# Check if a field is a given type in logstash

**URL:** <https://discuss.elastic.co/t/check-if-a-field-is-a-given-type-in-logstash/197304>\
**Category:** Logstash\
**Created:** [August 29, 2019, 9:35am UTC](https://discuss.elastic.co/t/check-if-a-field-is-a-given-type-in-logstash/197304 "2019-08-29T09:35:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![alchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alchy/32/47743_2.png) [@alchy](https://discuss.elastic.co/u/alchy)\
**Post date:** [August 29, 2019, 9:35am UTC](https://discuss.elastic.co/t/check-if-a-field-is-a-given-type-in-logstash/197304/1 "2019-08-29T09:35:02Z")

</div>

dear,  
from a source (winlogbeat 7.11) I'm getting the messages which should contain specific type, but sometime, the type is not the type expected and elastic won't index the data.  
i would like to have a condition in logstash which will check, if valid type is given and if it is not, then the field will be removed. i'm not sure how to achiveve this.

approx. example of what i would like to have:

```
  # failed to parse field [winlog.event_data.IpPort] of type [integer]
  #if ( "" in [winlog][event_data][IpPort] ) {
  # grok {
  # match => { "[winlog][event_data][UtcTime]" => "%{IP}" }
  # break_on_match => true
  # mutate { remove_field => ["[winlog][event_data][IpPort]" ] }
  # }
  #}

```

thanks for ideas

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2019, 9:35am UTC](https://discuss.elastic.co/t/check-if-a-field-is-a-given-type-in-logstash/197304/2 "2019-09-26T09:35:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
