# Include One Identifier for each log entry

**URL:** <https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919>\
**Category:** Logstash\
**Created:** [January 11, 2019, 3:23pm UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919 "2019-01-11T15:23:23Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 11, 2019, 3:23pm UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919/1 "2019-01-11T15:23:24Z")

</div>

My aim is to include an identifier for logs of a few Jenkins Jobs that run in sequence.

Kindly give your opinion on the following --

1. Is there any way to append an ID such as '1234' to each document entry i.e each line of log by using logstash ? I am not planning to append any hash value , rather a readable ID .I can find ways to include an increment value for each log entry. However, I want to include only one ID such that a particular sequence of jobs can be identified.

2. Is it possible to pass a variable from a file to the filebeat index name ? The variable will hold an identifier such as a number.

Kindly help.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 11, 2019, 7:04pm UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919/2 "2019-01-11T19:04:31Z")

</div>

can someone kindly give his/her opinion on this ? Any idea if this is possible ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 13, 2019, 11:40am UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919/3 "2019-01-13T11:40:01Z")

</div>

Where do you get the value from? Is it available in all the documents, e.g. through a file path or something similar? How do you logically determine that two documents belong to the same job?

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 14, 2019, 5:18am UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919/4 "2019-01-14T05:18:54Z")

</div>

@Christian_Dahlqvist thanks for responding back. I get the value i.e the unique number in only one document entry of the first job of Jenkins. I don't get the number in every document entry. Had I got the number in every document entry I could have easily used Grok to filter and create a new Field. So comes the problem.

What I am planning to do -

1. Use grok to filter the number into a new field.
2. Use Ruby to write that field , which holds my unique number into a ruby file.
3. Use Ruby plugin to read from a path (the path will hold the ruby file with my unique number) and append a new field with my unique number to every document entry.

But I will have to create a new job at the beginning of the sequence of Jenkins jobs just to create the unique number.

Is my approach correct ? Any input that you would like to give?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 14, 2019, 6:16am UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919/5 "2019-01-14T06:16:45Z")

</div>

Sounds tricky. Am not sure I have any good solution to recommend. I am not sure whether your solution would or wouldn't work either.

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 14, 2019, 7:46am UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919/6 "2019-01-14T07:46:21Z")

</div>

@Christian_Dahlqvist Any idea if I can write a field value into a .rb file ??

---

<div class="post-metadata">

**Author:** ![mrashid](https://avatars.discourse-cdn.com/v4/letter/m/9fc348/32.png) [@mrashid](https://discuss.elastic.co/u/mrashid)\
**Post date:** [January 14, 2019, 8:00am UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919/7 "2019-01-14T08:00:12Z")

</div>

@Christian_Dahlqvist

But its not working

This is what the config file looks like in logstash-

> input {  
> beats {  
> port =\> 5044  
> ssl =\> true  
> ssl\_certificate =\> "/security/logstash.crt"  
> ssl\_key =\> "/security/logstash.key"  
> }  
> }  
> filter {  
> grok {  
> match =\> { "message" =\> "^The build ID of the run is : %{NUMBER:filteredValues}" }  
> }  
> }  
> filter {  
> ruby {  
> code =\>'File.open(/etc/logstash/output.rb, 'w') { |file| file.write("%(filteredValues)") }'  
> path =\> "/etc/logstash/test.rb"  
> script\_params =\> { "percentage" =\> 100 }  
> }  
> }

It is the below grok filter which holds my unique number in the filed "filteredValues"

> match =\> { "message" =\> "^The build ID of the run is : %{NUMBER:filteredValues}" }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2019, 8:00am UTC](https://discuss.elastic.co/t/include-one-identifier-for-each-log-entry/163919/8 "2019-02-11T08:00:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
