# Get filter value in add\_field

**URL:** <https://discuss.elastic.co/t/get-filter-value-in-add-field/182946>\
**Category:** Logstash\
**Created:** [May 27, 2019, 4:11pm UTC](https://discuss.elastic.co/t/get-filter-value-in-add-field/182946 "2019-05-27T16:11:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![kentatoi](https://avatars.discourse-cdn.com/v4/letter/k/9fc348/32.png) [@kentatoi](https://discuss.elastic.co/u/kentatoi)\
**Post date:** [May 27, 2019, 4:11pm UTC](https://discuss.elastic.co/t/get-filter-value-in-add-field/182946/1 "2019-05-27T16:11:50Z")

</div>

Hi,  
I would like to get the path of my logs from Filebeat split it and get the name of my app\_serv as a new field. I am using ELK-stack 6.6.0

Here that is what I am trying :

```
input { stdin { } }
filter {

  grok {
    patterns_dir => "/u01/app/elk-config/logstash/patterns"
    match => { "message" => "%{COMMONAPACHELOG}" }
    match => { "source" => "/u01/app/oracle/admin/%{DATA:domain}/%{DATA:app_server}/logs/%{DATA:filename}"}
  }
  mutate {
    add_field => {"app_server" => "%{app_server}"}
  }

}
output {

  stdout { codec => rubydebug }

}

```

but when I do that the value in the output doesn't show up. It seems Logstash doesn't recognize my filter name or Is it because the source path is null ?

```
"app_server" => "%{app_server}",
      "timestamp" => "27/Apr/2019:22:15:00 -0400",
       "response" => "404",
       "@version" => "1",
           "auth" => "-"

```

Thanks for your help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 27, 2019, 7:42pm UTC](https://discuss.elastic.co/t/get-filter-value-in-add-field/182946/2 "2019-05-27T19:42:33Z")

</div>

> [@kentatoi](#):
>
> mutate { add\_field =\> {"app\_server" =\> "%{app\_server}"} }

What are you trying to do with that. I sets app\_server to the value of app\_server if it exists, or to "%{app\_server} if it does not.

I do not see anything create a source field on an event, so that match in the grok filter is a no-op.

---

<div class="post-metadata">

**Author:** ![kentatoi](https://avatars.discourse-cdn.com/v4/letter/k/9fc348/32.png) [@kentatoi](https://discuss.elastic.co/u/kentatoi)\
**Post date:** [May 29, 2019, 12:59pm UTC](https://discuss.elastic.co/t/get-filter-value-in-add-field/182946/3 "2019-05-29T12:59:03Z")

</div>

Thanks for your answer. That is what I though but how can I split the file path that I send to Logstash by filebeat, get the filename part and create a field with that ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 29, 2019, 1:02pm UTC](https://discuss.elastic.co/t/get-filter-value-in-add-field/182946/4 "2019-05-29T13:02:39Z")

</div>

You can extract the filename from a path using

```
grok { match => { "someField" => "/(?<filename>[^/]+)$" } }
```

---

<div class="post-metadata">

**Author:** ![kentatoi](https://avatars.discourse-cdn.com/v4/letter/k/9fc348/32.png) [@kentatoi](https://discuss.elastic.co/u/kentatoi)\
**Post date:** [May 30, 2019, 4:32pm UTC](https://discuss.elastic.co/t/get-filter-value-in-add-field/182946/5 "2019-05-30T16:32:52Z")

</div>

Thanks for your answer . I found what I needed

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2019, 4:33pm UTC](https://discuss.elastic.co/t/get-filter-value-in-add-field/182946/6 "2019-06-27T16:33:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
