# Logstash aggregation filter configuration

**URL:** <https://discuss.elastic.co/t/logstash-aggregation-filter-configuration/31814>\
**Category:** Logstash\
**Created:** [October 8, 2015, 1:49am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-configuration/31814 "2015-10-08T01:49:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![grycuk](https://avatars.discourse-cdn.com/v4/letter/g/ac8455/32.png) [@grycuk](https://discuss.elastic.co/u/grycuk)\
**Post date:** [October 8, 2015, 1:49am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-configuration/31814/1 "2015-10-08T01:49:15Z")

</div>

Hi there

I'm hoping someone can help me with this please. If I have an input file in json format with a field named uuid that I wish to use as a task id in the logstash aggregate plugin. What is the correct syntax to use to specify this?

Should it be task\_id =\> "uuid" or task\_id=\>event['uuid'] or something else. I can't get it to work at present and any help would be appreciated.

Thanks  
Paul G

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 8, 2015, 5:30am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-configuration/31814/2 "2015-10-08T05:30:29Z")

</div>

```
task_id => "%{task_id}"

```

Documented here: [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf)

---

<div class="post-metadata">

**Author:** ![grycuk](https://avatars.discourse-cdn.com/v4/letter/g/ac8455/32.png) [@grycuk](https://discuss.elastic.co/u/grycuk)\
**Post date:** [October 8, 2015, 6:24am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-configuration/31814/3 "2015-10-08T06:24:46Z")

</div>

Thanks very much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:27am UTC](https://discuss.elastic.co/t/logstash-aggregation-filter-configuration/31814/4 "2017-07-06T05:27:09Z")

</div>


