# How to get the value of a key in the created field using add\_fields processor?

**URL:** <https://discuss.elastic.co/t/how-to-get-the-value-of-a-key-in-the-created-field-using-add-fields-processor/230718>\
**Category:** Beats\
**Tags:** metricbeat\
**Created:** [May 1, 2020, 2:19pm UTC](https://discuss.elastic.co/t/how-to-get-the-value-of-a-key-in-the-created-field-using-add-fields-processor/230718 "2020-05-01T14:19:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![musician](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@musician](https://discuss.elastic.co/u/musician)\
**Post date:** [May 1, 2020, 2:19pm UTC](https://discuss.elastic.co/t/how-to-get-the-value-of-a-key-in-the-created-field-using-add-fields-processor/230718/1 "2020-05-01T14:19:19Z")

</div>

Hello,

I am using metricbeat 7.6.2 on Windows 2012. I have the following system.yml:

```auto
- module: system
  period: 10s
  metricsets:
    - cpu
    - memory
    - process
  processes: ['^metricbeat.exe$']
  processors:
   - add_fields:
        when:
            and:
                - has_fields: ['system.process.cpu.total.norm.pct']
                - range: 
                    system.process.cpu.total.norm.pct.gte: 0.0
        target: performance_issue
        fields:
          id: 'cpu'
          threshold: '0.0'
          val: system.process.cpu.total.norm.pct

```

I would like to get the value of the key system.process.cpu.total.norm.pct in the "val" key in the created JSON element show as below:

```auto
"performance_issue" : {
            "val" : "system.process.cpu.total.norm.pct",
            "threshold" : "0.0",
            "id" : "cpu"
          }

```

How would I change the system.yml file so that I can achieve this?

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [May 5, 2020, 8:33am UTC](https://discuss.elastic.co/t/how-to-get-the-value-of-a-key-in-the-created-field-using-add-fields-processor/230718/2 "2020-05-05T08:33:40Z")

</div>

Hi @musician!

Could you try to define it as string like: `val: 'system.process.cpu.total.norm.pct'`?

Resource: [https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html](https://www.elastic.co/guide/en/beats/filebeat/current/add-fields.html)

---

<div class="post-metadata">

**Author:** ![Sheli1a](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Sheli1a](https://discuss.elastic.co/u/Sheli1a)\
**Post date:** [May 5, 2020, 9:26am UTC](https://discuss.elastic.co/t/how-to-get-the-value-of-a-key-in-the-created-field-using-add-fields-processor/230718/3 "2020-05-05T09:26:53Z")

</div>

This allows to use advanced features like statistical analysis on value fields[!](http://employeesonlyhk.com/)

---

<div class="post-metadata">

**Author:** ![ChrsMark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chrsmark/32/55858_2.png) [@ChrsMark](https://discuss.elastic.co/u/ChrsMark)\
**Post date:** [May 5, 2020, 10:07am UTC](https://discuss.elastic.co/t/how-to-get-the-value-of-a-key-in-the-created-field-using-add-fields-processor/230718/4 "2020-05-05T10:07:34Z")

</div>

So you want the value of this field, and not the "name" of the field, right? Sorry I misunderstood the case. In cases like this, for special field handling I suggest [script-processor](https://www.elastic.co/guide/en/beats/filebeat/master/processor-script.html).

---

<div class="post-metadata">

**Author:** ![musician](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@musician](https://discuss.elastic.co/u/musician)\
**Post date:** [May 8, 2020, 1:11am UTC](https://discuss.elastic.co/t/how-to-get-the-value-of-a-key-in-the-created-field-using-add-fields-processor/230718/5 "2020-05-08T01:11:22Z")

</div>

OK - great. Thanks for the response. I will explore using script processor.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2020, 1:11am UTC](https://discuss.elastic.co/t/how-to-get-the-value-of-a-key-in-the-created-field-using-add-fields-processor/230718/6 "2020-06-05T01:11:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
