# Unbale to add filed in logstash for json source

**URL:** <https://discuss.elastic.co/t/unbale-to-add-filed-in-logstash-for-json-source/178099>\
**Category:** Logstash\
**Created:** [April 23, 2019, 7:02pm UTC](https://discuss.elastic.co/t/unbale-to-add-filed-in-logstash-for-json-source/178099 "2019-04-23T19:02:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Charan\_Adabala](https://avatars.discourse-cdn.com/v4/letter/c/eb8c5e/32.png) [@Charan\_Adabala](https://discuss.elastic.co/u/Charan_Adabala)\
**Post date:** [April 23, 2019, 7:02pm UTC](https://discuss.elastic.co/t/unbale-to-add-filed-in-logstash-for-json-source/178099/1 "2019-04-23T19:02:00Z")

</div>

Hi,

I am trying to add new filed based on the filed exists in the event, but I'm unable add can you please help on that.

Event:

{  
"@version": "1",  
"@timestamp": "2019-04-23T18:04:19.680Z",  
"headers": {  
"http\_version": "HTTP/1.1",  
"http\_accept": "_/_",  
"http\_user\_agent": "python-requests/2.15.1",  
"accept\_encoding": "gzip, deflate",  
"request\_path": "/",  
"connection": "keep-alive",  
"request\_method": "POST",  
"content\_length": "1430",  
"http\_host": "10.75.30.138:9600"  
},  
"message": "{"cluster\_host\_id": "localhost", "counter": 13, "stdout": "\r\nTASK [fetch galaxy roles from requirements.yml (forced update)] \*\*\*\*\*\*\*\*\*\*\*\*\*\*\*\*", "tower\_uuid": "", "@timestamp": "2019-04-23T18:05:46.013Z", "playbook": "project\_update.yml", "event\_display": "Task Started (fetch galaxy roles from requirements.yml (forced update))", "start\_line": 17, "id": 157421, "uuid": "fa163e19-4617-5547-021b-000000000021", "event": "playbook\_on\_task\_start", **"failed": false** , "role": "", "type": "logstash", "event\_data": {"play\_pattern": "all", "play": "all", "task": "fetch galaxy roles from requirements.yml (forced update)", "task\_args": "", "name": "fetch galaxy roles from requirements.yml (forced update)", "pid": 3, "play\_uuid": "fa163e19-4617-5547-021b-00000000001d", "is\_conditional": false, "task\_uuid": "fa163e19-4617-5547-021b-000000000021", "playbook\_uuid": "b4277288-81ad-443d-8839-abdf51d4f2f2", "playbook": "project\_update.yml", "task\_action": "command", "task\_path": "/var/lib/awx/venv/awx/lib/python2.7/site-packages/awx/playbooks/project\_update.yml:150"}, "play": "all", "host": "[a.ashs2.f.net.com](http://a.ashs2.f.net.com)", "project\_update": 10261, "logger\_name": "analytics.job\_events", "message": "Event data saved.", "task": "fetch galaxy roles from requirements.yml (forced update)", "level": "INFO", "verbosity": 0, "changed": false, "modified": "2019-04-23T18:05:45.000Z", "end\_line": 19, "created": "2019-04-23T18:05:45.000Z"}",  
"host": "10.75.34.196"  
}

In the above event highlighted one filed, based on that I need to add new filed, I written config like this 🙂

input {  
file {  
path =\> "input.json"  
start\_position =\> "beginning"  
codec =\> "json"  
}  
}  
filter {  
json {  
source =\> "message"  
}  
if [message][failed] == 'false' {  
mutate {  
add\_field =\> {  
"job\_status" =\> "success"  
}  
}  
}  
if [message][failed] == 'true' {  
mutate {  
add\_field =\> {  
"job\_status" =\> "failed"  
}  
}  
}  
}  
output {  
file{  
path =\> "output.json"  
codec =\> json\_lines  
}  
}

but I'm unable to add the field can you please help me.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 23, 2019, 7:14pm UTC](https://discuss.elastic.co/t/unbale-to-add-filed-in-logstash-for-json-source/178099/2 "2019-04-23T19:14:32Z")

</div>

> [@Charan\_Adabala](#):
>
> if [message][failed] == 'false' {

if either json codec or the json filter is able to parse the message (and you should only need one of those, not both) then I would expect the failed field to be at the top level. Additionally, its a boolean, so a string comparison with "false" is not what you want. Your test should be

```
if ![failed] {

```

---

<div class="post-metadata">

**Author:** ![Charan\_Adabala](https://avatars.discourse-cdn.com/v4/letter/c/eb8c5e/32.png) [@Charan\_Adabala](https://discuss.elastic.co/u/Charan_Adabala)\
**Post date:** [April 24, 2019, 2:08am UTC](https://discuss.elastic.co/t/unbale-to-add-filed-in-logstash-for-json-source/178099/3 "2019-04-24T02:08:02Z")

</div>

Hi Badger,  
Thanks for your help, It's solved

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2019, 2:08am UTC](https://discuss.elastic.co/t/unbale-to-add-filed-in-logstash-for-json-source/178099/4 "2019-05-22T02:08:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
