# Logstash aggregate problem

**URL:** <https://discuss.elastic.co/t/logstash-aggregate-problem/271760>\
**Category:** Logstash\
**Created:** [April 30, 2021, 10:05am UTC](https://discuss.elastic.co/t/logstash-aggregate-problem/271760 "2021-04-30T10:05:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![fabryx87](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabryx87/32/88165_2.png) [@fabryx87](https://discuss.elastic.co/u/fabryx87)\
**Post date:** [April 30, 2021, 10:05am UTC](https://discuss.elastic.co/t/logstash-aggregate-problem/271760/1 "2021-04-30T10:05:17Z")

</div>

Hi all,

I am trying to do an aggregate in logstash, but probably i am not understanding how it works....  
I want to copy the field contenent of elevated\_token inside the map, and create a new field with this value on the end task.  
I will need to apply this method to other fields as well.

can you please help me?

```auto
if "system_session" not in [tags] {
    aggregate {
      task_id => "%{winlog.event_data.TargetLogonId}"
      code => "map['elevated_token'] += event.get([winlog][event_data][ElevatedToken])"
      map_action => "create"
    }
}
if [winlog][event_id] == 4634{
    aggregate {
          task_id => "%{winlog.event_data.TargetLogonId}"
          code => "event.set('elevated_token', map['elevated_token'])"
          map_action => "update"
          end_of_task => true
          push_map_as_event_on_timeout => true
          timeout_tags => ['_aggregatetimeout']
          timeout => 28800
    }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 30, 2021, 3:34pm UTC](https://discuss.elastic.co/t/logstash-aggregate-problem/271760/2 "2021-04-30T15:34:40Z")

</div>

> [@fabryx87](#):
>
> `"%{winlog.event_data.TargetLogonId}"`

It seems likely that you mean %{[winlog][event\_data][TargetLoginId]}

---

<div class="post-metadata">

**Author:** ![fabryx87](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabryx87/32/88165_2.png) [@fabryx87](https://discuss.elastic.co/u/fabryx87)\
**Post date:** [May 4, 2021, 8:03am UTC](https://discuss.elastic.co/t/logstash-aggregate-problem/271760/3 "2021-05-04T08:03:53Z")

</div>

Hi Badger,

thanks for your reply.  
unfortunatelly it didn't help, do you have any other suggest?  
is there a way to add some tag to check if a step is done or not?

thanks

```auto
if "system_session" not in [tags] {
                    mutate {
                     add_field => { "legit" => "yes" }
                    }
                    aggregate {
                         task_id => "%{[winlog][event_data][TargetLoginId]}"
                         code => "map['elevated_token'] += event.get([winlog][event_data][ElevatedToken])"
                         map_action => "create"
                         }
                    }
                }
        }
           if [winlog][event_id] == 4634 or [event][code] == 4647{
           aggregate {
                 task_id => "%{[winlog][event_data][TargetLoginId]}"
                 code => "event.set('elevated_token', map['elevated_token'])"
                 map_action => "update"
                 end_of_task => true
                 push_map_as_event_on_timeout => true
                 timeout_tags => ['_aggregatetimeout']
                 timeout => 28800
            }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2021, 4:25pm UTC](https://discuss.elastic.co/t/logstash-aggregate-problem/271760/4 "2021-05-04T16:25:51Z")

</div>

> [@fabryx87](#):
>
> is there a way to add some tag to check if a step is done or not?

add\_tag is one of the [common options](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-common-options) that pretty much every filter supports. That said, adding the tag ("decorating the event") is only done if the filter matches the event. So, for example, in a date or grok filter, if the source field does not exist then nothing is done and the event is not decorated. An aggregate filter will [decorate](https://github.com/logstash-plugins/logstash-filter-aggregate/blob/8cb106fac8e54e77e747ee0d13575b327b33f8b9/lib/logstash/filters/aggregate.rb#L241) the event unless an error occurs.

---

<div class="post-metadata">

**Author:** ![fabryx87](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabryx87/32/88165_2.png) [@fabryx87](https://discuss.elastic.co/u/fabryx87)\
**Post date:** [May 5, 2021, 7:44am UTC](https://discuss.elastic.co/t/logstash-aggregate-problem/271760/5 "2021-05-05T07:44:25Z")

</div>

ok, how can I troubleshoot in this case to understand what is going on and why this aggregate doesn't work?  
because it add the field

```auto
mutate {
add_field => { "legit" => "yes" }
 }

```

but I don't have any trace of the aggregate.

---

<div class="post-metadata">

**Author:** ![fabryx87](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabryx87/32/88165_2.png) [@fabryx87](https://discuss.elastic.co/u/fabryx87)\
**Post date:** [May 12, 2021, 9:35am UTC](https://discuss.elastic.co/t/logstash-aggregate-problem/271760/6 "2021-05-12T09:35:27Z")

</div>

Any help on this?  
thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2021, 9:35am UTC](https://discuss.elastic.co/t/logstash-aggregate-problem/271760/7 "2021-06-09T09:35:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
