# How to add field using Environment plugin in Logstash configuration file

**URL:** <https://discuss.elastic.co/t/how-to-add-field-using-environment-plugin-in-logstash-configuration-file/92717>\
**Category:** Logstash\
**Created:** [July 11, 2017, 8:49pm UTC](https://discuss.elastic.co/t/how-to-add-field-using-environment-plugin-in-logstash-configuration-file/92717 "2017-07-11T20:49:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![SandhyaRani](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@SandhyaRani](https://discuss.elastic.co/u/SandhyaRani)\
**Post date:** [July 11, 2017, 8:49pm UTC](https://discuss.elastic.co/t/how-to-add-field-using-environment-plugin-in-logstash-configuration-file/92717/1 "2017-07-11T20:49:11Z")

</div>

Question: How to add field from Environment plugin in logstash config file. Here is my Config file  
input{  
stdin{  
}  
}

filter {

```
if "exception" not in [tags] {

    # example output:
    # 2016-12-16 20:43:20,535 DEBUG [CWMP-processor-6] [00D09E-0000000001:1002:C5852D7218635D7B09FE0DDE0FBE75F5:0:] c.twowire.dmc.service.PolicySvcImpl - Device matched policy 1001
    # encoder pattern (dmc/conf/logback.xml):
    # %date{ISO8601} %-5level [%thread] [%X{username}:%X{deviceId}:%X{sessionId}:%X{userInteraction}:%X{workflowName}] %logger{35} - %msg%n

    grok {
        match => {
            message => "%{DATESTAMP:timestamp} %{LOGLEVEL:level}( +)\[%{DATA:thread}\] \[%{DATA:mdc}\] %{JAVACLASS:class} - %{JAVALOGMESSAGE:logmessage}"
#message => "%{DATESTAMP:timestamp} %{LOGLEVEL:level}( +)\[%{DATA:thread}\] \[%{DATA:mdc}\] %{JAVACLASS:class} - %{GREEDYDATA:logmsg}"
        }
        # Record that this is an "log" event.
        add_tag => ["log"]
        
    }

    if "log" in [tags] {

        grok {
            match => {
                mdc => "%{DATA:username}:%{DATA:deviceId:int}:%{DATA:sessionId}:%{DATA:userInteraction:int}:%{GREEDYDATA:workflowName}"
            }
        }

        date {
            timezone => GMT
            match => [
                           # "16-12-16 21:58:20,606"
                "timestamp", "yy-MM-dd HH:mm:ss,SSS"
            ]
        }

    }

}

```

}

============================  
So, how can I add the field to get the source name i.e; to know from which server I am getting the log file?

I tried with the following line but didn't work

add\_metadata\_from\_env =\> { "SOURCE" =\> "SKY" } // indicates this log file is from "SKY"  
But when I load the index into elastic search I could not able to see my field SKY in kibana.

Could anyone help me with this??

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 12, 2017, 3:12pm UTC](https://discuss.elastic.co/t/how-to-add-field-using-environment-plugin-in-logstash-configuration-file/92717/2 "2017-07-12T15:12:48Z")

</div>

Which input plugins do you intend to use? Many of them (including stdin and file) already store the hostname in the `host` field.

If you're sure that you really need to add the hostname from an enviroment variable I suggest you just use `${SOURCE}` together with `add_field` in your inputs.

[https://www.elastic.co/guide/en/logstash/current/environment-variables.html](https://www.elastic.co/guide/en/logstash/current/environment-variables.html)

---

<div class="post-metadata">

**Author:** ![SandhyaRani](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@SandhyaRani](https://discuss.elastic.co/u/SandhyaRani)\
**Post date:** [July 12, 2017, 3:16pm UTC](https://discuss.elastic.co/t/how-to-add-field-using-environment-plugin-in-logstash-configuration-file/92717/3 "2017-07-12T15:16:49Z")

</div>

Hi,

I wanted to use environment plugin. I will try using ${SOURCE} with add\_field.

Thanks a lot !! 🙂

---

<div class="post-metadata">

**Author:** ![SandhyaRani](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@SandhyaRani](https://discuss.elastic.co/u/SandhyaRani)\
**Post date:** [July 13, 2017, 3:05pm UTC](https://discuss.elastic.co/t/how-to-add-field-using-environment-plugin-in-logstash-configuration-file/92717/4 "2017-07-13T15:05:48Z")

</div>

Hi Magnus,

Its working fine. I did  
filter{  
//To add a new field  
mutate{ add\_field =\> {"source'=\> "SKY"}}

// To get the host name  
environment{  
add\_field =\> ["my\_environment", "Hello World, from %{host}"]  
}

}

Thanks for your help! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 3:05pm UTC](https://discuss.elastic.co/t/how-to-add-field-using-environment-plugin-in-logstash-configuration-file/92717/5 "2017-08-10T15:05:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
