# Copy a field without making it a hash value?

**URL:** <https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342>\
**Category:** Logstash\
**Created:** [September 13, 2016, 4:33am UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342 "2016-09-13T04:33:01Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 13, 2016, 4:33am UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342/1 "2016-09-13T04:33:01Z")

</div>

Hi I have an array field. And i want to copy it without turning it to a hash data type, which is what "add\_field" does. Is there any ideas? Tks!

PS: the reason i want to do it is because i now have field **search\_terms** = [0]good, [1] day; and i want to ALSO have a new field **search\_query** = "good day". Both fields **at same time.**

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 13, 2016, 5:49am UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342/2 "2016-09-13T05:49:55Z")

</div>

Well, you could always use a ruby filter to make low-level manipulations of events. But I don't get what you mean by this:

> And i want to copy it without turning it to a hash data type, which is what "add\_field" does

Could you give an example?

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 13, 2016, 5:49pm UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342/3 "2016-09-13T17:49:45Z")

</div>

Sure...for example, i have an array field **search\_terms** = [0]good, [1] day. If i add\_field "temp" =\> "%{search\_terms}", this field **temp** will not be able to join, since it is a hash data type. It can not be converted in to any other format, only the hash format as: **good,day**.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 13, 2016, 6:04pm UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342/4 "2016-09-13T18:04:26Z")

</div>

Your use of the word "hash" is incorrect. There is no hash involved here. This shows why concrete examples with configuration snippets and copy/paste from terminal windows is so useful and reduces confusion.

If you want to join the `search_terms` array with spaces instead of commas without overwriting the original field you can use a ruby filter. Or, maybe using the mutate filter's gsub option to replace the commas in the joined string with spaces would work.

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 13, 2016, 6:36pm UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342/5 "2016-09-13T18:36:03Z")

</div>

Hi I want to have **search\_terms** both in an **array** format and as a **phrase**. If i join search\_terms, i would not have it as array format. If I copy search\_term using **add\_field** , the copied value is a hash data type, based on the online documentation, and become "good,day" only, not changeable to any other format...([https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html))

**Below is my config FYI:**  
originally k = good++day  
mutate {  
gsub =\> ["k", "[++]", " "]  
split =\> { "k" =\> " " }  
add\_field =\> { "search\_terms"=\> "%{k}" }  
join =\> { "search\_terms" =\> " "} ## search\_terms = good,day, as a hash data type, per the documentation  
gsub =\> ["search\_terms", "[,]", " "] ## nothing will be done since gsub doesn't work on hash type  
}

---

<div class="post-metadata">

**Author:** ![Allie\_Yang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/allie_yang/32/16538_2.png) [@Allie\_Yang](https://discuss.elastic.co/u/Allie_Yang)\
**Post date:** [September 13, 2016, 6:39pm UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342/6 "2016-09-13T18:39:28Z")

</div>

As for Ruby, is it similar like below? Would you point out the syntax error pls...coz i never write ruby:

Ruby{  
init =\> "search\_terms" = "%{k}"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 13, 2016, 7:51pm UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342/7 "2016-09-13T19:51:13Z")

</div>

The reason your mutate filter doesn't work as expected is that the options aren't applied in the order you specify them. The order is instead defined here:

> <https://github.com/logstash-plugins/logstash-filter-mutate/blob/v3.1.1/lib/logstash/filters/mutate.rb#L202-L217>

In other words, the gsub will happen first, then the join (and finally the add\_field). You have to use multiple mutate filters.

> If I copy search\_term using add\_field, the copied value is a hash data type, based on the online documentation

You are interpreting the documentation incorrectly.

> As for Ruby, is it similar like below?

No. Something like

```plaintext
ruby {
  code => "
    event['search_terms'] = event['k'].join(' ')
  "
}

```

should work though.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:38am UTC](https://discuss.elastic.co/t/copy-a-field-without-making-it-a-hash-value/60342/8 "2017-07-06T04:38:40Z")

</div>


