# Adding field creates an array not a static string

**URL:** <https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149>\
**Category:** Logstash\
**Created:** [December 9, 2020, 3:27pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149 "2020-12-09T15:27:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jknott](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@jknott](https://discuss.elastic.co/u/jknott)\
**Post date:** [December 9, 2020, 3:27pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/1 "2020-12-09T15:27:09Z")

</div>

When I add this in my filter it adds it but my other pipelines also add a field of the same and the values turn into an array instead of a static value per log.

```auto
     mutate {
       add_field => {
        "service_name" => "company"
       }
     }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 9, 2020, 4:28pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/2 "2020-12-09T16:28:53Z")

</div>

If that filter is executed twice then you will get an array instead of a text field. How are your pipelines configured? pipelines.yml?

---

<div class="post-metadata">

**Author:** ![jknott](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@jknott](https://discuss.elastic.co/u/jknott)\
**Post date:** [December 9, 2020, 4:42pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/3 "2020-12-09T16:42:30Z")

</div>

Its in K8s under logstashPipeline: I have multiple pipelines each with an input/filter/output

---

<div class="post-metadata">

**Author:** ![jknott](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@jknott](https://discuss.elastic.co/u/jknott)\
**Post date:** [December 9, 2020, 4:45pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/4 "2020-12-09T16:45:26Z")

</div>

```auto
  input {
    beats {
      port => 5052
    }
  }
  filter {
  dissect {
    mapping => {
      "message" => "%%{TIMESTAMP_ISO8601:timestamp}||%%{LOGLEVEL:level}||%%{DATA:thread_id}||%%{IPV4:originating_ip}||%%{USERNAME:username}||%%{USERNAME:legacy_person_id}||%%{UUID:person_id}||%%{USER:amzn_trace_id}||%%{DATA:source_location}||%%{GREEDYDATA:message}"
    }
  }

              mutate {
                       rename => ["TIMESTAMP_ISO8601:timestamp", "timestamp"]
              }

              mutate {
                       rename => ["LOGLEVEL:level", "level"]
              }

              mutate {
                       rename => ["DATA:thread_id", "thread_id"]
              }

              mutate {
                       rename => ["IPV4:originating_ip", "originating_ip"]
              }

              mutate {
                       rename => ["USERNAME:username", "username"]
              }

              mutate {
                       rename => ["USERNAME:legacy_person_id", "legacy_person_id"]
              }

              mutate {
                       rename => ["UUID:person_id", "person_id"]
              }

              mutate {
                       rename => ["USER:amzn_trace_id", "amzn_trace_id"]
              }

              mutate {
                       rename => ["DATA:source_location", "source_location"]
              }

              mutate {
                       rename => ["GREEDYDATA:message", "message"]
              }

   mutate {
     add_field => {
      "service_name" => "company"
     }
   }
    }
  output {
    amazon_es {
      hosts =>
      ssl => true
      region => "us-east-1"
      index => "${env}-services-company-logs-%%{+YYYY.MM}"
    }
  }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 9, 2020, 5:15pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/5 "2020-12-09T17:15:59Z")

</div>

Are you expecting that each configuration file will automatically get run in a separate pipeline? That does not happen unless you configure it that way using pipelines.yml. If you point path.config (or -f) at a directory that contains more than one configuration file then they are combined. So if you have two files

```
input { http { ... } }
filter { mutate { ... } }
output { stdout {... } }

```

and

```
input { file { ... } }
filter { csv { ... } }
output { elasticsearch {... } }

```

that is equivalent to

```
input {
    http { ... }
    file { ... }
}
filter {
    mutate { ... }
    csv { ... }
}
output {
    stdout {... }
    elasticsearch {... }
}
```

---

<div class="post-metadata">

**Author:** ![jknott](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@jknott](https://discuss.elastic.co/u/jknott)\
**Post date:** [December 9, 2020, 5:54pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/6 "2020-12-09T17:54:07Z")

</div>

How do you separate that from a helm values file perspective?

```auto
  logstash.yml: |
    http.host: "0.0.0.0"
    path.config: /usr/share/logstash/pipeline

# Allows you to add any pipeline files in /usr/share/logstash/pipeline/
### ***warn*** there is a hardcoded logstash.conf in the image, override it first
logstashPipeline: 
  logstash.conf: |
    input {
      beats {
        port => 5044
      }
    }
    output {
      amazon_es {
        hosts => 
        ssl => true
        region => "us-east-1"
        index => "${env}-logs-%%{+YYYY.MM}"
      }
    }

```

---

<div class="post-metadata">

**Author:** ![jknott](https://avatars.discourse-cdn.com/v4/letter/j/76d3ee/32.png) [@jknott](https://discuss.elastic.co/u/jknott)\
**Post date:** [December 9, 2020, 7:29pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/7 "2020-12-09T19:29:27Z")

</div>

I added the pipelines.yml config but still getting service\_name field with other values from other pipelines.

```auto
    - pipeline.id: main
      path.config: "/usr/share/logstash/pipeline/logstash.conf"
    - pipeline.id: services 
      path.config: "/usr/share/logstash/pipeline/services.conf"
    - pipeline.id: avenger 
      path.config: "/usr/share/logstash/pipeline/avenger.conf"
    - pipeline.id: homeval 
      path.config: "/usr/share/logstash/pipeline/homeval.conf"
    - pipeline.id: address 
      path.config: "/usr/share/logstash/pipeline/address.conf"
    - pipeline.id: company 
      path.config: "/usr/share/logstash/pipeline/company.conf"

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2020, 6:23pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/8 "2020-12-10T18:23:52Z")

</div>

I have no idea why that would happen.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2021, 6:23pm UTC](https://discuss.elastic.co/t/adding-field-creates-an-array-not-a-static-string/258149/9 "2021-01-07T18:23:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
