# Core vs extended field regarding a mutate error

**URL:** <https://discuss.elastic.co/t/core-vs-extended-field-regarding-a-mutate-error/298653>\
**Category:** Logstash\
**Created:** [March 2, 2022, 5:33pm UTC](https://discuss.elastic.co/t/core-vs-extended-field-regarding-a-mutate-error/298653 "2022-03-02T17:33:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [March 2, 2022, 5:33pm UTC](https://discuss.elastic.co/t/core-vs-extended-field-regarding-a-mutate-error/298653/1 "2022-03-02T17:33:41Z")

</div>

I'm getting a mutate error where the "host" value is being set to the "device\_hostname"but was wondering if it's because one is a core field and the other is an extended field?

Here is what is being applied in my filter:

```auto
"host "=> "[host][hostname]"
"device_hostname" => "[host][id]"

```

That said, it seems to be the similar problem as this link correct? :

> [@Error when copying a field to multiple others in a single mutate block](https://discuss.elastic.co/t/error-when-copying-a-field-to-multiple-others-in-a-single-mutate-block/234709):
>
> I noticed today, that copying the same field to multiple destinations inside the same mutate block, leads to a \_mutate\_error. Splitting the copy operation up to two mutate blocks works without any problem. Is this an intended behavior or should this be considered a bug? The following logstash.yml leads to a \_mutate\_error tag. input { generator { lines =\> [ 'May 28 11:11:01 threatarmor ta:BLOCKED\_CONNECTION: UTC\_TIME\_MS="1590657056547" LOCAL\_IP="1.1.1.1" …

Correct me if I'm wrong but rather than "copy" in the referenced article we are working with one "host" object due to "[host][hostname]" and "[host][id]" . Where one is a core field and the other is an extended, when my intent is to have them separate objects.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 2, 2022, 6:01pm UTC](https://discuss.elastic.co/t/core-vs-extended-field-regarding-a-mutate-error/298653/2 "2022-03-02T18:01:55Z")

</div>

What is your mutate filter configuration?

---

<div class="post-metadata">

**Author:** ![itschobot](https://avatars.discourse-cdn.com/v4/letter/i/439d5e/32.png) [@itschobot](https://discuss.elastic.co/u/itschobot)\
**Post date:** [March 2, 2022, 8:08pm UTC](https://discuss.elastic.co/t/core-vs-extended-field-regarding-a-mutate-error/298653/3 "2022-03-02T20:08:45Z")

</div>

Here is my filter, it's the second mutate that I'm having issues with:

```auto
filter {
  if "some_platform" in [ls-source] {
   json { source => "message" }
   json { source => "message" }
   mutate { gsub => ["message", "^[^{]+", "" ] }
   json { source => "message" }
  
  mutate{
    add_field => {
      "event_type" => "%{[fields][event_type]}"
      "log_offset" => "%{[log][offset]}"
      "log_filepath" => "%{[log][file][path]}"
      "agent_name" => "%{[agent][hostname]}"
      "agent_id" => "%{[agent][id]}"
      "agent_version" => "%{[agent][version]}"
      "ephemeral_id" => "%{[agent][ephemeral_id]}"
      "type" => "%{[agent][type]}"
      "device_label" => "%{[device][label]}"
      "device_ip" => "%{[device][ip]}"
      "device_hostname" => "%{[device][hostname]}"
      "device_macaddress" => "%{[device][macaddress]}"
      "device_vendor" => "%{[device][vendor]}"
      "priority" => "%{[model][priority]}"
      "model_description" => "%{[model][description]}"
      "ecs_version" => "%{[ecs][version]}"
   }
  }
  
  mutate{
   rename => {
    "@timestamp" => "[event][ingested]"
    "event_type" => "[event][type]"
    "ls-source" => "[event][category]"
    "priority" => "[event][risk_score]"
    "score" => "[event][risk_score_norm]"
    "host "=> "[host][hostname]"
    "device_hostname" => "[host][id]"
    "device_ip" => "[host][ip]"
    "device_macaddress" => "[device][mac]"
    "port" => "[source][port]"
    "device_vendor" => "[observer][vendor]"
    "device_label" => "[observer][product]"
    "agent_name" => "[agent][name]"
    "agent_id" => "[agent][id]"
    "agent_version" => "[agent][version]"
    "breachUrl" => "[threat][enrichments][indicator][url][full]"
    "model_description" => "[threat][enrichments][indicator][description]"
    "creationTime" => "[event][created]"
    "origin" => "[event][id]"
    "log_type" => "[event][kind]"
    "log_offset" => "[log][offset]"
    "ephemeral_id" => "[ephemeral][id]"
    "pbid" => "[service][id]"
    "log_filepath" => "[log][file][path]"
    "@version" => "[observer][version]"
    "ecs_version" => "[ecs][version]"
   }
  }
  
 }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 2, 2022, 8:24pm UTC](https://discuss.elastic.co/t/core-vs-extended-field-regarding-a-mutate-error/298653/4 "2022-03-02T20:24:25Z")

</div>

Can you enable debug logging and tell us what gets logged [here](https://github.com/logstash-plugins/logstash-filter-mutate/blob/d45bfb7211fc0a11afd7dc917cefa295752cc63d/lib/logstash/filters/mutate.rb#L269).

Also, it is unclear why you would

```
mutate { add_field => { "ecs_version" => "%{[ecs][version]}" } }
mutate { rename => { "ecs_version" => "[ecs][version]" } }

```

which is going to be a no-op if the original [ecs][version] field exists and is a string. If it is not a string it will get converted to a string. If it does not exist then it will get set to the literal string "%{[ecs][version]}".

The same applies to several other fields.

What is your ecs\_compatibility setting? In particular, is [host] a string or an object?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2022, 8:24pm UTC](https://discuss.elastic.co/t/core-vs-extended-field-regarding-a-mutate-error/298653/5 "2022-03-30T20:24:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
