# Problem with add\_tag

**URL:** <https://discuss.elastic.co/t/problem-with-add-tag/194426>\
**Category:** Logstash\
**Created:** [August 8, 2019, 12:07pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426 "2019-08-08T12:07:07Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arnodl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnodl/32/48837_2.png) [@Arnodl](https://discuss.elastic.co/u/Arnodl)\
**Post date:** [August 8, 2019, 12:07pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/1 "2019-08-08T12:07:07Z")

</div>

Hello, I would like to change the tags field to a lowercase field.

My original message like this:  
{ "@timestamp": "2019-08-08T13:33:38.86", "appid": "bla", "tags": ["SUCC:AUTHEN"] }

My filter:  
mutate {  
rename =\> { "[tags]" =\> "[tags\_tmp]" }  
}

```
	if "SUCC" in [tags_tmp] {
		add_tag = ["succ"]
	}

```

OR  
if [tags\_tmp] =~ /SUCC/ {  
add\_tag = ["succ"]  
}

My result:   
"tags\_tmp": ["SUCC:AUTHEN"],  
"tags": ,

Why the tags field is empty??

---

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [August 8, 2019, 12:22pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/2 "2019-08-08T12:22:01Z")

</div>

Have you tried the [mutate filter lowercase option](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-lowercase) instead?

---

<div class="post-metadata">

**Author:** ![Arnodl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnodl/32/48837_2.png) [@Arnodl](https://discuss.elastic.co/u/Arnodl)\
**Post date:** [August 8, 2019, 12:27pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/3 "2019-08-08T12:27:41Z")

</div>

no, tags must look like this :tags: ["succ","authen"]and not like this: tags: ["succ:authen"]

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [August 8, 2019, 12:51pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/4 "2019-08-08T12:51:59Z")

</div>

But if you followed Benny's suggestion and combined it with a [split filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html), you'd get what you want.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 8, 2019, 1:00pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/5 "2019-08-08T13:00:26Z")

</div>

> [@Arnodl](#):
>
> Why the tags field is empty??

The first one, using "in", fails because there is no member of the tags array that is exactly equal to "SUCC". For the second you would have to test against a member of the array

```
if [tags_tmp][0] =~ /SUCC/ { mutate { add_tag => ["succ"] } }

```

---

<div class="post-metadata">

**Author:** ![Arnodl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnodl/32/48837_2.png) [@Arnodl](https://discuss.elastic.co/u/Arnodl)\
**Post date:** [August 8, 2019, 2:07pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/7 "2019-08-08T14:07:15Z")

</div>

ok almost works.

"tags\_tmp": ["SUCC:AUTHEN"]

My filter:  
if [tags\_tmp][0] =~/SUCC/ {  
mutate { add\_tag =\> ["succ"] }  
}  
else if [tags\_tmp][0] =~/FAIL/ {  
mutate { add\_tag =\> ["fail"] }  
}  
else if [tags\_tmp][0] =~/AUTHEN/ {  
mutate { add\_tag =\> ["authen"] }  
}  
if [tags\_tmp][1] =~/SUCC/ {  
mutate { add\_tag =\> ["succ"] }  
}  
else if [tags\_tmp][1] =~/FAIL/ {  
mutate { add\_tag =\> ["fail"] }  
}  
else if [tags\_tmp][1] =~/AUTHEN/ {  
mutate { add\_tag =\> ["authen"] }  
}

My result: "tags": ["succ"], but why not "tags": ["succ","authen"] ??

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [August 8, 2019, 2:20pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/8 "2019-08-08T14:20:48Z")

</div>

There is no [tags\_tmp][1] because there is only one entry (which is a string with multiple words).

```
if [tags_tmp][0] =~/SUCC/ {
mutate { add_tag => ["succ"] }
}
if [tags_tmp][0] =~/FAIL/ {
mutate { add_tag => ["fail"] }
}
if [tags_tmp][0] =~/AUTHEN/ {
mutate { add_tag => ["authen"] }
}
```

---

<div class="post-metadata">

**Author:** ![Arnodl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnodl/32/48837_2.png) [@Arnodl](https://discuss.elastic.co/u/Arnodl)\
**Post date:** [August 8, 2019, 2:28pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/9 "2019-08-08T14:28:19Z")

</div>

Great !  
It's works:  
if [tags\_tmp][0] =~/SUCC/ {  
mutate { add\_tag =\> ["succ"] }  
}  
if [tags\_tmp][0] =~/FAIL/ {  
mutate { add\_tag =\> ["fail"] }  
}  
if [tags\_tmp][0] =~/AUTHEN/ {  
mutate { add\_tag =\> ["authen"] }  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 8, 2019, 2:45pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/10 "2019-08-08T14:45:10Z")

</div>

This is all going to be really fragile, because it can break if the initial message has more than one tags. That said, I would do it using

```
    mutate { copy => { "[tags][0]" => "[tags_tmp]" } }
    mutate { split => { "[tags_tmp]" => ":" } }
    mutate { lowercase => ["tags_tmp"] }

```

which gets you

```
  "tags_tmp" => [
    [0] "succ",
    [1] "authen"
],
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 5, 2019, 2:58pm UTC](https://discuss.elastic.co/t/problem-with-add-tag/194426/11 "2019-09-05T14:58:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
