# I want to add new field and replace the one of the existing field value to the newly added field

**URL:** <https://discuss.elastic.co/t/i-want-to-add-new-field-and-replace-the-one-of-the-existing-field-value-to-the-newly-added-field/195303>\
**Category:** Logstash\
**Created:** [August 15, 2019, 6:31am UTC](https://discuss.elastic.co/t/i-want-to-add-new-field-and-replace-the-one-of-the-existing-field-value-to-the-newly-added-field/195303 "2019-08-15T06:31:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![satyam2593](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@satyam2593](https://discuss.elastic.co/u/satyam2593)\
**Post date:** [August 15, 2019, 6:31am UTC](https://discuss.elastic.co/t/i-want-to-add-new-field-and-replace-the-one-of-the-existing-field-value-to-the-newly-added-field/195303/1 "2019-08-15T06:31:39Z")

</div>

The below is the input for the config file.. Here i want to grep the date from the one of the line and store into a field(called logdate).. Later i want to create the new field(called log\_timestamp) with null value and replace that null value with logdate field value..

For the second line, the log\_timestamp field is getting the value from the logdate field.. But next lines it is not getting

## My stdin input:

## START the log printing 08/08/19 09:10:06 343

## PID|THREAD NAME|CPU UTILIZATION|MEMORY UTILIZATION 7066|DestroyJavaVM|0.0|11.3 7072|Reference Handler|0.0|11.3 31204|qtp1459076321-3197|0.0|11.3

## END the log printing 08/08/19 09:10:06 831

My config file:  
filter  
{

```
     mutate
     {
     add_field=>{"log_timestamp"=>""}
     }
	if [message] =~ /^[-\/]/
    {
            drop{}

    }
    if "START" in [message]
    {
		grok 
			{
            match => { "message" => "%{GREEDYDATA} (?<logdate>%{MONTHDAY}/%{MONTHNUM}/%{YEAR}%{SPACE}%{HOUR}:%{MINUTE}:%{SECOND}%{SPACE}%{NUMBER})"}
			}	
	}
	else
	{
		grok
			{
			 match=> {"message" => "%{INT:Thread_Id}\|%{GREEDYDATA:Thread_Name}\|%{BASE16FLOAT:CPU_Utilization}\|%{BASE16FLOAT:Memory_Utilization}"}
			}
		
	}
	if "END the log printing" in [message]
    {
            drop{}
    }
	
	if "PID" in [message]
    {
		drop {}
    }
	mutate
       {
          replace => {"log_timestamp"=> " %{logdate}"}
       }	
}

```

Output:  
{  
"@timestamp" =\> 2019-08-15T06:19:31.505Z,  
**"logdate" =\> "08/08/19 09:10:06 343",**  
"@version" =\> "1",  
"log\_timestamp" =\> " 08/08/19 09:10:06 343",  
"host" =\> "localhost.localdomain",  
"message" =\> "START the log printing 08/08/19 09:10:06 343"  
}  
{  
"@timestamp" =\> 2019-08-15T06:19:31.506Z,  
"@version" =\> "1",  
"log\_timestamp" =\> " %{logdate}",  
"PID" =\> "7066",  
"THREAD NAME" =\> "DestroyJavaVM",  
"host" =\> "localhost.localdomain",  
"message" =\> "7066|DestroyJavaVM|0.0|11.3",  
"CPU UTILIZATION" =\> "0.0",  
"MEMORY UTILIZATION" =\> "11.3"  
}  
{  
"@timestamp" =\> 2019-08-15T06:19:31.507Z,  
"@version" =\> "1",  
**"log\_timestamp" =\> " %{logdate}",**  
"PID" =\> "7072",  
"THREAD NAME" =\> "Reference Handler",  
"host" =\> "localhost.localdomain",  
"message" =\> "7072|Reference Handler|0.0|11.3",  
"CPU UTILIZATION" =\> "0.0",  
"MEMORY UTILIZATION" =\> "11.3"  
}  
{  
"@timestamp" =\> 2019-08-15T06:19:31.507Z,  
"@version" =\> "1",  
**"log\_timestamp" =\> " %{logdate}",**  
"PID" =\> "31204",  
"THREAD NAME" =\> "qtp1459076321-3197",  
"host" =\> "localhost.localdomain",  
"message" =\> "31204|qtp1459076321-3197|0.0|11.3",  
"CPU UTILIZATION" =\> "0.0",  
"MEMORY UTILIZATION" =\> "11.3"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2019, 4:43pm UTC](https://discuss.elastic.co/t/i-want-to-add-new-field-and-replace-the-one-of-the-existing-field-value-to-the-newly-added-field/195303/3 "2019-09-13T16:43:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
