# Unable to add new fields in the output event

**URL:** <https://discuss.elastic.co/t/unable-to-add-new-fields-in-the-output-event/185905>\
**Category:** Logstash\
**Created:** [June 14, 2019, 7:57pm UTC](https://discuss.elastic.co/t/unable-to-add-new-fields-in-the-output-event/185905 "2019-06-14T19:57:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashokchinna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashokchinna/32/47123_2.png) [@ashokchinna](https://discuss.elastic.co/u/ashokchinna)\
**Post date:** [June 14, 2019, 7:57pm UTC](https://discuss.elastic.co/t/unable-to-add-new-fields-in-the-output-event/185905/1 "2019-06-14T19:57:46Z")

</div>

I am trying to add a new field with the name "failed\_reason\_new". The following filter is not working.

I am getting the below error message.

```
C:/Demo/logstash-7.1.1/logstash-core/lib/logstash/compiler.rb:49:in `compile_graph'", "C:/Demo/logstash-7.1.1/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2577:in `map'", "C:/Demo/logstash-7.1.1/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'",
"org/logstash/execution/AbstractPipelineExt.java:151:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "C:/Demo/logstash-7.1.1/logstash-core/lib/logstash/java_pipeline.rb:23:in `initialize'", "C:/Demo/logstash-7.1.1/logstash-core/lib/logstash/pipeline_action/create.rb:36:in `execute'", "C:/Demo/logstash-7.1.1/logstash-core/lib/logstash/agent.rb:325:in `block in converge_state'"]}

input {
        jdbc {
               
                jdbc_driver_library => "C:\Ashok\ojdbc8-full\ojdbc8.jar"

                jdbc_driver_class => "oracle.jdbc.Driver"

                jdbc_connection_string => "jdbc:oracle:thin:@new-connection:1234:dbsource"
            
                jdbc_user => "xyz"
                jdbc_password => "xyz"

                schedule => "30 * * * *"

               
                statement => "SELECT * FROM accounts WHERE creation_date > sysdate -1 "
            }
    }
	
	filter {

  mutate {
        
        add_field => { "failed_reason_new" => %{failed_reason}}
    }

  mutate {
    gsub => [      
      "failed_reason_new", "[^a-zA-Z]", ""
    ]
  }
}

    output {
        elasticsearch {
          index => "bank"
          document_type => "account"
          hosts => "localhost:9200"
     document_id => "%{account_no}"
        }
    }
```

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [June 14, 2019, 11:14pm UTC](https://discuss.elastic.co/t/unable-to-add-new-fields-in-the-output-event/185905/2 "2019-06-14T23:14:48Z")

</div>

> [@ashokchinna](#):
>
> ```auto
> mutate {
>         
> add_field => { "failed_reason_new" => %{failed_reason}}
> }
> 
> ```

The value argument for the Mutate filter's `add_field` needs to be a quoted string.

Below is a fixed configuration, including whitespace changes to make the structure more readable:

```auto
input {
  jdbc {
    jdbc_driver_library => "C:\Ashok\ojdbc8-full\ojdbc8.jar"
    jdbc_driver_class => "oracle.jdbc.Driver"
    jdbc_connection_string => "jdbc:oracle:thin:@new-connection:1234:dbsource"
    jdbc_user => "xyz"
    jdbc_password => "xyz"
    schedule => "30 * * * *"
    statement => "SELECT * FROM accounts WHERE creation_date > sysdate -1 "
  }
}

filter {
  mutate {
    add_field => { "failed_reason_new" => "%{failed_reason}"}
  }

  mutate {
    gsub => [      
      "failed_reason_new", "[^a-zA-Z]", ""
    ]
  }
}

output {
  elasticsearch {
    index => "bank"
    document_type => "account"
    hosts => "localhost:9200"
    document_id => "%{account_no}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![ashokchinna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashokchinna/32/47123_2.png) [@ashokchinna](https://discuss.elastic.co/u/ashokchinna)\
**Post date:** [June 18, 2019, 4:52pm UTC](https://discuss.elastic.co/t/unable-to-add-new-fields-in-the-output-event/185905/3 "2019-06-18T16:52:54Z")

</div>

@yaauie Thank you, it worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 16, 2019, 4:52pm UTC](https://discuss.elastic.co/t/unable-to-add-new-fields-in-the-output-event/185905/4 "2019-07-16T16:52:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
