# Logstash - Aggregate filter - one more field

**URL:** <https://discuss.elastic.co/t/logstash-aggregate-filter-one-more-field/220312>\
**Category:** Logstash\
**Created:** [February 21, 2020, 8:48am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-one-more-field/220312 "2020-02-21T08:48:00Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hofrichterovak](https://avatars.discourse-cdn.com/v4/letter/h/ba9def/32.png) [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Post date:** [February 21, 2020, 8:48am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-one-more-field/220312/1 "2020-02-21T08:48:00Z")

</div>

Hello,

I created aggregate filter.

---

<div class="post-metadata">

**Author:** ![ITIC](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Post date:** [February 21, 2020, 9:12am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-one-more-field/220312/2 "2020-02-21T09:12:49Z")

</div>

Hi

The `aggregate{}` filter generates a new empty event, you have to map any fields you need from the original event to the new event, just like you already do with `constants` or `message`. Try to do the same with your `TEST`.

Hope this helps.

---

<div class="post-metadata">

**Author:** ![hofrichterovak](https://avatars.discourse-cdn.com/v4/letter/h/ba9def/32.png) [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Post date:** [February 21, 2020, 9:20am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-one-more-field/220312/3 "2020-02-21T09:20:57Z")

</div>

Hello, thank you for your reply. I tried it, but I prefer to have TEST in header because I would like to add aggregate filter to existing index.  
I don´t want change header index structure so much. I wanted to add new field **constant** with nested values. Maybe I can do it different way, but I don´t know why. 🙂 Kattie

---

<div class="post-metadata">

**Author:** ![ITIC](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Post date:** [February 21, 2020, 10:04am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-one-more-field/220312/4 "2020-02-21T10:04:54Z")

</div>

Hi

Maybe I misunderstood your question. You mentioned in your original post that you want to obtain an output like this:

```auto
"@version" => "1",
"@timestamp" => 2020-02-21T08:40:53.121Z,
"message" => "a'a';b'b'\r",
"TEST" => "TEST",
"constants" => [
[0] {
"constant_clear" => [
[0] "a"
],
"constant" => [
[0] "a"
],

    },
    [1] {
        "constant_clear" => [
            [0] "b"
        ],
              "constant" => [
            [0] "b"
        ],
   
    }
],

```

To achieve it you would add to your filter a line like this:

```auto
map['TEST'] ||= event.get('TEST')

```

Is this what you need?

---

<div class="post-metadata">

**Author:** ![hofrichterovak](https://avatars.discourse-cdn.com/v4/letter/h/ba9def/32.png) [@hofrichterovak](https://discuss.elastic.co/u/hofrichterovak)\
**Post date:** [February 21, 2020, 10:23am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-one-more-field/220312/5 "2020-02-21T10:23:19Z")

</div>

OMG, you are right. Thank you. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2020, 10:23am UTC](https://discuss.elastic.co/t/logstash-aggregate-filter-one-more-field/220312/6 "2020-03-20T10:23:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
