# Push\_previous\_map\_as\_event if fields exist

**URL:** <https://discuss.elastic.co/t/push-previous-map-as-event-if-fields-exist/250566>\
**Category:** Logstash\
**Created:** [September 30, 2020, 9:08pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-if-fields-exist/250566 "2020-09-30T21:08:24Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 30, 2020, 9:26pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-if-fields-exist/250566/2 "2020-09-30T21:26:52Z")

</div>

```
input { generator { count => 1 lines => ['{ "task": 1, "in-mb": 10 }', '{ "task": 1, "cpu": 0.1}', '{ "task": 2, "in-mb": 11 }'] } }
filter {
    json { source => "message" remove_field => ["message"] }
    aggregate {
        task_id => "%{task}"
        timeout_task_id_field => "task_id"
        timeout_timestamp_field => "@timestamp"
        code => '
            event.to_hash.each { |k,v|
                unless map[k]
                    map[k] = v
                end
            }
        '
        push_previous_map_as_event => true
    }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

will produce these two aggregated events

```
{
      "task" => 1,
       "cpu" => 0.1,
   "task_id" => "1",
  "sequence" => 0,
     "in-mb" => 10,
  "@version" => "1",
      "host" => "dot.dot",
"@timestamp" => 2020-09-30T21:24:07.164Z
}
{
      "task" => 2,
   "task_id" => "2",
  "sequence" => 0,
     "in-mb" => 11,
      "tags" => [
    [0] "_aggregatefinalflush"
],
  "@version" => "1",
      "host" => "dot.dot",
"@timestamp" => 2020-09-30T21:24:07.251Z
}
```

---

_[View the full topic](https://discuss.elastic.co/t/push-previous-map-as-event-if-fields-exist/250566)._
