# I need add field, and do value counter, how do it?

**URL:** <https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005>\
**Category:** Elasticsearch\
**Created:** [February 11, 2022, 5:20pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005 "2022-02-11T17:20:08Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![VK345](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@VK345](https://discuss.elastic.co/u/VK345)\
**Post date:** [February 11, 2022, 6:16pm UTC](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005/3 "2022-02-11T18:16:00Z")

</div>

> [@How to hold a state in Logstash?](https://discuss.elastic.co/t/how-to-hold-a-state-in-logstash/120887/1):
>
> Hi, I'm trying to apply a state (with a field in ES) to subsequent log lines after seeing [message] =~ "foo" but have not had luck using class variables with the ruby filter (@@classVariable) as described in [Keeping global variables in LS?!](https://discuss.elastic.co/t/keeping-global-variables-in-ls/39908) with logstash 6.0.1. I find that the class variable does not hold the correct value when exploring the data on discover in Kibana. Specifically, I want the state to change when I see [message] =~ "bar" and then hold that value until [message] =~ "foo" is …

1. Thank you for you replay.
2. May be you khow different solve this task?
3. May be you know how not use standart -  
id for example\_id:o\_TT6X4B7HVNK6zt50Q8

i need

\_id:1  
\_id:2

Not has this data (1,2,3...) in input ?

---

_[View the full topic](https://discuss.elastic.co/t/i-need-add-field-and-do-value-counter-how-do-it/297005)._
