# Check event format against template

**URL:** <https://discuss.elastic.co/t/check-event-format-against-template/376451>\
**Category:** Logstash\
**Created:** [March 27, 2025, 7:49am UTC](https://discuss.elastic.co/t/check-event-format-against-template/376451 "2025-03-27T07:49:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ddoroshenko](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Post date:** [March 27, 2025, 7:49am UTC](https://discuss.elastic.co/t/check-event-format-against-template/376451/1 "2025-03-27T07:49:27Z")

</div>

Hi,

is it possible to check events format against certain template in Logstash?

1. For example I want to make sure that event contains certain mandatory fields, i.e. `"environment"`, `"application"` etc.
2. For example I want to make sure that event contains certain mandatory fields with certain values, i.e. `"environment": "production"`, `"application": "application_name"`

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 27, 2025, 1:09pm UTC](https://discuss.elastic.co/t/check-event-format-against-template/376451/2 "2025-03-27T13:09:12Z")

</div>

You can use IFs with or without regex. Also is possible to drop field or all event. It depends what do you want.

```auto
input {
      generator {
	message => ['Test']
        count => 1
      }
}
output {
 stdout {codec => rubydebug{ metadata => true}}
}
filter {
	mutate {
        add_field => {
          "environment" => "test"
          "application" => "SAP"
        }
	}
	# does field exist or not null
	if [environment] {
		mutate { add_field => { "info-exist" => "Check does the field environment exist" } }
	}
	# if environment is not OK, drop all event
    if [environment] == "prod" {
        drop { }
    }
	# strictly exact value
	if [environment]== "test" {
		mutate { add_field => { "info-test" => "This is %{environment} env" } }
	}
	# multiple case-insensitive values check
	if [environment] =~ /(?i)(prod|test|staging|dev)/ {
		mutate { add_field => { "info-env" => "The environment: %{environment}" } }	
	}
    # drop field if is not in approved list of values
	prune {
		whitelist_values => [ "application","(SAP|ORACLE)" , 
		"environment", "(?i)TEST"]
	}
}

```

Output:

```auto
{
    "environment" => "test",
     "@timestamp" => 2025-03-27T13:08:56.311959Z,
    "application" => "SAP",
       "info-env" => "The environment: test",
      "info-test" => "This is test env",
     "info-exist" => "Check does the field environment exist"
}

```

---

<div class="post-metadata">

**Author:** ![ddoroshenko](https://avatars.discourse-cdn.com/v4/letter/d/b9e5f3/32.png) [@ddoroshenko](https://discuss.elastic.co/u/ddoroshenko)\
**Post date:** [March 28, 2025, 9:35am UTC](https://discuss.elastic.co/t/check-event-format-against-template/376451/3 "2025-03-28T09:35:29Z")

</div>

@Rios thank you for your response.

Yes, `if` is the first obvious solution that comes to mind.  
I would be interested in if it is possible to save this template in a separate file and somehow compare them.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 28, 2025, 9:39am UTC](https://discuss.elastic.co/t/check-event-format-against-template/376451/4 "2025-03-28T09:39:57Z")

</div>

Is it a long list? If is 10-20, I wouldn't complicate it.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 28, 2025, 10:13am UTC](https://discuss.elastic.co/t/check-event-format-against-template/376451/5 "2025-03-28T10:13:03Z")

</div>

Another idea. You can use @metadata field to store your temporary lists in the runtime. The list will not end up in ES.

```auto
	mutate {
        add_field => {
          "[@metadata][app]" => ["Oracle", "SAP", "MySQL", "SQL Server"]
          "[@metadata][env]" => ["test", "prod", "staging"]
        }
	}
	# check does value exist - case sensitive
	if "SQL Server" in [@metadata][app] {
	mutate { add_field => { "infoapp" => "App exist" } }	
	}
	# check does field value exist in list
	if [environment] in [@metadata][env] {
	mutate { add_field => { "infoenv" => "Env exist" } }	
	}

```

Add metadata =\> true in the debug mode to see current values.

```auto
output {
 stdout {codec => rubydebug{ metadata => true}}
}

```

Output

```auto
{
    "environment" => "test"
      "@metadata" => {
        "app" => [
            [0] "Oracle",
            [1] "SAP",
            [2] "MySQL",
            [3] "SQL Server"
        ],
        "env" => [
            [0] "test",
            [1] "prod",
            [2] "staging"
        ]
    },
        "infoapp" => "App exist",
        "infoenv" => "Env exist",
}

```
