# Copy data from a field and make it available for all the documents

**URL:** <https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735>\
**Category:** Logstash\
**Created:** [January 10, 2019, 12:35pm UTC](https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735 "2019-01-10T12:35:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 10, 2019, 12:35pm UTC](https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735/1 "2019-01-10T12:35:30Z")

</div>

I am using grok filter to pass the number from a document of field message.

For instance,

> The build ID of the run is : 128

From the above document entry I have used grok to extract "128" to a new field.

However , the problem is that when I use "discover" to search for "128" only one entry of it is available.

![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/7552bd7cd6f4555a882cfed4fe323ff9bac1acc0.png)

Is there a way to pass the field value (that holds 128) to all the documents such that each entry holds the number .

I have tried using logstash-jenkins plugin , but I am not able to use grok in the plugin.

Please help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 10, 2019, 8:16pm UTC](https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735/2 "2019-01-10T20:16:51Z")

</div>

Can you provide some more detail? What does your current logstash configuration look like and what do the logs look like.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 11, 2019, 6:36am UTC](https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735/3 "2019-01-11T06:36:46Z")

</div>

@Badger Thank you for responding.

I am using the below logstash configuration :

> input {  
> beats {  
> port =\> 5044  
> ssl =\> true  
> ssl\_certificate =\> "/security/logstash.crt"  
> ssl\_key =\> "/security/logstash.key"  
> }  
> }  
> filter {  
> grok {  
> match =\> { "message" =\> "^The build ID of the run is : %{NUMBER:filteredValues}" }  
> }  
> }

I am able to successfully get the number (i.e 128) in the new field "filteredValues" . The filter is from the message field and the entry of the document (The build ID of the run is : 128) is only once. As the entry of the document is only once , I am able to see the number , 128, only once in the discover feature of Kibana. **What I am looking for is a way to make the number -128 available for all the entry documents.** i.e make the number 128 visible for any entry . Right now all the other entries remain blank as can be seen in the below log picture.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/7552bd7cd6f4555a882cfed4fe323ff9bac1acc0.png)

How do you think can this be made possible ?

The number is basically a unique ID which I am generating using Jenkins for a particular sequence of jobs. The unique number gets incremented when a new flow of jenkins jobs is triggered. I am not looking to use any Build ID, but only the unique number that I am generating through a shell script.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 11, 2019, 8:03am UTC](https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735/4 "2019-01-11T08:03:18Z")

</div>

I cannot see any way to do that based on the information you have given us.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 11, 2019, 9:20am UTC](https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735/5 "2019-01-11T09:20:37Z")

</div>

Okay @Badger . Thank you.

I am trying to use fingerprint plugin here.

Also will it be possible to pass the number in the filebeat index name ??

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2019, 9:20am UTC](https://discuss.elastic.co/t/copy-data-from-a-field-and-make-it-available-for-all-the-documents/163735/6 "2019-02-08T09:20:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
