# Logstash not creating new field

**URL:** <https://discuss.elastic.co/t/logstash-not-creating-new-field/69352>\
**Category:** Logstash\
**Created:** [December 18, 2016, 2:36am UTC](https://discuss.elastic.co/t/logstash-not-creating-new-field/69352 "2016-12-18T02:36:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kitex](https://avatars.discourse-cdn.com/v4/letter/k/f14d63/32.png) [@kitex](https://discuss.elastic.co/u/kitex)\
**Post date:** [December 18, 2016, 2:36am UTC](https://discuss.elastic.co/t/logstash-not-creating-new-field/69352/1 "2016-12-18T02:36:40Z")

</div>

**My Log Line:**

```
2016-12-18 05:30:46 kannel 2016-12-18 05:30:46 SMS HTTP-request sender:44176845678 request: 'The Today Date "18/12/2016",Adam Smith "18/12/2016",and Time "05:30"

```

I have installed logstash from rpm package manager. I have used filebeat as log shipper.

**My configuration:**

```
input {
        beats {
                port => 5000
          }
}

filter {
        if "sender:" in [message] {
                        grok {
                                match => { "message" => "%{TIMESTAMP_ISO8601:senttime} %{GREEDYDATA:hostname} %{TIMESTAMP_ISO8601:timestamp} %{WORD:type} %{GREEDYDATA:method} sender:%{WORD:phno} request: %{GREEDYDATA:txtmessage}" }
                    }

                     mutate {
                          add_field => { "senttime" => "%{senttime}"}
                        }
        }else{
                 drop { }
            }
        }

output {
                 elasticsearch {
                        hosts => ["192.20.10.12:9200"]
                        index => "sender_log"
                }
}

```

I have also tried to add field in grok itself:

> ```
> grok {
> match => { "message" => "%{TIMESTAMP_ISO8601:senttime} %{GREEDYDATA:hostname} %{TIMESTAMP_ISO8601:timestamp} %{WORD:type} %{GREEDYDATA:method} sender:%{WORD:phno} request: %{GREEDYDATA:txtmessage}" }
> add_field => ["senttime", "%{senttime}"]
> }
> 
> ```

I am trying to add field using mutate but the field content is %{senttime} instead of 2016-12-18 05:30:46 itself. How do I add content as per match. Also, how do i dynamically specify optput index?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 20, 2016, 9:16pm UTC](https://discuss.elastic.co/t/logstash-not-creating-new-field/69352/2 "2016-12-20T21:16:07Z")

</div>

Your mutate filter serves no purpose, remove it. Listing `add_field => ["senttime", "%{senttime}"]` in the grok filter is equally pointless.

It sounds like your grok filter doesn't match. Are your events getting a `_grokparsefailure` tag?

> Also, how do i dynamically specify optput index?

The `index` option supports `%{name-of-field}` references so you can piece together an index name based on one or more fields.

---

<div class="post-metadata">

**Author:** ![kitex](https://avatars.discourse-cdn.com/v4/letter/k/f14d63/32.png) [@kitex](https://discuss.elastic.co/u/kitex)\
**Post date:** [December 23, 2016, 7:26am UTC](https://discuss.elastic.co/t/logstash-not-creating-new-field/69352/3 "2016-12-23T07:26:48Z")

</div>

Yes. There was grokparsefailure.I changed it then it worked.Thank you !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 20, 2017, 7:27am UTC](https://discuss.elastic.co/t/logstash-not-creating-new-field/69352/4 "2017-01-20T07:27:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
