# Match multiple values into one field

**URL:** <https://discuss.elastic.co/t/match-multiple-values-into-one-field/181115>\
**Category:** Logstash\
**Created:** [May 15, 2019, 7:48am UTC](https://discuss.elastic.co/t/match-multiple-values-into-one-field/181115 "2019-05-15T07:48:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [May 15, 2019, 7:48am UTC](https://discuss.elastic.co/t/match-multiple-values-into-one-field/181115/1 "2019-05-15T07:48:56Z")

</div>

Hi,

We want to match multiple values into one field from a single Document/Message.

For example, the following message:

"Testlog, Field1=value1,asdasda,asdasd,asdasd,Field2=value2"

With the following grok patterns:

"Field1=%{WORD:matched\_field}" And "Field2=%{WORD:matched\_field}".

So we want to create a field, "matched\_field" and populate it with values from two matches. Our concern is that if we match on "Field1" it will overwrite the value when it matches "Field2". We simply want to append it and have both matches in a single field. We have set the logstash pipeline to not break on match.

---

<div class="post-metadata">

**Author:** ![CristianoFerreira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cristianoferreira/32/47529_2.png) [@CristianoFerreira](https://discuss.elastic.co/u/CristianoFerreira)\
**Post date:** [May 15, 2019, 10:02am UTC](https://discuss.elastic.co/t/match-multiple-values-into-one-field/181115/2 "2019-05-15T10:02:08Z")

</div>

Hi,

You could do the following grok patterns:

"Field1=%{WORD:matched\_field\_1}" And "Field2=%{WORD:matched\_field\_2}".

And then concatenate like:

```
mutate {
   add_field => {
      "matched_field" => "%{matched_field_1} %{matched_field_2}"
   }
   remove_field => ["matched_field_1", "matched_field_2"]
}

```

Best Regards

---

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [May 15, 2019, 10:52am UTC](https://discuss.elastic.co/t/match-multiple-values-into-one-field/181115/3 "2019-05-15T10:52:33Z")

</div>

I don't think that's really what we are trying to do.

We want to have two values in one field. Like this:  
Field1: value1,value2

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 15, 2019, 12:45pm UTC](https://discuss.elastic.co/t/match-multiple-values-into-one-field/181115/4 "2019-05-15T12:45:21Z")

</div>

> [@victor.nilsson](#):
>
> Our concern is that if we match on "Field1" it will overwrite the value when it matches "Field2".

No it will not, you will end up with matched\_field being an array containing both values.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2019, 12:45pm UTC](https://discuss.elastic.co/t/match-multiple-values-into-one-field/181115/5 "2019-06-12T12:45:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
