# How to add\_field in index using logstash and output of a search query of same index

**URL:** <https://discuss.elastic.co/t/how-to-add-field-in-index-using-logstash-and-output-of-a-search-query-of-same-index/177326>\
**Category:** Logstash\
**Created:** [April 17, 2019, 3:01pm UTC](https://discuss.elastic.co/t/how-to-add-field-in-index-using-logstash-and-output-of-a-search-query-of-same-index/177326 "2019-04-17T15:01:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![msk\_76](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@msk\_76](https://discuss.elastic.co/u/msk_76)\
**Post date:** [April 17, 2019, 3:01pm UTC](https://discuss.elastic.co/t/how-to-add-field-in-index-using-logstash-and-output-of-a-search-query-of-same-index/177326/1 "2019-04-17T15:01:05Z")

</div>

\*\ ***I have below data stored in an elasticsearch index**  
{  
"prospector" =\> {  
"type" =\> "log"  
},  
"message" =\> "11/1/2018 10:05:00,fabrice,eldo,7,100",  
"@timestamp" =\> 2019-04-17T05:44:47.133Z,  
"SITE" =\> "GRENOBLE",  
"source" =\> "/home/msk/strgrept/CAD\_REPORTS/USAGE\_REPORTS/2018/try/PA\_lic\_usage4.csv",  
"LIC\_TOTAL" =\> 100,  
"@version" =\> "1",  
"fields" =\> {  
"document\_type" =\> "usage-type"  
},  
"GROUP" =\> "TRD",  
"division" =\> "TRD\_GNB",  
"DATE" =\> "11/1/2018 10:05:00",  
"LIC\_USAGE" =\> 7,  
"offset" =\> 933,  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied"  
],  
"USER" =\> "fabrice",  
"LIC\_FEATURE\_NAME" =\> "eldo",  
"beat" =\> {  
"version" =\> "6.4.2",  
"name" =\> "dlhl2117",  
"hostname" =\> "dlhl2117" },  
"host" =\> { "name" =\> "dlhl2117" },  
"TIME\_STAMP" =\> "2018-11-01T04:35:00.000Z",  
"input" =\> { "type" =\> "log" } }  
{  
"prospector" =\> {  
"type" =\> "log" },  
"message" =\> "11/1/2018 10:05:00,narwal,eldo,2,100",  
"@timestamp" =\> 2019-04-17T05:44:47.132Z,  
"SITE" =\> "GREATER NOIDA",  
"source" =\> "/home/msk/strgrept/CAD\_REPORTS/USAGE\_REPORTS/2018/try/PA\_lic\_usage4.csv",  
"LIC\_TOTAL" =\> 100,  
"@version" =\> "1",  
"fields" =\> {  
"document\_type" =\> "usage-type" },  
"GROUP" =\> "ADG",  
"division" =\> "ADG\_MICRO",  
"DATE" =\> "11/1/2018 10:05:00",  
"LIC\_USAGE" =\> 2,  
"offset" =\> 603,  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied" ],  
"USER" =\> "narwal",  
"LIC\_FEATURE\_NAME" =\> "eldo",  
"beat" =\> {  
"version" =\> "6.4.2",  
"name" =\> "dlhl2117",  
"hostname" =\> "dlhl2117" },  
"host" =\> { "name" =\> "dlhl2117" },  
"TIME\_STAMP" =\> "2018-11-01T04:35:00.000Z",  
"input" =\> { "type" =\> "log" } }  
{  
"prospector" =\> {  
"type" =\> "log"  
},  
"message" =\> "11/1/2018 10:00:00,paul,eldo,1,100",  
"@timestamp" =\> 2019-04-17T05:44:47.132Z,  
"SITE" =\> "GRENOBLE",  
"source" =\> "/home/msk/strgrept/CAD\_REPORTS/USAGE\_REPORTS/2018/try/PA\_lic\_usage4.csv",  
"LIC\_TOTAL" =\> 100,  
"@version" =\> "1",  
"fields" =\> {  
"document\_type" =\> "usage-type"  
},  
"GROUP" =\> "TRD",  
"division" =\> "TRD\_MEMS",  
"DATE" =\> "11/1/2018 10:00:00",  
"LIC\_USAGE" =\> 1,  
"offset" =\> 489,  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied"  
],  
"USER" =\> "paul",  
"LIC\_FEATURE\_NAME" =\> "eldo",  
"beat" =\> {  
"version" =\> "6.4.2",  
"name" =\> "dlhl2117",  
"hostname" =\> "dlhl2117"  
},  
"host" =\> {  
"name" =\> "dlhl2117"  
},  
"TIME\_STAMP" =\> "2018-11-01T04:30:00.000Z",  
"input" =\> {  
"type" =\> "log"  
}  
}  
{  
"prospector" =\> {  
"type" =\> "log"  
},  
"message" =\> "11/1/2018 10:00:00,shamsi,eldo,1,100",  
"@timestamp" =\> 2019-04-17T05:44:47.132Z,  
"SITE" =\> "GREATER NOIDA",  
"source" =\> "/home/msk/strgrept/CAD\_REPORTS/USAGE\_REPORTS/2018/try/PA\_lic\_usage4.csv",  
"LIC\_TOTAL" =\> 100,  
"@version" =\> "1",  
"fields" =\> {  
"document\_type" =\> "usage-type"  
},  
"GROUP" =\> "TRD",  
"division" =\> "TRD\_MEMS",  
"DATE" =\> "11/1/2018 10:00:00",  
"LIC\_USAGE" =\> 1,  
"offset" =\> 265,  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied"  
],  
"USER" =\> "shamsi",  
"LIC\_FEATURE\_NAME" =\> "eldo",  
"beat" =\> {  
"version" =\> "6.4.2",  
"name" =\> "dlhl2117",  
"hostname" =\> "dlhl2117"  
},  
"host" =\> {  
"name" =\> "dlhl2117"  
},  
"TIME\_STAMP" =\> "2018-11-01T04:30:00.000Z",  
"input" =\> {  
"type" =\> "log"  
}  
}

