# Tagging a document

**URL:** <https://discuss.elastic.co/t/tagging-a-document/251899>\
**Category:** Logstash\
**Created:** [October 13, 2020, 12:21pm UTC](https://discuss.elastic.co/t/tagging-a-document/251899 "2020-10-13T12:21:48Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [October 13, 2020, 12:21pm UTC](https://discuss.elastic.co/t/tagging-a-document/251899/1 "2020-10-13T12:21:48Z")

</div>

With the logic below, I am getting a field in the document, a\_device\_customer\_code = 'dupont', but the document is tagged with tags = '%{cust\_code]'. Is there something I am over looking?

|t a\_device\_customer\_code |||---|---|||dupont|  
|t tags |||---|---|||syslog, shared, beats\_input\_codec\_plain\_applied, %{cust\_code}|

```auto
        if "shared" in [tags] {
            mutate {
               add_field => { a_device_customer_code => "%{cust_code}" }
               add_tag => ["%{cust_code}"]

               remove_field => ["cust_code"]
            }
        }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 13, 2020, 3:54pm UTC](https://discuss.elastic.co/t/tagging-a-document/251899/2 "2020-10-13T15:54:38Z")

</div>

common options are applied in a [fixed order](https://github.com/elastic/logstash/blob/6e5ea14c0be933823ff8515ffafe94f497692b98/logstash-core/lib/logstash/filters/base.rb#L197) -- add\_field, remove\_field, add\_tag, remove\_tag. By the time your add\_tag option is applied the remove\_field has already been applied. You will need to use two mutate filters to control the order.

---

<div class="post-metadata">

**Author:** ![chapmantrain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chapmantrain/32/22646_2.png) [@chapmantrain](https://discuss.elastic.co/u/chapmantrain)\
**Post date:** [October 13, 2020, 4:13pm UTC](https://discuss.elastic.co/t/tagging-a-document/251899/3 "2020-10-13T16:13:10Z")

</div>

Thanks Badger, didn't know that. I will apply appropriate controls from now on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2020, 4:13pm UTC](https://discuss.elastic.co/t/tagging-a-document/251899/4 "2020-11-10T16:13:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
