# Unable to get new field with mutate filter

**URL:** <https://discuss.elastic.co/t/unable-to-get-new-field-with-mutate-filter/302228>\
**Category:** Logstash\
**Created:** [April 12, 2022, 1:01pm UTC](https://discuss.elastic.co/t/unable-to-get-new-field-with-mutate-filter/302228 "2022-04-12T13:01:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zubair\_aftab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zubair_aftab/32/103257_2.png) [@zubair\_aftab](https://discuss.elastic.co/u/zubair_aftab)\
**Post date:** [April 12, 2022, 1:01pm UTC](https://discuss.elastic.co/t/unable-to-get-new-field-with-mutate-filter/302228/1 "2022-04-12T13:01:22Z")

</div>

i split my array temp as below

if [temp] {  
split {  
field =\> "[temp]"  
}  
}

i get different fields, one of the is : temp.isup\_isup\_message\_type

Then i want to add a new field based on values in this field : temp.isup\_isup\_message\_type

if [temp.isup\_isup\_message\_type] == "65" {  
mutate {  
add\_field =\> { "test" =\> "APM" }  
}  
}

I dont get any syntax error but the field "test" is not getting created.

What am i doing wrong?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 12, 2022, 1:06pm UTC](https://discuss.elastic.co/t/unable-to-get-new-field-with-mutate-filter/302228/2 "2022-04-12T13:06:57Z")

</div>

Can you share an example of your message?

Also, you are not referring to nested fields in the correct way.

If you have a field named `temp` with a nested field named `isup_isup_message_type`, in logstash you need to use `[temp][isup_isup_message_type]` in your conditional.

---

<div class="post-metadata">

**Author:** ![zubair\_aftab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zubair_aftab/32/103257_2.png) [@zubair\_aftab](https://discuss.elastic.co/u/zubair_aftab)\
**Post date:** [April 12, 2022, 1:26pm UTC](https://discuss.elastic.co/t/unable-to-get-new-field-with-mutate-filter/302228/3 "2022-04-12T13:26:45Z")

</div>

I have just taken the part from the output to show you:

```
 "timestamp" => "1640072854196",
      "temp" => [

    [1] {
              "isup_isup_message_type" => "65",
   			}

```

i tried with [temp][isup\_isup\_message\_type] but not working

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 12, 2022, 2:36pm UTC](https://discuss.elastic.co/t/unable-to-get-new-field-with-mutate-filter/302228/4 "2022-04-12T14:36:05Z")

</div>

> [@zubair\_aftab](#):
>
> ```auto
> "temp" => [
> 
> [1] {
> "isup_isup_message_type" => "65",
> }
> 
> ```

In that case [temp] is an array, so you would need to use

```
[temp][1][isup_isup_message_type]

```

(I assume you removed the [0] entry from the rubydebug output...

---

<div class="post-metadata">

**Author:** ![zubair\_aftab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zubair_aftab/32/103257_2.png) [@zubair\_aftab](https://discuss.elastic.co/u/zubair_aftab)\
**Post date:** [April 13, 2022, 10:35am UTC](https://discuss.elastic.co/t/unable-to-get-new-field-with-mutate-filter/302228/5 "2022-04-13T10:35:10Z")

</div>

Yes i removed [0].  
And thanks it worked with [temp][1][isup\_isup\_message\_type]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2022, 10:35am UTC](https://discuss.elastic.co/t/unable-to-get-new-field-with-mutate-filter/302228/6 "2022-05-11T10:35:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
