# Combine fields inside aggregation filter

**URL:** <https://discuss.elastic.co/t/combine-fields-inside-aggregation-filter/123048>\
**Category:** Logstash\
**Created:** [March 8, 2018, 11:00am UTC](https://discuss.elastic.co/t/combine-fields-inside-aggregation-filter/123048 "2018-03-08T11:00:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![daniender](https://avatars.discourse-cdn.com/v4/letter/d/9d8465/32.png) [@daniender](https://discuss.elastic.co/u/daniender)\
**Post date:** [March 8, 2018, 11:00am UTC](https://discuss.elastic.co/t/combine-fields-inside-aggregation-filter/123048/1 "2018-03-08T11:00:17Z")

</div>

Hi all.

I've been googling this for a couple of days and have not found any help, although I think this problem should be very easy to solve.

I'm using Logstash to import data from MySQL database and export it to Elastic. Everything is working as expected.

But now I want to "combine" the result of 3 fields into a new one, and I cannot figure out how.

From MySQL I get this structure:

- Ticket
  - User
    - FirstName
    - SecondName
    - LastName

I would like to combine those 3 fields for each user into new field, let's call it 'completeName'.

I've configured a filter for results like this:

```
filter {
    aggregate {
        task_id => "%{ticket_id}"
        code => "
            map['id'] = event.get('ticket_id')
            map['name'] = event.get('ticket_name')
            map['issueTime'] = event.get('issue_time')

            map['assignedTo'] = {
                'id' => event.get('assignedTo_id'),
                'userName' => event.get('assignedTo_username'),
                'firstName' => event.get('assignedTo_first_name'),
                'familyName' => event.get('assignedTo_family_name'),
                'secondFamilyName' => event.get('assignedTo_second_family_name'),
                'completeName' => **_WHAT HERE?_**			
            }

        ... more code here ...

            event.cancel()
        "
        push_previous_map_as_event => true
        timeout => 10
    }
}

```

First 3 fields come from ticket. AssignedTo is the user that holds the ticket, that is mapped to ES as _Object_ inside ticket.

I am getting everything mapped correctly to ES, only missing 'completeName', that sholud be: _FirstName FamilyName SecondFamilyName_.

Thanks for help.

Regards.

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [March 8, 2018, 12:45pm UTC](https://discuss.elastic.co/t/combine-fields-inside-aggregation-filter/123048/2 "2018-03-08T12:45:06Z")

</div>

You can use the usual Ruby string concatenation methods. One example would be this.

```auto
            map['assignedTo'] = {
                'id' => event.get('assignedTo_id'),
                'userName' => event.get('assignedTo_username'),
                'firstName' => event.get('assignedTo_first_name'),
                'familyName' => event.get('assignedTo_family_name'),
                'secondFamilyName' => event.get('assignedTo_second_family_name'),
                'completeName' => [event.get('FirstName').to_s, event.get('SecondName').to_s, event.get('LastName').to_s].join(' ')			
            }
```

---

<div class="post-metadata">

**Author:** ![daniender](https://avatars.discourse-cdn.com/v4/letter/d/9d8465/32.png) [@daniender](https://discuss.elastic.co/u/daniender)\
**Post date:** [March 9, 2018, 8:24am UTC](https://discuss.elastic.co/t/combine-fields-inside-aggregation-filter/123048/3 "2018-03-09T08:24:24Z")

</div>

Thanks @paz for your answer. I will try it.

One more question. Does it matter if any of the fields is null or empty?

I mean, for example in Java if you try to concatenate 3 strings and one of them is null, you get an exception.

In this case, 'LastName' is null in many of the users...

Regards.

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [March 9, 2018, 10:15am UTC](https://discuss.elastic.co/t/combine-fields-inside-aggregation-filter/123048/4 "2018-03-09T10:15:09Z")

</div>

For this specific case, not really. _Join_ handles nils gracefully (whereas other Ruby functions/operations might be more picky).  
The only side-effect with null values would be having 2 join characters together in the final field (2 spaces in that specific case).

To avoid this, you can clear the array before performing join on it, like so:

```auto
            map['assignedTo'] = {
                ...,
                'completeName' => [event.get('FirstName').to_s, event.get('SecondName').to_s, event.get('LastName').to_s].reject(&:empty?).join(' ')			
            }
```

---

<div class="post-metadata">

**Author:** ![daniender](https://avatars.discourse-cdn.com/v4/letter/d/9d8465/32.png) [@daniender](https://discuss.elastic.co/u/daniender)\
**Post date:** [March 9, 2018, 10:24am UTC](https://discuss.elastic.co/t/combine-fields-inside-aggregation-filter/123048/5 "2018-03-09T10:24:44Z")

</div>

Great!!

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2018, 10:24am UTC](https://discuss.elastic.co/t/combine-fields-inside-aggregation-filter/123048/6 "2018-04-06T10:24:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
