# Logstash Aggregate copy last Event to Map

**URL:** <https://discuss.elastic.co/t/logstash-aggregate-copy-last-event-to-map/251149>\
**Category:** Logstash\
**Created:** [October 6, 2020, 2:35pm UTC](https://discuss.elastic.co/t/logstash-aggregate-copy-last-event-to-map/251149 "2020-10-06T14:35:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![siiman](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@siiman](https://discuss.elastic.co/u/siiman)\
**Post date:** [October 6, 2020, 2:35pm UTC](https://discuss.elastic.co/t/logstash-aggregate-copy-last-event-to-map/251149/1 "2020-10-06T14:35:27Z")

</div>

Hello there,

I would like to combine several consecutive events. For this purpose I consider the use of the aggregation filter as useful. Since I don't have a specific start or end event, I will use example #3 in the Logstash documentation.

If a new event is created from the map at the time of the timeout, it will unfortunately only contain the previously assigned fields. How is it possible to use all fields of the last aggregated event? I think I need something like `map['_source'] = event.get('[_source]')` in my code section. But these Codeline doesn't work.

_background:_  
_In my log are ten consecutive entries with different parameters. I would like to combine these in one event. A unique task\_id is present. The events occur in irregular intervals, so that the use of the_ `push_previous_map_as_event` _does not seem to make sense to me._

Thanks for your tips  
Best regards  
siiman

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 6, 2020, 2:45pm UTC](https://discuss.elastic.co/t/logstash-aggregate-copy-last-event-to-map/251149/2 "2020-10-06T14:45:31Z")

</div>

> [@siiman](#):
>
> How is it possible to use all fields of the last aggregated event?

[This](https://discuss.elastic.co/t/push-previous-map-as-event-if-fields-exist/250566/2) might help.

---

<div class="post-metadata">

**Author:** ![siiman](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@siiman](https://discuss.elastic.co/u/siiman)\
**Post date:** [October 6, 2020, 3:37pm UTC](https://discuss.elastic.co/t/logstash-aggregate-copy-last-event-to-map/251149/3 "2020-10-06T15:37:54Z")

</div>

Hi,

I have tried the following code from you.

```auto
aggregate {
    task_id => "%{task_id}"
    code => "                                                                                       
            event.to_hash.each { |k,v|
                   unless map[k]
                           map[k] = v 
                   end
            }
    "
    push_map_as_event_on_timeout => true
    timeout => 3
    timeout_tags => ['agg_timeout']
    add_tag => ["_aggregate"]
    timeout_task_id_field => "task_id"
}

```

this one works for my understanding exactly like this one.

```auto
code => "                                                                                       
    map.merge!(event)
"

```

Unfortunately both variants only copy the last event before the timeout into the `map`. Which I cannot understand logically.

Can you understand the behaviour and/or tell me a solution how to combine all events?

---

<div class="post-metadata">

**Author:** ![siiman](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@siiman](https://discuss.elastic.co/u/siiman)\
**Post date:** [October 7, 2020, 6:22am UTC](https://discuss.elastic.co/t/logstash-aggregate-copy-last-event-to-map/251149/4 "2020-10-07T06:22:12Z")

</div>

Alright the problem is solved.

Merge does not work with nested hashes (JSON structure). So here is my solution.

```auto
aggregate {
    task_id => "%{task_id}"
    code => "
            merger = proc { |key, v1, v2| Hash === v1 && Hash === v2 ? v1.merge(v2, &merger) : v2 }                                                                                           
            map.merge!(event, &merger)
     "
     push_map_as_event_on_timeout => true
     timeout => 3
     timeout_tags => ['agg_timeout']
     add_tag => ["_aggregate"]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2020, 6:22am UTC](https://discuss.elastic.co/t/logstash-aggregate-copy-last-event-to-map/251149/5 "2020-11-04T06:22:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
