# How to pull a field from an event to another event?

**URL:** <https://discuss.elastic.co/t/how-to-pull-a-field-from-an-event-to-another-event/34235>\
**Category:** Logstash\
**Created:** [November 10, 2015, 12:02pm UTC](https://discuss.elastic.co/t/how-to-pull-a-field-from-an-event-to-another-event/34235 "2015-11-10T12:02:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fereshteh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fereshteh/32/5926_2.png) [@fereshteh](https://discuss.elastic.co/u/fereshteh)\
**Post date:** [November 10, 2015, 12:02pm UTC](https://discuss.elastic.co/t/how-to-pull-a-field-from-an-event-to-another-event/34235/1 "2015-11-10T12:02:11Z")

</div>

I am currently working with logs with some of its content looking like this:

```
00:19:59.771 (07120/evtThread ) TRC> Cem< [Core1] CALL_STATE... 
#S#|Call stats, ongoing calls: 8, handled_calls: 7304
#S#+----------------------------+----------+----------+----------+----------+----------+
#S#|Peer | From| To| MinTime| MaxTime| AvgTime|
#S#+----------------------------+----------+----------+----------+----------+----------+
#S#| CallDispatcher:Core2| 0| 0| 0| 0| 0|

```

I parsed the line containing the time like this:

```
grok {
    match => ["message", "%{TIME:time} (?<bcm_comp>\(\d{5}\/\w{4,}\:*\ *\w*\)) (?<loglevel>\w{3}>{1}) %{GREEDYDATA:message}"]
    overwrite => ["message"]
    add_field => ["BCM_System", "PROD"]
}

```

The lines containing the #S# at the front was parsed like this.

```
grok {
    match => ["message", "(?<start>\#\S\#\|)\s* (?<peer>\w*\:\w*)(?<div2>\|)\s* %{NUMBER:From}(?<div3>\|)\s* %{NUMBER:To}(?<div4>\|)\s* %{NUMBER:MinTime}(?<div5>\|)\s* %{NUMBER:MaxTime}(?<div6>\|)\s* %{NUMBER:AvgTime}(?<div7>\|)"]        
    remove_field => ["start", "div2", "div3", "div4", "div5", "div6", "div7"]
    overwrite => ["message"]       
    add_field => ["reference_time", "%{@time}"]
}

```

What I am trying to do is take the time from the previous line and add it as a field for where I groked the #s# lines. I try using the add\_field syntax from logstash as shown but it doesn't work...it just literally prints out %{@time}.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 10, 2015, 12:13pm UTC](https://discuss.elastic.co/t/how-to-pull-a-field-from-an-event-to-another-event/34235/2 "2015-11-10T12:13:15Z")

</div>

There's no simple way, no. See the following related thread from last week:

> [@Pulling year from event to place into timestamps for future events?](https://discuss.elastic.co/t/pulling-year-from-event-to-place-into-timestamps-for-future-events/33737):
>
> I have i feeling I already know the answer to this (which is probably "can't be done") but worth a shot. The application logs I'm recording have the unfortunate incident of having no year specified in the timestamp for the log events, so it always assumes it's current year. There are exceptions: in the log event message for application startup it will specify the year. So i would like to pull the year from that event and then attach it as the year for every subsequent event in that log file unt…

---

<div class="post-metadata">

**Author:** ![jjdepaul](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@jjdepaul](https://discuss.elastic.co/u/jjdepaul)\
**Post date:** [February 9, 2016, 4:22pm UTC](https://discuss.elastic.co/t/how-to-pull-a-field-from-an-event-to-another-event/34235/3 "2016-02-09T16:22:49Z")

</div>

This probably comes to you too late to be of any use, but you can do it with class variables, if you're careful. There is a tradeoff: you will have to settle on only ONE worker in your logstash to avoid problems.

Here is a thread on how I did it:

> [@Keeping global variables in LS?!](https://discuss.elastic.co/t/keeping-global-variables-in-ls/39908/3):
>
> Well you didn't really wait too long for an answer slight_smile So you are treating each of these lines as unique events?

Good luck -

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:12am UTC](https://discuss.elastic.co/t/how-to-pull-a-field-from-an-event-to-another-event/34235/4 "2017-07-06T05:12:27Z")

</div>


