# Assigning value to add\_field new field

**URL:** <https://discuss.elastic.co/t/assigning-value-to-add-field-new-field/56430>\
**Category:** Logstash\
**Created:** [July 26, 2016, 5:44pm UTC](https://discuss.elastic.co/t/assigning-value-to-add-field-new-field/56430 "2016-07-26T17:44:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 26, 2016, 5:44pm UTC](https://discuss.elastic.co/t/assigning-value-to-add-field-new-field/56430/1 "2016-07-26T17:44:12Z")

</div>

Hi,

## I get the field defined in filebeat.yml file as:

paths:  
- /var/logs/mylog.log  
document\_type: LOG1  
fields:  
mytype: FORMAT1

,defining different format spec for each of the log files in the overall group of log files ...

Now I need to take this in the logstash filter and use it for new variables / fields; I can reference it inside the logstash filter as:  
...  
[fields][mytype] - I can check it inside the 'if' statements, etc ..

How do I assign the value of that file to the new filed created in the mutate section using add\_field:  
add\_field =\> { "NEWFIELD", [fields][mytype] } - this did not work - what is the correct syntax for this ?

I also tried referencing it with %{[field][mytype]} - but that did not work either:  
add\_field =\> { "NEWFIELD", %{[fields][mytype]} }

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 26, 2016, 5:52pm UTC](https://discuss.elastic.co/t/assigning-value-to-add-field-new-field/56430/2 "2016-07-26T17:52:55Z")

</div>

I mean - "How do I assign the value of that field to the new field created in the mutate" - sorry for the typo

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 26, 2016, 7:27pm UTC](https://discuss.elastic.co/t/assigning-value-to-add-field-new-field/56430/3 "2016-07-26T19:27:21Z")

</div>

```
add_field => { "NEWFIELD", "%{[fields][mytype]}" }

```

See [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references) for more examples.

You might also want to use a mutate filter and its `rename` option if you want to move a field. With `add_field` you'll end up with two fields with the same contents.

Another option is to configure Filebeat to store the extra fields at the root of the event rather than as subfields of `fields`. See Filebeat's `fields_under_root` option.

---

<div class="post-metadata">

**Author:** ![zoplex](https://avatars.discourse-cdn.com/v4/letter/z/bc8723/32.png) [@zoplex](https://discuss.elastic.co/u/zoplex)\
**Post date:** [July 27, 2016, 12:16am UTC](https://discuss.elastic.co/t/assigning-value-to-add-field-new-field/56430/4 "2016-07-27T00:16:09Z")

</div>

I was missing outside double quotes in "%{[fields][mytype]}" - thank you Magnus!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:46am UTC](https://discuss.elastic.co/t/assigning-value-to-add-field-new-field/56430/5 "2017-07-06T04:46:24Z")

</div>


