# I cant set values in new fields

**URL:** <https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930>\
**Category:** Logstash\
**Created:** [January 14, 2020, 6:06am UTC](https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930 "2020-01-14T06:06:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonny3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonny3/32/50275_2.png) [@Jonny3](https://discuss.elastic.co/u/Jonny3)\
**Post date:** [January 14, 2020, 6:06am UTC](https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930/1 "2020-01-14T06:06:42Z")

</div>

I use grok to differentiate the content in each line of the log and mutate to create a new field and be able to assign those values ​​but it doesn't work, write the configuration content literally.

I don't have compiling problems. I try the first one and the second and nothing change.

```
  grok {
    match => { 
      "message" => ["%{DATE:date} (?:(?:%{TIME:time})|(?:%{TIMEX:timex})) %{WORD} (?:(?:%{PROG:prog})|(?:%{PROGRAM:program})) (?:\(%{USERNAME:value}\)) (?:%{WORD:level}\:) %{GREEDYDATA:text}"] 
    }
    pattern_definitions => {
      "TIMEX" => "(?!<[0-9])%{HOUR}:%{MINUTE}(?::%{SECONDX})(?![0-9])"
      "SECONDX" => "(?:(?:[0-5]?[0-9]|60)(?:[:.,][x]+)?)"
      "PROGRAM" => "(?:%{PROG}\s\-\s%{PROG})"
    }
  }

  mutate {
        add_field => { "Host" => "%{value}" }
	add_field => { "Level" => "%{level}" }
	add_field => { "Text" => "%{text}" }
  }

```

Is something wrong?

Thanks

---

<div class="post-metadata">

**Author:** ![Jonny3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonny3/32/50275_2.png) [@Jonny3](https://discuss.elastic.co/u/Jonny3)\
**Post date:** [January 14, 2020, 8:32am UTC](https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930/2 "2020-01-14T08:32:16Z")

</div>

I answer myself with this wonderful entry 😅

> [@Grok add\_field creates two values](https://discuss.elastic.co/t/grok-add-field-creates-two-values/54277):
>
> Hi, I'm using logstash 2.1, and I have the following filter: if ("sha1\_hash" in [hash\_field]) { grok { patterns\_dir =\> ["/opt/logstash/patterns"] match =\> {"sha1\_hash: %{SHA1:sha1}"} add\_field =\> {"sha1" =\> "%{sha1}"} } } The grok match works, but the add\_field has a problem, it adds the value %{sha1} twice. Why is this happening and how can I solve this? Thanks.

That was my problem...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2020, 8:32am UTC](https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930/3 "2020-02-11T08:32:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
