# How to get field value in logstash?

**URL:** https://discuss.elastic.co/t/how-to-get-field-value-in-logstash/48757
**Category:** Logstash
**Created:** [April 29, 2016, 2:42am UTC](https://discuss.elastic.co/t/how-to-get-field-value-in-logstash/48757 "2016-04-29T02:42:30Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![stefansaye](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@stefansaye](https://discuss.elastic.co/u/stefansaye)
#### Post date: [April 29, 2016, 2:42am UTC](https://discuss.elastic.co/t/how-to-get-field-value-in-logstash/48757/1 "2016-04-29T02:42:30Z")

</div>

from my output as below,

> "message" =\>"\<....... ",  
> "@version" =\> "1",  
> "@timestamp" =\> "2016-04-29T02:33:34.586Z",  
> "timestamp" =\> "Apr 29 10:30:37",  
> "syslog\_severity\_code" =\> 5,  
> "syslog\_facility\_code" =\> 1,  
> "syslog\_facility" =\> "user-level",  
> "syslog\_severity" =\> "notice"  
> i try to get the field value

```
filter
 {
     mutate {
     add_field => {"newfield"=> "timestamp"}
  }

```

but still cann't get the timestamp value to newfield it's will get

```
"newfield" => "newfield",

```

Is anyone is having the same problem or find a solution?  
Any help is welcome to resolve this

---

<div class="post-metadata">

### Author: ![MrLee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrlee/32/9429_2.png) [@MrLee](https://discuss.elastic.co/u/MrLee)
#### Post date: [April 29, 2016, 3:52am UTC](https://discuss.elastic.co/t/how-to-get-field-value-in-logstash/48757/2 "2016-04-29T03:52:33Z")

</div>

Maybe you should read the logstash reference first:  
[https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 29, 2016, 5:31am UTC](https://discuss.elastic.co/t/how-to-get-field-value-in-logstash/48757/3 "2016-04-29T05:31:17Z")

</div>

> ```
> add_field => {"newfield"=> "timestamp"}
> 
> ```

To copy the _contents_ of the `timestamp` field to `newfield` you need this:

```
 add_field => {"newfield"=> "%{timestamp}"}

```

---

<div class="post-metadata">

### Author: ![stefansaye](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@stefansaye](https://discuss.elastic.co/u/stefansaye)
#### Post date: [April 29, 2016, 9:05am UTC](https://discuss.elastic.co/t/how-to-get-field-value-in-logstash/48757/4 "2016-04-29T09:05:14Z")

</div>

i have tried the cmd

```
add_field => {"newfield"=> "%{timestamp}"}

```

but It's strange , it's still can't get the timestamp value.  
get results as follow,

```
 newfield => %{timestamp}

```

Is anyone is having the same problem or find a solution?  
Any help is welcome to resolve this

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [April 30, 2016, 2:50pm UTC](https://discuss.elastic.co/t/how-to-get-field-value-in-logstash/48757/5 "2016-04-30T14:50:22Z")

</div>

If `newfield` ends up containing "%{timestamp}" then there was to `timestamp` field in the event. If you show us a complete example of your configuration, the input messages, what you actually get, and what you'd like to get it'll be easier to help out.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/how-to-get-field-value-in-logstash/48757/6 "2017-07-06T04:59:55Z")

</div>


