# How to add a field/value from a previuos log

**URL:** <https://discuss.elastic.co/t/how-to-add-a-field-value-from-a-previuos-log/29423>\
**Category:** Logstash\
**Created:** [September 16, 2015, 4:14pm UTC](https://discuss.elastic.co/t/how-to-add-a-field-value-from-a-previuos-log/29423 "2015-09-16T16:14:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![danygor](https://avatars.discourse-cdn.com/v4/letter/d/a8b319/32.png) [@danygor](https://discuss.elastic.co/u/danygor)\
**Post date:** [September 16, 2015, 4:14pm UTC](https://discuss.elastic.co/t/how-to-add-a-field-value-from-a-previuos-log/29423/1 "2015-09-16T16:14:50Z")

</div>

Hi all,

I am using ELK to store and search logs and I need some sort of aggregation over logs that are somehow correlated.  
My use case is as follows:

Log #1 contains field A and field B  
Log #2 contains field B and field C  
Log #3 contains field B and field D  
Log #4 contains field B and field E  
...

I want to add field A and its value in all the next log lines containing field B. During my search I found the aggregate filter plugin which performs a similar action but only adds its result on the final event of a task. Instead I could use the elasticsearch filter plugin but I realized the ELK stack takes some minutes to index/make available an event, so the filter will not find Log #1 if invoked shortly after Log #1.

I know what I need is quite simple so I'm sure there is a straightforward solution, but which one?

Many thanks,  
Daniele

---

<div class="post-metadata">

**Author:** ![danygor](https://avatars.discourse-cdn.com/v4/letter/d/a8b319/32.png) [@danygor](https://discuss.elastic.co/u/danygor)\
**Post date:** [September 18, 2015, 10:53am UTC](https://discuss.elastic.co/t/how-to-add-a-field-value-from-a-previuos-log/29423/2 "2015-09-18T10:53:44Z")

</div>

I eventually used the aggregate filter with the following configuration, don't know if this is efficient though:

```
if [A] {
  # field A is present
  aggregate {
    task_id => "%{B}"
    code => "map['stored_field_A'] = event['A']"
    map_action => "create"
  }
}
if ![A] {
  # field A is NOT present
  aggregate {
    task_id => "%{B}"
    code => "event['A'] = map['stored_field_A']"
    map_action => "update"
    timeout => 86400
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:28am UTC](https://discuss.elastic.co/t/how-to-add-a-field-value-from-a-previuos-log/29423/3 "2017-07-06T05:28:43Z")

</div>


