# Field Exists like capability in ES|QL

**URL:** https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089
**Category:** Elasticsearch
**Tags:** esql
**Created:** [June 11, 2025, 9:25am UTC](https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089 "2025-06-11T09:25:39Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ashit\_pupu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashit_pupu/32/101113_2.png) [@ashit\_pupu](https://discuss.elastic.co/u/ashit_pupu)
#### Post date: [June 11, 2025, 9:25am UTC](https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089/1 "2025-06-11T09:25:39Z")

</div>

Hi Team  
Reaching out to understand if there is any functionality available in ES|QL which could handle if a field doesn't exist. Currently if a field has never been indexed we don't have the field name in index mapping then it gives **Unknown Column** verification exception.  
In query DSL we have something called exists, I am looking for any functionality which achieves the same in ES|QL.  
The reason I am looking for this is we currently have an index which in future will have logs from a different application which will have a field called **event.type** which is not part of existing index. Before the data is indexed I wanted to build some search query but it fails once I use the given field in my ES|QL query.  
Any pointers by which I can handle this ... please let me know. I have tried is not null which again gives the same error.  
I am using Elasticsearch 8.17 version .

---

<div class="post-metadata">

### Author: ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)
#### Post date: [June 12, 2025, 4:33am UTC](https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089/2 "2025-06-12T04:33:27Z")

</div>

Hello @ashit_pupu  
Welcome back.

```auto
GET kibana_sample_data_logs/_search
{
  "query": {
    "exists": {
      "field": "event.type"
    }
  }
}

```

Output :

```auto

{
  "took": 0,
  "timed_out": false,
  "_shards": {
    "total": 1,
    "successful": 1,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": {
      "value": 0,
      "relation": "eq"
    },
    "max_score": null,
    "hits": []
  }
}

```

I have checked and see that ES|QL does not have a direct equivalent to the exists query as it returns below message :

```auto

Unexpected error from Elasticsearch: verification_exception - Found 1 problem line 3:30: Unknown column [event.type]

```

Thanks!!

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [June 12, 2025, 5:32am UTC](https://discuss.elastic.co/t/field-exists-like-capability-in-es-ql/379089/3 "2025-06-12T05:32:27Z")

</div>

I tried this:

```auto
DELETE test1,test2
POST test1/_doc
{
  "foo": "bar",
  "size": 1
}
POST test2/_doc
{
  "size": 1
}
POST _query?format=txt
{
  "query": """
    FROM test1, test2 
    | WHERE foo == "bar"
    | LIMIT 10
  """
}

```

And this gives:

```auto
      foo | foo.keyword | size      
---------------+---------------+---------------
bar |bar |1              

```

So no failure here.

But indeed, if you query the exact index name, it will fail:

```auto
POST _query?format=txt
{
  "query": """
    FROM test2
    | WHERE foo == "bar"
    | LIMIT 10
  """
}

```

What is the query you would like to run?
