With the logic below, I am getting a field in the document, a_device_customer_code = 'dupont', but the document is tagged with tags = '%{cust_code]'. Is there something I am over looking?
|t a_device_customer_code |||---|---|||dupont|
|t tags |||---|---|||syslog, shared, beats_input_codec_plain_applied, %{cust_code}|
if "shared" in [tags] {
mutate {
add_field => { a_device_customer_code => "%{cust_code}" }
add_tag => [ "%{cust_code}" ]
remove_field => [ "cust_code" ]
}
}