# Non-sprintf reference to fields

**URL:** <https://discuss.elastic.co/t/non-sprintf-reference-to-fields/244>\
**Category:** Logstash\
**Created:** [May 5, 2015, 6:57pm UTC](https://discuss.elastic.co/t/non-sprintf-reference-to-fields/244 "2015-05-05T18:57:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mike\_Hepple](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_hepple/32/44921_2.png) [@Mike\_Hepple](https://discuss.elastic.co/u/Mike_Hepple)\
**Post date:** [May 5, 2015, 6:57pm UTC](https://discuss.elastic.co/t/non-sprintf-reference-to-fields/244/1 "2015-05-05T18:57:46Z")

</div>

I'm trying to set up environment variables to control my logstash elasticsearch output , like below

```
    # filter
    environment {
           add_field_from_env => ["elasticsearch_host", "ES_HOST", "elasticsearch_port", "ES_PORT", "elasticsearch_cluster", "ES_CLUSTER"]
    }

    # output
    elasticsearch {
            host => "%{[elasticsearch_host]}"
            port => [elasticsearch_port]
            cluster => elasticsearch_cluster
            protocol => "transport"
            flush_size => 10
            index => "application_logs"
    }

```

However, when I try to run the agent, the output fails - looking at the verbose output it's trying to connect to:

```
New Elasticsearch output {:cluster=>"elasticsearch_cluster", :host=>"%{[elasticsearch_host]}", :port=>"elasticsearch_port", :embedded=>false, :protocol=>"transport", :level=>:info}

```

So not using the fields from the event. Looking at the code, it seems like `sprintf()` needs to be called in the output to use the %{} format, and I'll raise a bug against the output if someone can confirm that is the correct assessment, however is there an alternative way to inject fields from the event without relying on the plugin correctly calling sprintf?

---

<div class="post-metadata">

**Author:** ![Mike\_Hepple](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mike_hepple/32/44921_2.png) [@Mike\_Hepple](https://discuss.elastic.co/u/Mike_Hepple)\
**Post date:** [May 5, 2015, 7:15pm UTC](https://discuss.elastic.co/t/non-sprintf-reference-to-fields/244/2 "2015-05-05T19:15:36Z")

</div>

Ah, I see why it's done this way. The ElasticSearch client is created at startup, rather than initialised with each event. So there's no way to use the environment variables as I've described - I'll have to modify my own plugin.

---

<div class="post-metadata">

**Author:** ![jordansissel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordansissel/32/44957_2.png) [@jordansissel](https://discuss.elastic.co/u/jordansissel)\
**Post date:** [May 5, 2015, 11:02pm UTC](https://discuss.elastic.co/t/non-sprintf-reference-to-fields/244/3 "2015-05-05T23:02:30Z")

</div>

Yeah, you should be able to use conditionals for this, though it's not perfect if you have unpredictable destinations in each event:

For example, using the `environment` field name to determine where to send logs for production/staging/etc:

```auto
if [environment] == "production" {
  elasticsearch {
    host => "production.example.com"
    ...
  }
} else if [environment] == "staging" {
  elasticsearch {
    host => "staging.example.com"
    ...
  }
} else {
  # neither production nor staging
  ...
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:40am UTC](https://discuss.elastic.co/t/non-sprintf-reference-to-fields/244/4 "2017-07-06T05:40:14Z")

</div>


