# Aggregate filter (Combine Logs)

**URL:** <https://discuss.elastic.co/t/aggregate-filter-combine-logs/124919>\
**Category:** Logstash\
**Created:** [March 21, 2018, 7:22am UTC](https://discuss.elastic.co/t/aggregate-filter-combine-logs/124919 "2018-03-21T07:22:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yimjunhyeok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yimjunhyeok/32/19052_2.png) [@Yimjunhyeok](https://discuss.elastic.co/u/Yimjunhyeok)\
**Post date:** [March 21, 2018, 7:22am UTC](https://discuss.elastic.co/t/aggregate-filter-combine-logs/124919/1 "2018-03-21T07:22:02Z")

</div>

Hello..

I have a trouble making 1 log with 2 events.

1521537121385|172.16.130.205|First  
1521537121385|172.16.130.205|Second  
1521537121386|172.16.130.205|Third  
(LastSessionTime)(SrcIP)(ExtractedText)

Then i want to make combined log (ExtractedText + ExtractedText ==\> FullContent)

==\>  
1521537121385|172.16.130.2015|FirstSecond

aggregate{  
task\_id =\> "%{LastSessionTime}"  
code =\> "  
map['LastSessionTime'] = event.get('LastSessionTime')  
map['FullContent'] ||= []  
map['FullContent'] \<\< {'ExtractedText' =\> event.get('ExtractedText')}  
event.cancel()  
"  
push\_previous\_map\_as\_event =\> true  
timeout =\> 3  
map\_action =\> "update"  
}

But i can't see the "FullContent" Column in Kibana.

Who knows the solution?

---

<div class="post-metadata">

**Author:** ![Yimjunhyeok](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yimjunhyeok/32/19052_2.png) [@Yimjunhyeok](https://discuss.elastic.co/u/Yimjunhyeok)\
**Post date:** [March 27, 2018, 8:13am UTC](https://discuss.elastic.co/t/aggregate-filter-combine-logs/124919/2 "2018-03-27T08:13:51Z")

</div>

```
		if "1" == [DivideStatus] {
         aggregate {
            task_id => "%{SavedFileName}"
            code => "map['FullContent'] ||= '' ; map['FullContent'] += event.get('FileExtractText')"
            map_action => "create"
			}
		}
		if "2" == [DivideStatus] {
         aggregate {
            task_id => "%{SavedFileName}"
            code => "map['FullContent'] += event.get('FileExtractText')"
            map_action => "update"
            }
		}
		if "3" == [DivideStatus] {
		aggregate {
            task_id => "%{SavedFileName}"
            code => "map['FullContent'] += event.get('FileExtractText')
					event.set('FullContent', map['FullContent'])"
			map_action => "update"
			end_of_task => true
			timeout => 600
            timeout_tags => ["aggregate_timeout"]
            }
		}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2018, 8:14am UTC](https://discuss.elastic.co/t/aggregate-filter-combine-logs/124919/3 "2018-04-24T08:14:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
