# Best way to prevent add\_fields with %{} when field does not exist

**URL:** <https://discuss.elastic.co/t/best-way-to-prevent-add-fields-with-when-field-does-not-exist/74444>\
**Category:** Logstash\
**Created:** [February 8, 2017, 10:58pm UTC](https://discuss.elastic.co/t/best-way-to-prevent-add-fields-with-when-field-does-not-exist/74444 "2017-02-08T22:58:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![djhart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djhart/32/8990_2.png) [@djhart](https://discuss.elastic.co/u/djhart)\
**Post date:** [February 8, 2017, 10:58pm UTC](https://discuss.elastic.co/t/best-way-to-prevent-add-fields-with-when-field-does-not-exist/74444/1 "2017-02-08T22:58:37Z")

</div>

I have a lot of csv fields that i'm using a csv filter to parse and sometimes the fields are blank. Right after parsing them, I assign the results to new fields using mutate's add\_field. Here is a sample

csv {  
separator =\> "," columns =\> ["pid", "name", "dev\_contact", "dev\_location", "dev\_vendor", "dev\_family"]  
}

mutate {  
add\_field =\> {  
"id" =\> "%{pid}"  
"name" =\> "%{name}"  
"[dev][contact]" =\> "%{dev\_contact}"  
"[dev][location]" =\> "%{dev\_location}"  
"[dev][vendor]" =\> "%{dev\_vendor}"  
"[dev][family]" =\> "%{dev\_family}"  
}  
}

Using this method, if there is no entry for any field, such as dev\_contact, then my [dev][contact] will contain  
%{dev\_contact}.

I'm aware that I can check if dev\_contact exists before assignment like this:

if [dev\_contact]{  
mutate {  
add\_field =\> { "[dev][contact]" =\> "%{dev\_contact}" }  
}  
}

but i really do not want to do that for all of my fields since my actual csv has hundreds of fields. Is there a better way to prevent add\_field from putting the variable in if nothing exists?

Thanks for any ideas!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 9, 2017, 6:52am UTC](https://discuss.elastic.co/t/best-way-to-prevent-add-fields-with-when-field-does-not-exist/74444/2 "2017-02-09T06:52:57Z")

</div>

No, but you could e.g.

- write a snippet of ruby in a ruby filter to do all the necessary mutations or
- generate the necessary configuration so it doesn't matter if you have hundreds of conditionals.

---

<div class="post-metadata">

**Author:** ![djhart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djhart/32/8990_2.png) [@djhart](https://discuss.elastic.co/u/djhart)\
**Post date:** [February 9, 2017, 9:33pm UTC](https://discuss.elastic.co/t/best-way-to-prevent-add-fields-with-when-field-does-not-exist/74444/3 "2017-02-09T21:33:42Z")

</div>

Thanks, Magnus. I just wanted to verify that I wasn't making things harder than they should be.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2017, 9:34pm UTC](https://discuss.elastic.co/t/best-way-to-prevent-add-fields-with-when-field-does-not-exist/74444/4 "2017-03-09T21:34:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
