# Logstash clone filter use event field as clones parameter

**URL:** https://discuss.elastic.co/t/logstash-clone-filter-use-event-field-as-clones-parameter/275250
**Category:** Logstash
**Created:** [June 8, 2021, 8:09am UTC](https://discuss.elastic.co/t/logstash-clone-filter-use-event-field-as-clones-parameter/275250 "2021-06-08T08:09:50Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ebourlon](https://avatars.discourse-cdn.com/v4/letter/e/a6a055/32.png) [@ebourlon](https://discuss.elastic.co/u/ebourlon)
#### Post date: [June 8, 2021, 8:09am UTC](https://discuss.elastic.co/t/logstash-clone-filter-use-event-field-as-clones-parameter/275250/1 "2021-06-08T08:09:50Z")

</div>

Hello,

I made some tests with the clone filter in logstash. In my opinion there is no way to make the "clones" parameter dynamic.  
Does someone know how this can be done? Looking at the filter code I think it might be considered as an enhancement of this plugin.

Br,

```auto
input {
  stdin{
    id => "mystdin"
	ecs_compatibility => disabled
	add_field => {"clones_array" => ["clone1","clone2"]}
  }	
}
'''
filter {
	clone {
	  clones => "%{[clones_array]}"
	  #clones => clones_array
	  #clones => [clones_array]
	  ecs_compatibility => disabled
	}
}
output {
  stdout {
    codec => json
  }
}

```

The clones parameter is taken as-is, giving as result:

```auto
{"clones_array":["clone1","clone2"],"message":"Hello\r","host":"ms-prd-eaiwe-02","@version":"1","@timestamp":"2021-06-08T07:28:53.065Z"}
{"clones_array":["clone1","clone2"],"message":"Hello\r","host":"ms-prd-eaiwe-02","type":"%{[clones_array]}","@version":"1","@timestamp":"2021-06-08T07:28:53.065Z"}

```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [June 8, 2021, 5:02pm UTC](https://discuss.elastic.co/t/logstash-clone-filter-use-event-field-as-clones-parameter/275250/2 "2021-06-08T17:02:01Z")

</div>

Correct, the value of the clones option is a literal, the clone filter [does not](https://github.com/logstash-plugins/logstash-filter-clone/blob/b430084f7876805f2ad9074f955c54542c56d225/lib/logstash/filters/clone.rb#L37) sprintf it.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2021, 5:02pm UTC](https://discuss.elastic.co/t/logstash-clone-filter-use-event-field-as-clones-parameter/275250/3 "2021-07-06T17:02:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
