# I am trying to pick a field from one event to another using aggregation filter

**URL:** <https://discuss.elastic.co/t/i-am-trying-to-pick-a-field-from-one-event-to-another-using-aggregation-filter/278955>\
**Category:** Logstash\
**Created:** [July 17, 2021, 4:34am UTC](https://discuss.elastic.co/t/i-am-trying-to-pick-a-field-from-one-event-to-another-using-aggregation-filter/278955 "2021-07-17T04:34:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kamikaze\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kamikaze_k/32/77246_2.png) [@Kamikaze\_K](https://discuss.elastic.co/u/Kamikaze_K)\
**Post date:** [July 17, 2021, 4:34am UTC](https://discuss.elastic.co/t/i-am-trying-to-pick-a-field-from-one-event-to-another-using-aggregation-filter/278955/1 "2021-07-17T04:34:04Z")

</div>

have log files that I am able to get fields based on two different if/grok statements and patterns. The output from the two are like below;

```auto
{
       timestamp" => 2021-06-09T03:08:30.943Z,
            "Loc" => "91340",
       "@version" => "1",
     "@timestamp" => 2021-07-17T04:09:36.438Z,
       "location" => 274.05292,
          "speed" => 2.6279999999999997,
"target_location" => 261.11999999999995,
           "host" => "AUDPRWL00192",
           "path" => "C:/ELK/LOGS/91340 ____________ 090621_021536_2653_ATO_B.txt",
}
{
        "ID" => "066",
      "host" => "AUDPRWL00192",
   "MESSAGE" => "0560BFC0BC00C8005023AE00164260BFC0BC6B5DDC5B",
 "timestamp" => 2021-06-09T03:08:27.540Z,
      "path" => "C:/ELK/LOGS/91340 ____________ 090621_021536_2653_ATO_B.txt",
       "Loc" => "91340",
  "@version" => "1",
"@timestamp" => 2021-07-17T04:09:36.428Z

```

I am trying to aggregate so that my end goal is to get the following i.e pick values from the previous event i.e speed and location so that the output that i can send to Elastic is;

```auto
{
        "ID" => "066",
      "host" => "AUDPRWL00192",
   "MESSAGE" => "0560BFC0BC00C8005023AE00164260BFC0BC6B5DDC5B",
 "timestamp" => 2021-06-09T03:08:27.540Z,
      "path" => "C:/ELK/LOGS/91340 ____________ 090621_021536_2653_ATO_B.txt",
       "Loc" => "91340",
     "speed" => 2.6279999999999997,
  "location" => 274.05292,
  "@version" => "1",
"@timestamp" => 2021-07-17T04:09:36.428Z
}

```

The aggregation filter i am trying is;

```auto
aggregate {
task_id => "%{host}%{path}"
code => "map['location'] = event.get('[location]')"
map_action => "create"}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2021, 6:10pm UTC](https://discuss.elastic.co/t/i-am-trying-to-pick-a-field-from-one-event-to-another-using-aggregation-filter/278955/2 "2021-07-17T18:10:01Z")

</div>

You are not even close to providing enough information to propose a solution for this. If you look at the [aggregate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html) documentation then which of the 5 examples is closest to your use case?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2021, 6:10pm UTC](https://discuss.elastic.co/t/i-am-trying-to-pick-a-field-from-one-event-to-another-using-aggregation-filter/278955/3 "2021-08-14T18:10:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