**I have to execute the below query on this index itself, the output of which is to be stored in an new field based on matching division field in the same index.**

{  
"aggs": {  
"hr": {  
"date\_histogram": {  
"field": "TIME\_STAMP",  
"interval": "5m",  
"format": "dd-MM-yyyy hh:mm:ss" },  
"aggs": { "site": { "terms": { "field": "SITE.keyword" }, "aggs": { "group": { "terms": { "field": "GROUP" }, "aggs": { "division": { "terms": {"field": "DIVISION" }, "aggs": { SUM\_LICU\_BY\_DIVISION": { "sum": { "field": "LIC\_USAGE" } } } } } } } } } } } }

**For example, field "SUM\_LICU\_BY\_DIVISION" of given DIVISION( in output of query) should be stored in corresponding(matched) DIVISION in data as new field for the same TIME\_STAMP & same SITE.**  
**The output expected is :**

|Time|Site|Group|Division|User|Lic Feature|Lic Usage|Lic Total| **SUM\_LICU\_BY\_DIVISON** |  
|11/1/2018 10:00|GREATER NOIDA|ADG|ADG\_MICRO|rajeshb|eldo|2|100|5|  
|11/1/2018 10:00|GREATER NOIDA|ADG|ADG\_MICRO|narwal|eldo|3|100|5|  
|11/1/2018 10:00|GREATER NOIDA|ADG|ADG\_RF|das|eldo|4|100|4|  
|11/1/2018 10:00|GREATER NOIDA|TRD|TRD\_LAB|ashu|eldo|3|100|9|  
|11/1/2018 10:00|GREATER NOIDA|TRD|TRD\_LAB|vivek|eldo|6|100|9|  
|11/1/2018 10:00|GREATER NOIDA|TRD|TRD\_MEMS|bally|eldo|1|100|2|  
|11/1/2018 10:00|GREATER NOIDA|TRD|TRD\_MEMS|shamsi|eldo|1|100|2|  
|11/1/2018 10:00|GRENOBLE|ADG|ADG\_MICRO|pcm|eldo|2|100|2|  
|11/1/2018 10:00|GRENOBLE|ADG|ADG\_GNB|JPM|eldo|3|100|3|  
|11/1/2018 10:00|GRENOBLE|ADG|ADG\_RF|olivier|eldo|4|100|4|  
|11/1/2018 10:00|GRENOBLE|TRD|TRD\_GNB|fabrice|eldo|3|100|3|  
|11/1/2018 10:00|GRENOBLE|TRD|TRD\_LAB|arnaud|eldo|6|100|6|  
|11/1/2018 10:00|GRENOBLE|TRD|TRD\_MEMS|paul|eldo|1|100|2|  
|11/1/2018 10:00|GRENOBLE|TRD|TRD\_MEMS|sylvain|eldo|1|100|2|  
|11/1/2018 10:05|GREATER NOIDA|ADG|ADG\_MICRO|rajeshb|eldo|1|100|3|  
|11/1/2018 10:05|GREATER NOIDA|ADG|ADG\_MICRO|narwal|eldo|2|100|3|  
|11/1/2018 10:05|GREATER NOIDA|ADG|ADG\_RF|das|eldo|3|100|3|  
|11/1/2018 10:05|GREATER NOIDA|TRD|TRD\_LAB|ashu|eldo|4|100|10|  
|11/1/2018 10:05|GREATER NOIDA|TRD|TRD\_LAB|vivek|eldo|6|100|10|  
|11/1/2018 10:05|GREATER NOIDA|TRD|TRD\_MEMS|bally|eldo|2|100|3|  
|11/1/2018 10:05|GREATER NOIDA|TRD|TRD\_MEMS|shamsi|eldo|1|100|3|  
|11/1/2018 10:05|GRENOBLE|ADG|ADG\_MICRO|pcm|eldo|5|100|5|  
|11/1/2018 10:05|GRENOBLE|ADG|ADG\_GNB|JPM|eldo|2|100|2|  
|11/1/2018 10:05|GRENOBLE|ADG|ADG\_RF|olivier|eldo|3|100|3|  
|11/1/2018 10:05|GRENOBLE|TRD|TRD\_GNB|fabrice|eldo|7|100|7|  
|11/1/2018 10:05|GRENOBLE|TRD|TRD\_LAB|arnaud|eldo|5|100|5|  
|11/1/2018 10:05|GRENOBLE|TRD|TRD\_MEMS|paul|eldo|1|100|2|  
|11/1/2018 10:05|GRENOBLE|TRD|TRD\_MEMS|sylvain|eldo|1|100|2|

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2019, 3:01pm UTC](https://discuss.elastic.co/t/how-to-add-field-in-index-using-logstash-and-output-of-a-search-query-of-same-index/177326/2 "2019-05-15T15:01:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
