# Detecting empty fields not working as before in logstash 7.12.1

**URL:** <https://discuss.elastic.co/t/detecting-empty-fields-not-working-as-before-in-logstash-7-12-1/271764>\
**Category:** Logstash\
**Created:** [April 30, 2021, 10:50am UTC](https://discuss.elastic.co/t/detecting-empty-fields-not-working-as-before-in-logstash-7-12-1/271764 "2021-04-30T10:50:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mario\_wood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_wood/32/88001_2.png) [@mario\_wood](https://discuss.elastic.co/u/mario_wood)\
**Post date:** [April 30, 2021, 10:50am UTC](https://discuss.elastic.co/t/detecting-empty-fields-not-working-as-before-in-logstash-7-12-1/271764/1 "2021-04-30T10:50:10Z")

</div>

Hi,

I'm migrating our logstash from 6.8 to 7.12 and I'm finding that the detection of empty fields is not working as it used to.

For example given the input

```json
{
  "foo":"",
  "bar":"baz"
}

```

and the logstash filter

```auto
if [foo] and [foo] == "" {
  mutate {
    remove_field => ["foo"]
  }
}

```

in logstash 6.8 we would have seen a document in elasticsearch like this:

```json
{
  "bar":"baz"
}

```

but in logstash 7.12 it seems like it's not detecting the empty field so we see this in elasticsearch:

```json
{
  "foo":"",
  "bar":"baz"
}

```

Are there some changes I've missed in the release notes that are affecting this, or should I be doing field detection another way?

We use this approach quite a lot and it's affecting our ability to detect and remove bad data from logs, or to coerce the data with the mutate filter to have default values.

Thanks,  
Andy

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 30, 2021, 3:49pm UTC](https://discuss.elastic.co/t/detecting-empty-fields-not-working-as-before-in-logstash-7-12-1/271764/2 "2021-04-30T15:49:35Z")

</div>

Interesting. This will have changed in 7.0. With

```
input { generator { count => 1 lines => [''] } }
filter {
    mutate { add_field => { "foo" => "" } }
    if [foo] { drop { } }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

by default the event is dropped. However, if you add `--java_execution false` then the event is not dropped.

---

<div class="post-metadata">

**Author:** ![mario\_wood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_wood/32/88001_2.png) [@mario\_wood](https://discuss.elastic.co/u/mario_wood)\
**Post date:** [May 13, 2021, 7:30am UTC](https://discuss.elastic.co/t/detecting-empty-fields-not-working-as-before-in-logstash-7-12-1/271764/3 "2021-05-13T07:30:44Z")

</div>

Thanks, setting

```auto
...
pipeline.java_execution: false
...

```

In logstash.yml has restored the expected behaviour.

Would this be considered as a bug as there is a difference in behaviour when java\_execution is used for creating an issue on github?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2021, 3:18pm UTC](https://discuss.elastic.co/t/detecting-empty-fields-not-working-as-before-in-logstash-7-12-1/271764/4 "2021-05-13T15:18:34Z")

</div>

> [@mario\_wood](#):
>
> Would this be considered as a bug

That is a matter of opinion. I think it is. I would try opening an issue on github and see if anyone agrees.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2021, 3:19pm UTC](https://discuss.elastic.co/t/detecting-empty-fields-not-working-as-before-in-logstash-7-12-1/271764/5 "2021-06-10T15:19:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
