# Copying field in from one event to other in logstash

**URL:** <https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621>\
**Category:** Logstash\
**Created:** [March 3, 2019, 12:09pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621 "2019-03-03T12:09:13Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pranav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranav/32/135850_2.png) [@Pranav](https://discuss.elastic.co/u/Pranav)\
**Post date:** [March 3, 2019, 12:09pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/1 "2019-03-03T12:09:13Z")

</div>

Can anyone tell me if I can copy a field from one event to another in logstash based on a unique\_key present in both the events?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2019, 1:08pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/2 "2019-03-03T13:08:34Z")

</div>

You might be able to do it with an aggregate filter.

---

<div class="post-metadata">

**Author:** ![Pranav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranav/32/135850_2.png) [@Pranav](https://discuss.elastic.co/u/Pranav)\
**Post date:** [March 4, 2019, 5:43am UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/3 "2019-03-04T05:43:19Z")

</div>

can you please share the config... I have been trying to solve this from a long time now..

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 4, 2019, 1:27pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/4 "2019-03-04T13:27:20Z")

</div>

That depends on what the events look like.

---

<div class="post-metadata">

**Author:** ![Pranav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranav/32/135850_2.png) [@Pranav](https://discuss.elastic.co/u/Pranav)\
**Post date:** [March 4, 2019, 1:28pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/5 "2019-03-04T13:28:33Z")

</div>

Should I share the logs?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 4, 2019, 1:37pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/6 "2019-03-04T13:37:49Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![Pranav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranav/32/135850_2.png) [@Pranav](https://discuss.elastic.co/u/Pranav)\
**Post date:** [March 4, 2019, 1:47pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/7 "2019-03-04T13:47:12Z")

</div>

These are the logs:  
{  
{  
"\_index": "agent",  
"\_type": "doc",  
"\_id": "GYmqSGkB5QCX5-g3yFpy",  
"\_score": 1,  
"\_source": {  
"host": "C02X5KQ4JG5H.group.on",  
"@version": "1",  
"@timestamp": "2019-03-04T12:25:45.734Z",  
"\_time": "2019-02-20T09:02:16.842+0000”,  
"Email": "c\_adimlich@xyz.com",  
"Status": “break,  
"preview": false,  
"FirstName": "Adil "  
},  
{  
"\_index": "agent",  
"\_type": "doc",  
"\_id": "24mqSGkB5QCX5-g3yFYF",  
"\_score": 1,  
"\_source": {  
"host": "C02X5KQ4JG5H.group.on",  
"@version": "1",  
"@timestamp": "2019-03-04T12:25:45.588Z",  
"\_time": "2019-02-20T09:02:14.842+0000”,  
"Email": "c\_hesbahi@xyz.com",  
"Status": "Unavailable",  
"preview": false,  
"FirstName": “Hamza”  
},  
{  
"\_index": "agent",  
"\_type": "doc",  
"\_id": "GYmqSGkB5QCX5-g3yFpy",  
"\_score": 1,  
"\_source": {  
"host": "C02X5KQ4JG5H.xyz.on",  
"@version": "1",  
"@timestamp": "2019-03-04T12:25:45.734Z",  
"\_time": "2019-02-20T09:02:18.766+0000”,  
"Email": "c\_adimlich@xyz.com",  
"Status": “eating,  
"preview": false,  
"FirstName": "Adil"  
}  
}

Is there a way in which we can merge the logs with the Firstname as "Adil" ? Here email can work as a unique key.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 4, 2019, 2:10pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/8 "2019-03-04T14:10:25Z")

</div>

If you use

```
    aggregate {
        task_id => "%{Email}"
        code => '
            if map["FirstName"]
                event.set("FirstName", map["FirstName"])
            else
                map["FirstName"] = event.get("FirstName")
            end
        '
    }

```

then every event for each Email will have the same FirstName. However, since order is not preserved you cannot be sure which FirstName the filter will see first.

Note that you must have --pipeline.workers set to 1.

---

<div class="post-metadata">

**Author:** ![Pranav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pranav/32/135850_2.png) [@Pranav](https://discuss.elastic.co/u/Pranav)\
**Post date:** [March 4, 2019, 2:25pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/9 "2019-03-04T14:25:04Z")

</div>

Thanks for the solution Badger.  
I tried this earlier but this is creating some extra logs with multiple values in a field and that too similar values something like:

 ![36%20PM](https://us1.discourse-cdn.com/elastic/original/3X/c/a/ca1fe5a23b3876ca5db43925358dba811fec0c3c.png)

And yes you are right, order is not preserved maybe that's why its showing this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2019, 2:25pm UTC](https://discuss.elastic.co/t/copying-field-in-from-one-event-to-other-in-logstash/170621/10 "2019-04-01T14:25:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
