# Logstash Syntax :: Copy String from One Field into a New Field

**URL:** <https://discuss.elastic.co/t/logstash-syntax-copy-string-from-one-field-into-a-new-field/237661>\
**Category:** Logstash\
**Created:** [June 18, 2020, 3:10pm UTC](https://discuss.elastic.co/t/logstash-syntax-copy-string-from-one-field-into-a-new-field/237661 "2020-06-18T15:10:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![redapplesonly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redapplesonly/32/57700_2.png) [@redapplesonly](https://discuss.elastic.co/u/redapplesonly)\
**Post date:** [June 18, 2020, 3:10pm UTC](https://discuss.elastic.co/t/logstash-syntax-copy-string-from-one-field-into-a-new-field/237661/1 "2020-06-18T15:10:31Z")

</div>

Hello Logstash Zen Masters,

In my data, I have a field named FieldA which contains a string. Later in my filter{} section, I need to access and copy that string into a newly-created field. I've tried a lot of variations which allow Logstash to launch, but cause a Java error shortly after LS gets going.

I need this:

```
if SOME_CONDITION {
  mutate {
    add_field => { "NewField" => %[FieldA] }
  }
}

```

...or even...

```
if SOME_CONDITION {
  mutate {
    add_field => { "NewField" => "blahblah" }
    copy => { "FieldA" => "NewField" }
  }
}

```

Whatever works. Any suggestions?

BTW, the Java error message is really long and scary and far too large to post here in its entirity. I see Null Pointer Exceptions and Illegal State Exceptions and worse. I'm fairly confident that FieldA is not NULL... but perhaps the error means I got the syntax right and FieldA is not being set correctly? Asking for a friend...

```
[2020-06-18T10:56:39,229][FATAL][logstash.runner] An unexpected error occurred! {:error=>java.lang.IllegalStateException: java.lang.NullPointerException, :backtrace=>["org.logstash.execution.WorkerLoop.run(org/logstash/execution/WorkerLoop.java:105)", "jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)", "jdk.internal.reflect.NativeMethodAccessorImpl.invoke(jdk/internal/reflect/NativeMethodAccessorImpl.java:62)", "jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(jdk/internal/reflect/DelegatingMethodAccessorImpl.java:43)", "java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:566)", "org.jruby.javasupport.JavaMethod.invokeDirectWithExceptionHandling(org/jruby/javasupport/JavaMethod.java:441)", "org.jruby.javasupport.JavaMethod.invokeDirect(org/jruby/javasupport/JavaMethod.java:305)", "home.me.logstash.logstash_minus_7_dot_7_dot_1.logstash_minus_core.lib.logstash.java_pipeline.start_workers(/home/me/logstash/logstash-7.7.1/logstash-core/lib/logstash/java_pipeline.rb:279)", "org.jruby.RubyProc.call(org/jruby/RubyProc.java:318)", "java.lang.Thread.run(java/lang/Thread.java:834)"]}
[2020-06-18T10:56:39,248][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 18, 2020, 3:19pm UTC](https://discuss.elastic.co/t/logstash-syntax-copy-string-from-one-field-into-a-new-field/237661/2 "2020-06-18T15:19:42Z")

</div>

> [@redapplesonly](#):
>
> `add_field => { "NewField" => %[FieldA] }`

That should be

```
add_field => { "NewField" => "%{[FieldA]}" }

```

---

<div class="post-metadata">

**Author:** ![redapplesonly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redapplesonly/32/57700_2.png) [@redapplesonly](https://discuss.elastic.co/u/redapplesonly)\
**Post date:** [June 18, 2020, 3:29pm UTC](https://discuss.elastic.co/t/logstash-syntax-copy-string-from-one-field-into-a-new-field/237661/3 "2020-06-18T15:29:58Z")

</div>

THanks Badger,

Still getting the scary Java error, though, so now I need to investigate why that is. Perhaps FieldA is null...? I'll have to dig deeper.

```
 THanks! -ROA
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2020, 3:29pm UTC](https://discuss.elastic.co/t/logstash-syntax-copy-string-from-one-field-into-a-new-field/237661/4 "2020-07-16T15:29:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
