# Combining two inputs how to access the fields

**URL:** <https://discuss.elastic.co/t/combining-two-inputs-how-to-access-the-fields/109415>\
**Category:** Logstash\
**Created:** [November 28, 2017, 2:35pm UTC](https://discuss.elastic.co/t/combining-two-inputs-how-to-access-the-fields/109415 "2017-11-28T14:35:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ericohtake](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericohtake/32/24539_2.png) [@ericohtake](https://discuss.elastic.co/u/ericohtake)\
**Post date:** [November 28, 2017, 2:35pm UTC](https://discuss.elastic.co/t/combining-two-inputs-how-to-access-the-fields/109415/1 "2017-11-28T14:35:37Z")

</div>

Hi,  
I have 2 inputs in a config file where I need to send a field from one to another if a condition is met. However I'm failing to find documentation on how to reference the fields living in different input events.

Below I put a simple example on what I'm trying to do to not overcomplicate the question, since my real requirement is to combine DB2 and Elasticsearch inputs.

```
input {
  generator {
    lines => ["1234"]
    count => 1
    type => "db"
  }

  generator {
    lines => ["5678"]
    count => 1
    type => "es"
  }
}

filter {
  if [type] == "db" {
    mutate {
      add_field => { "from_es_event" => "%{[type:es][message]}" }
    }
  }
}

```

This is the result expected:

> ```
> "sequence" => 0,
> "@timestamp" => 2017-11-29T01:57:02.933Z,
> "from_es_event" => "5678",
> "message" => "1234",
> "type" => "db"
> 
> ```

How can I accomplish this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 29, 2017, 6:38am UTC](https://discuss.elastic.co/t/combining-two-inputs-how-to-access-the-fields/109415/2 "2017-11-29T06:38:44Z")

</div>

Maybe the aggregate filter could help? This isn't a use case that Logstash handles very well.

---

<div class="post-metadata">

**Author:** ![ericohtake](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericohtake/32/24539_2.png) [@ericohtake](https://discuss.elastic.co/u/ericohtake)\
**Post date:** [November 29, 2017, 7:05am UTC](https://discuss.elastic.co/t/combining-two-inputs-how-to-access-the-fields/109415/3 "2017-11-29T07:05:30Z")

</div>

Thank you for your reply Magnus. I was analyzing the aggregate filter, but I'm not sure how to give the plugin the fields addresses (depending on the events) so it can do the lookup and add the field in the other event. Any idea how to address the field for a given event?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 29, 2017, 7:23am UTC](https://discuss.elastic.co/t/combining-two-inputs-how-to-access-the-fields/109415/4 "2017-11-29T07:23:22Z")

</div>

No, sorry. I've never used that filter.

---

<div class="post-metadata">

**Author:** ![ericohtake](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ericohtake/32/24539_2.png) [@ericohtake](https://discuss.elastic.co/u/ericohtake)\
**Post date:** [November 29, 2017, 9:39am UTC](https://discuss.elastic.co/t/combining-two-inputs-how-to-access-the-fields/109415/5 "2017-11-29T09:39:57Z")

</div>

No problem. I will index both datasets and reindex using LS query with joins.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2017, 9:40am UTC](https://discuss.elastic.co/t/combining-two-inputs-how-to-access-the-fields/109415/6 "2017-12-27T09:40:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
