# Filter mutate add\_field from nested field

**URL:** <https://discuss.elastic.co/t/filter-mutate-add-field-from-nested-field/170231>\
**Category:** Logstash\
**Created:** [February 27, 2019, 7:20pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-from-nested-field/170231 "2019-02-27T19:20:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Welton\_Leao\_Machado](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@Welton\_Leao\_Machado](https://discuss.elastic.co/u/Welton_Leao_Machado)\
**Post date:** [February 27, 2019, 7:20pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-from-nested-field/170231/1 "2019-02-27T19:20:32Z")

</div>

i'm trying to catch a nested field to add in a new field with mutate add\_field

So, i have the follow data

"beat" =\> {  
"name" =\> "LBR001001-172.net.mapfre.com.br",  
"hostname" =\> "LBR001001-172.net.mapfre.com.br",  
"version" =\> "6.6.1"  
}

I want the nested field "name" or "hostname"

I tried the following way

```
mutate {
			add_field => { "hostname" => [beat][hostname]}
		}

```

and

```
mutate {
			add_field => { "hostname" => "[beat][hostname]"}
		}

```

and

```
mutate {
			add_field => { "hostname" => "%{beat.hostname}"}
		}

```

But...

I still can not get the field nested

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [February 27, 2019, 7:25pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-from-nested-field/170231/2 "2019-02-27T19:25:39Z")

</div>

You were super close! you'll need to use the [sprintf syntax](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf), and use a [field reference](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references) to reference the specific field.

```auto
mutate {
  add_field => { "hostname" => "%{[beat][hostname]}" }
}

```

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [February 27, 2019, 7:27pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-from-nested-field/170231/3 "2019-02-27T19:27:37Z")

</div>

If you're looking to _copy_ the field to a new location, the Mutate Filter Plugin's [`copy` directive](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-copy) may be a better match.

```auto
mutate {
  copy => { "[beat][hostname]" => "hostname" }
}

```

---

<div class="post-metadata">

**Author:** ![Welton\_Leao\_Machado](https://avatars.discourse-cdn.com/v4/letter/w/c4cdca/32.png) [@Welton\_Leao\_Machado](https://discuss.elastic.co/u/Welton_Leao_Machado)\
**Post date:** [February 28, 2019, 2:06pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-from-nested-field/170231/4 "2019-02-28T14:06:19Z")

</div>

Must later i tried that way and i catched the field.Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2019, 2:06pm UTC](https://discuss.elastic.co/t/filter-mutate-add-field-from-nested-field/170231/5 "2019-03-28T14:06:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
