# Logstash dash "-" (hyphen) problem with aggregation

**URL:** <https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947>\
**Category:** Logstash\
**Created:** [October 13, 2020, 6:12pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947 "2020-10-13T18:12:29Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![bnmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bnmtl/32/77109_2.png) [@bnmtl](https://discuss.elastic.co/u/bnmtl)\
**Post date:** [October 13, 2020, 6:12pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/1 "2020-10-13T18:12:29Z")

</div>

Hello,  
With my logstash configuration, I am reading JSON log, but in my JSON log I have fields like below;

"host-name":"[comp-1.example.com](http://comp-1.example.com)",  
"name-surname":"john-doe"

My configuration in logstash;

```
input {
    file {
        path => "/path/my_json_access.log"
        codec => json { charset => "UTF-8" }
    }
}
filter {
     mutate {
       add_field => { "computer_tag" => "something" }
}
aggregate {
    task_id => "%{host-name}"
    code => "map['host_count'] ||= 0; map['host_count'] += 1;
    map['hostname'] = event.get('host-name');
    map['name_surname'] = event.get('name-surname');
    timeout_task_id_field => "host-name"
    timeout => 100
    timeout_tags => ['_timeouttag1']
    timeout_code => "event.set('several_count', event.get('host_count') > 1)"
    push_previous_map_as_event => true
}}

output {
  if "_timeouttag1" in [tags] {
        rabbitmq {
            codec => "json"
            durable => true
            exchange => "myexchange"
            exchange_type => "fanout"
            host => "192.168.0.1"
            key => "logstash"
            password => "myp4ss"
            user => "test"
            workers => 1
    }}

```

At the end of the story, I cannot get any messages, or errors when I am starting logstash. I think there is something wrong with "dash", can you guys please give me advise or way for success.

My expected output is;  
"computer\_tag":"something",  
"host\_count":"12",  
"hostname":"[comp-1.example.com](http://comp-1.example.com)",  
"name\_surname":"john-doe",

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 13, 2020, 6:48pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/2 "2020-10-13T18:48:33Z")

</div>

> [@bnmtl](#):
>
> ```auto
> if "_timeouttag1" in [tags] {
> rabbitmq {
> 
> ```

So you only send events to rabbitmq if they have a \_timeouttag1tag, but since you are using push\_previous\_map\_as\_event only one event (the last one) will timeout.

With that configuration I would expect nothing to happen for the first 100 seconds, then a single event written to rabbitmq.

---

<div class="post-metadata">

**Author:** ![bnmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bnmtl/32/77109_2.png) [@bnmtl](https://discuss.elastic.co/u/bnmtl)\
**Post date:** [October 13, 2020, 6:51pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/3 "2020-10-13T18:51:35Z")

</div>

I understand that, but whats the correct way to count host-name and publish when timeout ?  
I would like to count "host-names" and publish to rabbit after 100 seconds.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 13, 2020, 7:38pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/4 "2020-10-13T19:38:21Z")

</div>

Well the event that goes to rabbitmq will not have computer\_tag since that mutate is only applied to the events that are discarded, not the event created by aggregate. Move the mutate after the aggregate.

Generally your aggregate looks good. I would add event.cancel to the code option of the aggregate and change push\_previous\_map\_as\_event to push\_map\_as\_event\_on\_timeout

Which logstash version. I wonder if you are hitting [this](https://github.com/elastic/logstash/pull/12204) issue.

---

<div class="post-metadata">

**Author:** ![bnmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bnmtl/32/77109_2.png) [@bnmtl](https://discuss.elastic.co/u/bnmtl)\
**Post date:** [October 13, 2020, 8:18pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/5 "2020-10-13T20:18:11Z")

</div>

Thank you so much for your help Badger, I changed my config to this;

### my logstash version 7.8.1

```
input {
    file {
        path => "/path/my_json_access.log"
        codec => json { charset => "UTF-8" }
    }
filter {
aggregate {
    task_id => "%{host-name}"
    code => "map['host_count'] ||= 0; map['host_count'] += 1;
    map['host-name'] = event.get('host-name');
    map['name-surname'] = event.get('name-surname');
    timeout_task_id_field => "host-name"
    timeout => 100
    timeout_tags => ['_timeouttag1']
    timeout_code => "event.set('several_count', event.get('host_count') > 1)"
    push_map_as_event_on_timeout => true
}
     mutate {
       add_field => { "computer_tag" => "something" }
}
}

output {
        rabbitmq {
            codec => "json"
            durable => true
            exchange => "myexchange"
            exchange_type => "fanout"
            host => "192.168.0.1"
            key => "logstash"
            password => "myp4ss"
            user => "test"
            workers => 1
    }}

```

Problems;

- I am not getting any host\_count field in my output.

- I am getting output whatever json sends

- computer\_tag added additional to json input

- I checked the logstash.yml and I have no #pipeline.java\_execution line

Is there any problem with dash ( - ) characters in aggregation?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 13, 2020, 8:39pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/6 "2020-10-13T20:39:59Z")

</div>

> [@bnmtl](#):
>
> - I checked the logstash.yml and I have no #pipeline.java\_execution line
> 
> Is there any problem with dash ( - ) characters in aggregation?

java\_execution became the default in 7.0. The bug with flushers was introduced in 7.7 or 7.8 (I think) and fixed in 7.9.1. What version are you running? If it is an affected version try disabling java\_execution.

I know of no problems with hyphens in field names.

---

<div class="post-metadata">

**Author:** ![bnmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bnmtl/32/77109_2.png) [@bnmtl](https://discuss.elastic.co/u/bnmtl)\
**Post date:** [October 14, 2020, 5:47am UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/7 "2020-10-14T05:47:17Z")

</div>

### 7.8.1

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 14, 2020, 2:33pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/8 "2020-10-14T14:33:38Z")

</div>

That version definitely has the bug I linked to. Disable java\_execution.

---

<div class="post-metadata">

**Author:** ![bnmtl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bnmtl/32/77109_2.png) [@bnmtl](https://discuss.elastic.co/u/bnmtl)\
**Post date:** [October 14, 2020, 2:39pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/9 "2020-10-14T14:39:44Z")

</div>

Badger thank you for your support, everything goes well now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2020, 2:39pm UTC](https://discuss.elastic.co/t/logstash-dash-hyphen-problem-with-aggregation/251947/10 "2020-11-11T14:39:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
