# Filter logstash - Add simple field

**URL:** <https://discuss.elastic.co/t/filter-logstash-add-simple-field/249490>\
**Category:** Logstash\
**Created:** [September 22, 2020, 9:33am UTC](https://discuss.elastic.co/t/filter-logstash-add-simple-field/249490 "2020-09-22T09:33:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thomas74](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@Thomas74](https://discuss.elastic.co/u/Thomas74)\
**Post date:** [September 22, 2020, 9:33am UTC](https://discuss.elastic.co/t/filter-logstash-add-simple-field/249490/1 "2020-09-22T09:33:01Z")

</div>

Hi,

I'm trying to assign a value to a field. This one is the same than another variable.

Here is my filter :

```auto
    filter{

      if !([fields][hostgroup]) {
        mutate {
          update => { "[fields][hostgroup]" => "default" }
        }
      }

      mutate {
        add_field => { "[@metadata][indexName]" => "%{[fields][hostgroup]}" }
      }

```

I use `[@metadata][indexName]` to create an index use a specific index into my output :

```auto
    index => "syslog_%{[@metadata][indexName]}"

```

The problem is my final index name is equal at : `syslog_%{[fields][hostgroup]}`

Can you help me to find my mistake ?

Best regards,

Thomas

---

<div class="post-metadata">

**Author:** ![Thomas74](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@Thomas74](https://discuss.elastic.co/u/Thomas74)\
**Post date:** [September 25, 2020, 8:31am UTC](https://discuss.elastic.co/t/filter-logstash-add-simple-field/249490/2 "2020-09-25T08:31:28Z")

</div>

I tests this config also :

```auto
    if [type] != "forti_log" and [type] != "syslog" and [type] != ""{
        mutate {
          update => { "[@metadata][indexName]" => "${[type]}" }
        }
    }

```

But same result 😕 :

`syslog_${[type]}`

On other forum they said that you can assign an object to another object like this but it doesn't work. What is the good syntax ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 25, 2020, 2:09pm UTC](https://discuss.elastic.co/t/filter-logstash-add-simple-field/249490/3 "2020-09-25T14:09:37Z")

</div>

> [@Thomas74](#):
>
> Can you help me to find my mistake ?

Look in the syslog\_%{[fields][hostgroup]} index and see what value the [fields][hostgroup] field has.

---

<div class="post-metadata">

**Author:** ![Thomas74](https://avatars.discourse-cdn.com/v4/letter/t/3bc359/32.png) [@Thomas74](https://discuss.elastic.co/u/Thomas74)\
**Post date:** [September 25, 2020, 2:39pm UTC](https://discuss.elastic.co/t/filter-logstash-add-simple-field/249490/4 "2020-09-25T14:39:04Z")

</div>

I finally found my mistake. I had to use mutate `copy` instead of "add\_field" or "update". But thanks @Badger for your answer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 23, 2020, 2:39pm UTC](https://discuss.elastic.co/t/filter-logstash-add-simple-field/249490/5 "2020-10-23T14:39:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
