# \[Solved\] Fingerprint does not work as expected II

**URL:** <https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560>\
**Category:** Logstash\
**Created:** [June 1, 2016, 1:20pm UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560 "2016-06-01T13:20:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Swen](https://avatars.discourse-cdn.com/v4/letter/s/e8c25b/32.png) [@Swen](https://discuss.elastic.co/u/Swen)\
**Post date:** [June 1, 2016, 1:20pm UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560/1 "2016-06-01T13:20:10Z")

</div>

I want to use a fingerprint to put it into the document\_id.

fingerprint {  
key =\> "78787878"  
method =\> "SHA1"  
}

I expect this to make a hash from my 'message' and to see a 'fingerprint' variable with the hash in the output. That is not the case. I played around allot.

Only way to get it work is:

fingerprint {  
key =\> "78787878"  
method =\> "SHA1"  
concatenate\_sources =\> true  
}

Then I finally see a fingerprint with a hash in the output. BUT. It's the same for all events although the 'message' is definitely distinguished.

My whole filter is this:

filter {  
split {  
field =\> "mail"  
}  
fingerprint {  
key =\> "78787878"  
method =\> "SHA1"  
concatenate\_sources =\> true  
}

mutate {  
add\_field =\> {  
"log\_domain" =\> "cio"  
"log\_component" =\> "disflower\_input\_test6"  
}  
}  
}

What's wrong here?

I'm using logstash 2.3.2

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 1, 2016, 2:23pm UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560/2 "2016-06-01T14:23:19Z")

</div>

It works just fine for me. Do you have the default 'message' field available when you invoke the fingerprint filter? What does the resulting event look like if you output it to stdout using the rubydebug codec?

---

<div class="post-metadata">

**Author:** ![Swen](https://avatars.discourse-cdn.com/v4/letter/s/e8c25b/32.png) [@Swen](https://discuss.elastic.co/u/Swen)\
**Post date:** [June 1, 2016, 2:36pm UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560/3 "2016-06-01T14:36:37Z")

</div>

Output looks like this:

```
   "@version" => "1",
   "@timestamp" => "2016-06-01T14:35:35.579Z",
   "host" => "WPNLL0037485",
   "command" => "C:\\Data\\INGteststraat\\TestEngine\\LogStashLib\\RequestRest\\bin\\Debug\\RequestRest.exe",
   "log_domain" => "cio",
"log_component" => "disflower_input_test6"
```

---

<div class="post-metadata">

**Author:** ![Swen](https://avatars.discourse-cdn.com/v4/letter/s/e8c25b/32.png) [@Swen](https://discuss.elastic.co/u/Swen)\
**Post date:** [June 1, 2016, 2:39pm UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560/4 "2016-06-01T14:39:49Z")

</div>

Update:

This works. But only this. "Message" does not work.

fingerprint {  
source =\> ["@timestamp"]  
key =\> "78787878"  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 1, 2016, 2:41pm UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560/5 "2016-06-01T14:41:25Z")

</div>

There does not seem to be any `message` field, so you will need to specify the field(s) to use for the fingerprint using the `source` parameter.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 1, 2016, 2:43pm UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560/6 "2016-06-01T14:43:18Z")

</div>

You should be able to specify multiple fields in the source array as long as you also enable `concatenate_sources`.

It would be useful if it automatically concatenated sources if you provide an array.

---

<div class="post-metadata">

**Author:** ![Swen](https://avatars.discourse-cdn.com/v4/letter/s/e8c25b/32.png) [@Swen](https://discuss.elastic.co/u/Swen)\
**Post date:** [June 1, 2016, 4:04pm UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560/7 "2016-06-01T16:04:07Z")

</div>

You are right. It's working. I was thinking that I Always have a 'message' variable.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:55am UTC](https://discuss.elastic.co/t/solved-fingerprint-does-not-work-as-expected-ii/51560/8 "2017-07-06T04:55:00Z")

</div>


