# Is there a way to add new field in bulk in logstash filter?

**URL:** <https://discuss.elastic.co/t/is-there-a-way-to-add-new-field-in-bulk-in-logstash-filter/179912>\
**Category:** Logstash\
**Created:** [May 7, 2019, 7:42am UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-new-field-in-bulk-in-logstash-filter/179912 "2019-05-07T07:42:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![david3721](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@david3721](https://discuss.elastic.co/u/david3721)\
**Post date:** [May 7, 2019, 7:42am UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-new-field-in-bulk-in-logstash-filter/179912/1 "2019-05-07T07:42:35Z")

</div>

I am using elastiflow to analysis netflow, now I am trying to add a new field, and fill the corresponding value when matching a specific IP. The filter conf is working like this, but the issue is I have thousands IPs to need to match, so is there a way to add new field in bulk ?

if [flow][dst\_addr] == "10.153.227.225"{  
mutate {  
add\_field =\> { "netflow.server\_name" =\> "PAAS,redis cluster" }  
}  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 7, 2019, 8:01am UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-new-field-in-bulk-in-logstash-filter/179912/2 "2019-05-07T08:01:39Z")

</div>

Have you looked at the translate filter?

---

<div class="post-metadata">

**Author:** ![david3721](https://avatars.discourse-cdn.com/v4/letter/d/a5b964/32.png) [@david3721](https://discuss.elastic.co/u/david3721)\
**Post date:** [May 7, 2019, 12:33pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-new-field-in-bulk-in-logstash-filter/179912/3 "2019-05-07T12:33:05Z")

</div>

Thanks for your suggestion. it is a good solution

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2019, 12:33pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-add-new-field-in-bulk-in-logstash-filter/179912/4 "2019-06-04T12:33:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
