# Logtash copy one field to another in a different log

**URL:** <https://discuss.elastic.co/t/logtash-copy-one-field-to-another-in-a-different-log/324423>\
**Category:** Logstash\
**Created:** [February 1, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logtash-copy-one-field-to-another-in-a-different-log/324423 "2023-02-01T12:39:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tegerei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tegerei/32/132992_2.png) [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Post date:** [February 1, 2023, 12:39pm UTC](https://discuss.elastic.co/t/logtash-copy-one-field-to-another-in-a-different-log/324423/1 "2023-02-01T12:39:45Z")

</div>

Hello,  
I have the following sample log.

```auto
Feb 1 15:30:49 sudo: pam_unix(sudo-i:auth): authentication failure; logname= uid=10050 euid=0 tty=/dev/pts/2 user=test

Feb 1 15:30:50 sudo: pam_sss(sudo-i:auth): authentication success; logname= uid=10050 euid=0 tty=/dev/pts/2 

```

I am using elapsed logstash filter to calculate the time difference. I have it working, however I need the second log to have the field **user=test** as in first log so that I can use the field in Kibana Visualization.  
Any ideas on how this can be achieved?  
Thank you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2023, 12:40pm UTC](https://discuss.elastic.co/t/logtash-copy-one-field-to-another-in-a-different-log/324423/2 "2023-03-01T12:40:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
