab043-gnmic,subscription=140 in_octets=3522806333i 1753175837837000000`

![image](https://us1.discourse-cdn.com/elastic/original/3X/b/3/b30888077a5809f040bf44ce2600676160623d3b.png)

Thanks!!
