# Clean method for adding field when the values may be missing?

**URL:** <https://discuss.elastic.co/t/clean-method-for-adding-field-when-the-values-may-be-missing/303769>\
**Category:** Logstash\
**Created:** [May 2, 2022, 7:42pm UTC](https://discuss.elastic.co/t/clean-method-for-adding-field-when-the-values-may-be-missing/303769 "2022-05-02T19:42:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jbrowe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jbrowe/32/99821_2.png) [@jbrowe](https://discuss.elastic.co/u/jbrowe)\
**Post date:** [May 2, 2022, 7:42pm UTC](https://discuss.elastic.co/t/clean-method-for-adding-field-when-the-values-may-be-missing/303769/1 "2022-05-02T19:42:28Z")

</div>

I have logs with variable field names. For example:

```auto
{"field_one":"first", "field_two":"second"}

("field_two":"second", "field_three": "third"}

```

To get the correct index mapping, I currently I use:

```auto
mutate {
     add_field => {
          "[field][one]" => "%{field_one}"
          "[field][two]" => "%{field_two}"
          "[field][three]" => "%{field_three}"
     }
}

```

This works, but I get the following indexed events:

```auto
[field][one] : "first", [field][two]: "second", [field][three]: "%{field_three}"

[field][one]: "%{field_one}", [field][two]: "second", [field][three]: "third"

```

If a value is not present in the event, then the value for the added field is just "%{value}". Is there a cleaner way to do this without adding an if statement to every single field added?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2022, 7:42pm UTC](https://discuss.elastic.co/t/clean-method-for-adding-field-when-the-values-may-be-missing/303769/2 "2022-05-30T19:42:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
