# Logstash adding tag issue

**URL:** <https://discuss.elastic.co/t/logstash-adding-tag-issue/250787>\
**Category:** Logstash\
**Created:** [October 2, 2020, 12:42pm UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787 "2020-10-02T12:42:20Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ashish\_Jindal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_jindal/32/46023_2.png) [@Ashish\_Jindal](https://discuss.elastic.co/u/Ashish_Jindal)\
**Post date:** [October 2, 2020, 12:42pm UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/1 "2020-10-02T12:42:20Z")

</div>

We had given a task as

Try adding tag A if the data read is a.

```auto
a
b
a
c
d

```

Ensure that the input data is tagged with type as a test, and write the output to the file output.txt in the path `usr/share/logstash` .

For which we have written the code as below, but could not complete the task, please help us -

```auto
input { 
  beats {
      port => 5044
}
        stdin { 
                tags => ["A"] 
                type => "test"
                } 
        } 

filter {
if "a" in [tags] {
       {
      separator => ","
      columns =>["a","b","c","d"]
    }
}
}
output {
if "a" in [tags] {
    stdout {
            codec => "rubydebug"
    }
   file {
      path => "/usr/share/logstash/output.txt"
   }
    elasticsearch {
    }
}
}

```

---

<div class="post-metadata">

**Author:** ![Ashish\_Jindal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_jindal/32/46023_2.png) [@Ashish\_Jindal](https://discuss.elastic.co/u/Ashish_Jindal)\
**Post date:** [October 11, 2020, 4:10pm UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/2 "2020-10-11T16:10:05Z")

</div>

please help us on it. we tried below code also not working -

```auto
input {
  stdin {
    type => 'test'
  }
}
filter {
  if [type] = 'test' {
    mutate {
     add_tag => ["A"]
    }
  }
}
output {
  stdout {
    codec => 'rubydebug'
  }
   file {
      path => "usr/share/logstash/output.txt"
   }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 11, 2020, 4:27pm UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/3 "2020-10-11T16:27:40Z")

</div>

> [@Ashish\_Jindal](#):
>
> ```auto
> tags => ["A"] ...
> if "a" in [tags] {
> 
> ```

"A" and "a" are different. For the other one,

> [@](#):
>
> if [type] = 'test' {

That should be ==, not just =.

---

<div class="post-metadata">

**Author:** ![Ashish\_Jindal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_jindal/32/46023_2.png) [@Ashish\_Jindal](https://discuss.elastic.co/u/Ashish_Jindal)\
**Post date:** [October 11, 2020, 4:42pm UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/4 "2020-10-11T16:42:19Z")

</div>

We had tried

```auto
input {
   stdin {
     type => 'test'
   }
 }
 filter {
   if [type] == 'test' {
     mutate {
      add_tag => ["A"]
     }
   }
 }
 output {
   stdout {
     codec => 'rubydebug'
   }
    file {
       path => "usr/share/logstash/output.txt"
    }
 }

```

still not working

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 11, 2020, 7:00pm UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/5 "2020-10-11T19:00:05Z")

</div>

> [@Ashish\_Jindal](#):
>
> ```auto
> file {
> path => "usr/share/logstash/output.txt"
> }
> 
> ```

Perhaps Missing the leading `/` path need to be absolute

Perhaps you could just send to standard out to check the output

---

<div class="post-metadata">

**Author:** ![Ashish\_Jindal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_jindal/32/46023_2.png) [@Ashish\_Jindal](https://discuss.elastic.co/u/Ashish_Jindal)\
**Post date:** [October 12, 2020, 3:59am UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/6 "2020-10-12T03:59:56Z")

</div>

still not working

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 12, 2020, 4:20am UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/7 "2020-10-12T04:20:41Z")

</div>

I took this config.

```
input {
   stdin {
     type => 'test'
   }
 }
 filter {
   if [type] == 'test' {
     mutate {
      add_tag => ["A"]
     }
   }
 }
 output {
   stdout {
     codec => 'rubydebug'
  
   }
   file {
       path => "/Users/sbrown/workspace/elastic-install/7.9.1/logstash-7.9.1/output.txt"
    }
 }

```

ran this command

`$ echo "Test Data" | ./bin/logstash -f config/test.conf `

This was my output on stdout.  
.....

```auto
    {
        "@timestamp" => 2020-10-12T04:15:39.217Z,
              "tags" => [
            [0] "A"
        ],
              "host" => "ceres",
              "type" => "test",
          "@version" => "1",
           "message" => "Test Data"
    }
    [2020-10-11T21:15:39,503][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
    [2020-10-11T21:15:39,587][INFO][logstash.outputs.file][main][494100533301f78e41c77d45b207aa556b6645c623bf67a642d4d67e5d3ee6b0] Opening file {:path=>"/Users/sbrown/workspace/elastic-install/7.9.1/logstash-7.9.1/output.txt"}
    [2020-10-11T21:15:40,867][INFO][logstash.runner] Logstash shut down.

```

and then

```auto
$ cat output.txt 
{"@timestamp":"2020-10-12T04:15:39.217Z","tags":["A"],"host":"ceres","type":"test","@version":"1","message":"Test Data"}

```

Works fine ... perhaps it would help if you posted your logstash output so we could see what is actually happening.

---

<div class="post-metadata">

**Author:** ![Ashish\_Jindal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_jindal/32/46023_2.png) [@Ashish\_Jindal](https://discuss.elastic.co/u/Ashish_Jindal)\
**Post date:** [October 12, 2020, 4:35am UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/9 "2020-10-12T04:35:33Z")

</div>

thanks it worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2020, 4:35am UTC](https://discuss.elastic.co/t/logstash-adding-tag-issue/250787/10 "2020-11-09T04:35:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
