# I cant set values in new fields

**URL:** <https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930>\
**Category:** Logstash\
**Created:** [January 14, 2020, 6:06am UTC](https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930 "2020-01-14T06:06:42Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Jonny3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonny3/32/50275_2.png) [@Jonny3](https://discuss.elastic.co/u/Jonny3)\
**Post date:** [January 14, 2020, 8:32am UTC](https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930/2 "2020-01-14T08:32:16Z")

</div>

I answer myself with this wonderful entry 😅

> [@Grok add\_field creates two values](https://discuss.elastic.co/t/grok-add-field-creates-two-values/54277):
>
> Hi, I'm using logstash 2.1, and I have the following filter: if ("sha1\_hash" in [hash\_field]) { grok { patterns\_dir =\> ["/opt/logstash/patterns"] match =\> {"sha1\_hash: %{SHA1:sha1}"} add\_field =\> {"sha1" =\> "%{sha1}"} } } The grok match works, but the add\_field has a problem, it adds the value %{sha1} twice. Why is this happening and how can I solve this? Thanks.

That was my problem...

---

_[View the full topic](https://discuss.elastic.co/t/i-cant-set-values-in-new-fields/214930)._
