# Logstash add\_field

**URL:** <https://discuss.elastic.co/t/logstash-add-field/50036>\
**Category:** Logstash\
**Created:** [May 13, 2016, 9:43pm UTC](https://discuss.elastic.co/t/logstash-add-field/50036 "2016-05-13T21:43:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![piyush](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@piyush](https://discuss.elastic.co/u/piyush)\
**Post date:** [May 13, 2016, 9:43pm UTC](https://discuss.elastic.co/t/logstash-add-field/50036/1 "2016-05-13T21:43:25Z")

</div>

Hi Team,  
I am trying to add a field but not getting expected result please assist, surely i am overlooking something. It's logstash-2.3.2-1

# PFB Details:

grok{  
match =\> ["message", "%{WORD:appname}"]  
}

mutate {  
add\_field =\> { "ApplicationName" =\> "%{appname}" }  
}

========

appname=Testing123

I am expecting "ApplicationName" = Testing123 but i am getting:  
"ApplicationName" =\> "%{appname}"

Thanks & Regards,

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [May 14, 2016, 8:27am UTC](https://discuss.elastic.co/t/logstash-add-field/50036/2 "2016-05-14T08:27:59Z")

</div>

I just tried with logstash 2.3.2 and your configuration, and it works just fine.

Are you really sure appname field is filled ? Are you sure that appcase field has this case (not Appcase for example)

I invite you to use this output to debug your problem :

```
output {
  stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2016, 8:49am UTC](https://discuss.elastic.co/t/logstash-add-field/50036/3 "2016-05-14T08:49:43Z")

</div>

Perhaps this is just a simplified example, but why not capture the string directly into the `ApplicationName` field instead of using `appname` and copying that string to `ApplicationName`?

---

<div class="post-metadata">

**Author:** ![piyush](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@piyush](https://discuss.elastic.co/u/piyush)\
**Post date:** [May 14, 2016, 9:07am UTC](https://discuss.elastic.co/t/logstash-add-field/50036/4 "2016-05-14T09:07:54Z")

</div>

Appname wasn't blank and i was looking at rubydebug only. And Appname, i am trying to retrieve from given URL, so it was like that.

I tested this scenario just now and i got my result, here is update:

tested with:  
mutate {  
add\_field =\> { "testrun" =\> "%{testrun}" }  
add\_field =\> { "critical" =\> "%{critical}" }  
}

1. Below is console output of rubydebug: [This created my confusion, i don't know why i am getting this output where i was expecting "testrun" = 0]

2. where as elasticsearch is showing testrun as a field. [my expectation] and 0 as value

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2016, 9:10am UTC](https://discuss.elastic.co/t/logstash-add-field/50036/5 "2016-05-14T09:10:59Z")

</div>

> add\_field =\> { "testrun" =\> "%{testrun}" }

I don't get it. What is this supposed to do? You're assigning a field to itself which doesn't strike me as a very useful operation. What does an event look like _without_ the mutate filter above?

---

<div class="post-metadata">

**Author:** ![piyush](https://avatars.discourse-cdn.com/v4/letter/p/ecb155/32.png) [@piyush](https://discuss.elastic.co/u/piyush)\
**Post date:** [May 14, 2016, 9:15am UTC](https://discuss.elastic.co/t/logstash-add-field/50036/6 "2016-05-14T09:15:34Z")

</div>

source of testrun:

grok {  
match =\> {"message" =\> "Tests run: %{INT:testrun}"}  
}

i am trying to create a field "testrun" where i will be inserting value of tests executed during a build.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 14, 2016, 1:53pm UTC](https://discuss.elastic.co/t/logstash-add-field/50036/7 "2016-05-14T13:53:55Z")

</div>

I repeat: What does an event look like without the mutate filter above?

In other words, what does your Logstash's input look like?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:57am UTC](https://discuss.elastic.co/t/logstash-add-field/50036/8 "2017-07-06T04:57:36Z")

</div>


