# Conditionals: check field type

**URL:** <https://discuss.elastic.co/t/conditionals-check-field-type/54527>\
**Category:** Logstash\
**Created:** [July 1, 2016, 10:08am UTC](https://discuss.elastic.co/t/conditionals-check-field-type/54527 "2016-07-01T10:08:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ebuildy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebuildy/32/6070_2.png) [@ebuildy](https://discuss.elastic.co/u/ebuildy)\
**Post date:** [July 1, 2016, 10:08am UTC](https://discuss.elastic.co/t/conditionals-check-field-type/54527/1 "2016-07-01T10:08:58Z")

</div>

With the following logstash config:

```
filter
{
	if [client]
	{
		if [ip] in [client]
		{}
        }
}

```

Which is converted as:

`if (((x = event["[client]"]; x.respond_to?(:include?) && x.include?(event["[ip]"])))) # if [ip] in [client]`

When I enter the following input data to Logstash '{"client": ""}',it throws error (then stop the daemon which is not really cool in production...):

> TypeError: can't convert nil into String

Hence my question, is it possible to check if the field is a string, or an object? (or a good way to validate/sanitize input data).

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixelrebel/32/14056_2.png) [@pixelrebel](https://discuss.elastic.co/u/pixelrebel)\
**Post date:** [December 21, 2016, 11:00pm UTC](https://discuss.elastic.co/t/conditionals-check-field-type/54527/2 "2016-12-21T23:00:25Z")

</div>

I would like to do this too. I assume this may be a ruby filter, but I can't find any examples. I have a field that sometimes comes over as an array, sometimes it's a hash. I need to be able to test the field's type or logstash will crash trying to split a hash.

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [December 22, 2016, 9:40am UTC](https://discuss.elastic.co/t/conditionals-check-field-type/54527/3 "2016-12-22T09:40:25Z")

</div>

@ebuildy you can do something like:

```auto
filter {
  if [client] {
    if [client][ip] {
      # ...
    }
  }
}

```

@pixelrebel if your case you might need a rubyfilter, yes:

```auto
input {
  stdin { codec => json }
}
filter {
  ruby { code => 'case event.get("[client]")
                  when Hash
                    event.tag("hash")
                  when Array
                    event.tag("array")
                  else
                    event.tag("oh no")
                  end'
  }
}
output { stdout { codec => rubydebug } } 

```

output:

```auto
{"client": []}
{
    "@timestamp" => 2016-12-22T09:39:04.561Z,
      "@version" => "1",
          "host" => "Joaos-MBP-5.lan",
        "client" => [],
          "tags" => [
        [0] "array"
    ]
}
{"client": {}}
{
    "@timestamp" => 2016-12-22T09:39:13.829Z,
      "@version" => "1",
          "host" => "Joaos-MBP-5.lan",
        "client" => {},
          "tags" => [
        [0] "hash"
    ]
}
{"client": ""}
{
    "@timestamp" => 2016-12-22T09:39:20.005Z,
      "@version" => "1",
          "host" => "Joaos-MBP-5.lan",
        "client" => "",
          "tags" => [
        [0] "oh no"
    ]
}

```

---

<div class="post-metadata">

**Author:** ![pixelrebel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pixelrebel/32/14056_2.png) [@pixelrebel](https://discuss.elastic.co/u/pixelrebel)\
**Post date:** [December 22, 2016, 9:25pm UTC](https://discuss.elastic.co/t/conditionals-check-field-type/54527/4 "2016-12-22T21:25:24Z")

</div>

@jsvd You are an example of everything that is right in this world! Thanks so much for this!!!

And, for those playing on 2.x like myself, this is how it's done the old-fashioned way:

```
filter {
  ruby { code => 'case event["client"]
                  when Hash
                    event.tag("hash")
                  when Array
                    event.tag("array")
                  else
                    event.tag("oh no")
                  end'
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:29am UTC](https://discuss.elastic.co/t/conditionals-check-field-type/54527/5 "2017-07-06T04:29:42Z")

</div>


