# Cannot add new field from event type

**URL:** <https://discuss.elastic.co/t/cannot-add-new-field-from-event-type/203875>\
**Category:** Logstash\
**Created:** [October 16, 2019, 3:37pm UTC](https://discuss.elastic.co/t/cannot-add-new-field-from-event-type/203875 "2019-10-16T15:37:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![francescouk](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Post date:** [October 16, 2019, 3:37pm UTC](https://discuss.elastic.co/t/cannot-add-new-field-from-event-type/203875/1 "2019-10-16T15:37:22Z")

</div>

Hello guys,

I´m new to ELK stack and trying to add custom field to kibana using the filter in logstash. Can someone point me to right direction??

I want to add the field "Logon Activity" like "message" showing in the picture bellow:

![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d2979f27a85d18ea00464a5f13241f18eca698a8.png)

filter {  
if [agent][type] == "winlogbeat" and [winlog][channel] == "Security" and [event\_id] == 4624 or [event\_id] == 4634 {  
mutate {  
remove\_field =\> ["[message]"]  
add\_field =\> { "short\_message" =\> "Logon Activity" }  
}  
}  
}

Thanks,

---

<div class="post-metadata">

**Author:** ![arxo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arxo/32/56054_2.png) [@arxo](https://discuss.elastic.co/u/arxo)\
**Post date:** [October 16, 2019, 9:02pm UTC](https://discuss.elastic.co/t/cannot-add-new-field-from-event-type/203875/2 "2019-10-16T21:02:34Z")

</div>

Would you be happy with just replacing the value of message e.g.

mutate {  
replace =\> ["message", "Logon Activity"]  
}

If you have already added the change you outlined in your post, you will probably need to refresh the field mappings in Kibana.

---

<div class="post-metadata">

**Author:** ![francescouk](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Post date:** [October 17, 2019, 10:37am UTC](https://discuss.elastic.co/t/cannot-add-new-field-from-event-type/203875/3 "2019-10-17T10:37:42Z")

</div>

What I´ve done so far and it seens to work was:

filter {  
if "winlogbeat" in [tags] and [winlog][channel] == "Security" and [winlog][event\_id] == 4624 or [winlog][event\_id] == 4634 {  
mutate {  
remove\_field =\> ["[message]"]  
add\_field =\> { "ADLogon" =\> "Logon Activity" }  
}  
}  
}

Had to specify the [winlog] at [event\_id] as the code below shows:

**"winlog"** =\> {  
"opcode" =\> "Info",  
"computer\_name" =\> "demo.local",  
"task" =\> "Process Creation",  
"keywords" =\> [  
[0] "Audit Success"  
],  
"record\_id" =\> 8110800,  
"provider\_name" =\> "Microsoft-Windows-Security-Auditing",  
"process" =\> {  
"thread" =\> {  
"id" =\> 20228  
},  
"pid" =\> 4  
},  
"api" =\> "wineventlog",  
"channel" =\> "Security",  
"version" =\> 2,  
**"event\_id"** =\> 4624,  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 14, 2019, 10:37am UTC](https://discuss.elastic.co/t/cannot-add-new-field-from-event-type/203875/4 "2019-11-14T10:37:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
