# Checking for existence of nested field

**URL:** <https://discuss.elastic.co/t/checking-for-existence-of-nested-field/34330>\
**Category:** Logstash\
**Created:** [November 11, 2015, 12:46pm UTC](https://discuss.elastic.co/t/checking-for-existence-of-nested-field/34330 "2015-11-11T12:46:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![danieljamesscott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danieljamesscott/32/47151_2.png) [@danieljamesscott](https://discuss.elastic.co/u/danieljamesscott)\
**Post date:** [November 11, 2015, 12:46pm UTC](https://discuss.elastic.co/t/checking-for-existence-of-nested-field/34330/1 "2015-11-11T12:46:41Z")

</div>

Hi,

Some of my grok filters parse my message fields into 2 parts:

```
             "message" => [
    [0] "2015-11-11 12:44:38.225 +0000 INFO [pool-1-thread-1] com.example.JavaClass: logmessage",
    [1] "logmessage"
],

```

I'm trying to replace the 'message' field with the parsed message, and store the original message in another field:

```
   if [message][1] =~ /.+/ {
      mutate {
           add_field => {"original_message" => "%{[message][0]}"}
           }
      mutate {
           replace => {"message" => "%{[message][1]}"}
           }
   }

```

This works fine for messages which do have [0] and [1] parts, but messages which do not have subfields are coming out with literal '0' and '1' in the field values, according to 'rubydebug':

```
{
         "message" => "1",
         "original_message" => "0"
}

```

Any ideas what I'm doing wrong?

Thanks,

Dan

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 11, 2015, 12:48pm UTC](https://discuss.elastic.co/t/checking-for-existence-of-nested-field/34330/2 "2015-11-11T12:48:39Z")

</div>

Can't you just avoid capturing `message` twice, perhaps by renaming `message` to `original_message` prior to the grok filter?

---

<div class="post-metadata">

**Author:** ![danieljamesscott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danieljamesscott/32/47151_2.png) [@danieljamesscott](https://discuss.elastic.co/u/danieljamesscott)\
**Post date:** [November 11, 2015, 1:10pm UTC](https://discuss.elastic.co/t/checking-for-existence-of-nested-field/34330/3 "2015-11-11T13:10:54Z")

</div>

Thanks - I've worked around it by using `log_message` in my `grok`'s, to hold the parsed log message

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:23am UTC](https://discuss.elastic.co/t/checking-for-existence-of-nested-field/34330/4 "2017-07-06T05:23:09Z")

</div>


