# I need add field, and do value counter, how do it?

**URL:** <https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005>\
**Category:** Elasticsearch\
**Created:** [February 11, 2022, 5:20pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005 "2022-02-11T17:20:08Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 11, 2022, 5:57pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/2 "2022-02-11T17:57:22Z")

</div>

You need to hold state in Logstash, but it is not explicitly supported.

> [@How to hold a state in Logstash?](https://discuss.elastic.co/t/how-to-hold-a-state-in-logstash/120887):
>
> Hi, I'm trying to apply a state (with a field in ES) to subsequent log lines after seeing [message] =~ "foo" but have not had luck using class variables with the ruby filter (@@classVariable) as described in [Keeping global variables in LS?!](https://discuss.elastic.co/t/keeping-global-variables-in-ls/39908) with logstash 6.0.1. I find that the class variable does not hold the correct value when exploring the data on discover in Kibana. Specifically, I want the state to change when I see [message] =~ "bar" and then hold that value until [message] =~ "foo" is …

What is your purpose of using such incremental ids? Elasticsearch default `_id` is not enough?

---

_[View the full topic](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005)._
