# Custom add\_field storing as an array with value duplicated in Elasticsearch

**URL:** <https://discuss.elastic.co/t/custom-add-field-storing-as-an-array-with-value-duplicated-in-elasticsearch/117277>\
**Category:** Logstash\
**Created:** [January 27, 2018, 12:06am UTC](https://discuss.elastic.co/t/custom-add-field-storing-as-an-array-with-value-duplicated-in-elasticsearch/117277 "2018-01-27T00:06:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nodesocket](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nodesocket/32/27023_2.png) [@nodesocket](https://discuss.elastic.co/u/nodesocket)\
**Post date:** [January 27, 2018, 12:06am UTC](https://discuss.elastic.co/t/custom-add-field-storing-as-an-array-with-value-duplicated-in-elasticsearch/117277/1 "2018-01-27T00:06:50Z")

</div>

Hello. I am trying to add a custom field **msgid** and while the groc and field is working, the result is an array with the value duplicated twice.

Here is an example raw message:

```
Jan 26 22:58:01 ip-172-31-23-201 mailqueued: [1822bd7c-02e6-11e8-b20a-b566ad59a605] [90] Retry message in 120 minutes (retry: 3 of 30, increment_retry)

```

And the Logstash groc match:

```
%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: \[%{UUID:msgid}\] %{GREEDYDATA:syslog_message}

```

The Logstash field:

```
add_field => ["msgid", "%{msgid}"]

```

In Elasticsearch it is saving as:

```
"msgid": [
    "1822bd7c-02e6-11e8-b20a-b566ad59a605",
    "1822bd7c-02e6-11e8-b20a-b566ad59a605"
]

```

I want to store as a flat value, no array, and no duplicates. Ideas?

---

<div class="post-metadata">

**Author:** ![Vladi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vladi/32/108686_2.png) [@Vladi](https://discuss.elastic.co/u/Vladi)\
**Post date:** [January 27, 2018, 5:19am UTC](https://discuss.elastic.co/t/custom-add-field-storing-as-an-array-with-value-duplicated-in-elasticsearch/117277/2 "2018-01-27T05:19:53Z")

</div>

> [@nodesocket](#):
>
> The Logstash field:
> 
> add\_field =\> ["msgid", "%{msgid}"]

Justin, your output is exactly correct.  
The code **`add_field => ["msgid", "%{msgid}"]`** just dupicates the value from grok.  
"..(?:[%{POSINT:syslog\_pid}])?: [%{ **UUID:msgid** }] %{GREEDYDATA:syslog\_message}.."  
Just comment the line **#add\_field =\> ["msgid", "%{msgid}"]** and it will be solved. Or rename you custome field add\_field =\> ["msgid\_renamed", "%{msgid}"]

---

<div class="post-metadata">

**Author:** ![nodesocket](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nodesocket/32/27023_2.png) [@nodesocket](https://discuss.elastic.co/u/nodesocket)\
**Post date:** [January 28, 2018, 8:40pm UTC](https://discuss.elastic.co/t/custom-add-field-storing-as-an-array-with-value-duplicated-in-elasticsearch/117277/3 "2018-01-28T20:40:38Z")

</div>

@Vladi thanks for the reply. My misunderstanding. I thought I had to setup the groc to capture, and then `add_field` separately. Thanks so much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 25, 2018, 8:40pm UTC](https://discuss.elastic.co/t/custom-add-field-storing-as-an-array-with-value-duplicated-in-elasticsearch/117277/4 "2018-02-25T20:40:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
