# Filter records that contain a specfic field name

**URL:** <https://discuss.elastic.co/t/filter-records-that-contain-a-specfic-field-name/124476>\
**Category:** Logstash\
**Created:** [March 19, 2018, 2:52am UTC](https://discuss.elastic.co/t/filter-records-that-contain-a-specfic-field-name/124476 "2018-03-19T02:52:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lemec\_Cinq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lemec_cinq/32/28949_2.png) [@Lemec\_Cinq](https://discuss.elastic.co/u/Lemec_Cinq)\
**Post date:** [March 19, 2018, 2:52am UTC](https://discuss.elastic.co/t/filter-records-that-contain-a-specfic-field-name/124476/1 "2018-03-19T02:52:58Z")

</div>

I have a json input with different fields name and I would like to filter the data in order to keep at the end of the chain only the records that have a specific field

For example in the data set below I just want to keep records that have field " `recordid`"

> {  
> "records": [  
> {  
> "fields": {  
> "last\_reported": 1519897717,  
> "lon": 2.275342586850291,  
> "station\_id": 7234,  
> "xy": [  
> 48.8296843301,  
> 2.27534258685  
> ],  
> "lat": 48.8296843300915,  
> "name": "Colonel Pierre Avia",  
> "numbikesavailable": 4,  
> "capacity": 31,  
> "is\_installed": 1,  
> "numdocksavailable": 25,  
> "is\_renting": 1,  
> "is\_returning": 1  
> },  
> "geometry": {  
> "coordinates": [  
> 2.27534258685,  
> 48.8296843301  
> ],  
> "type": "Point"  
> },  
> "recordid": "e9a4f7a8874ba8dd9b3d004640d99759b3683005"  
> },  
> {  
> "fields": {  
> "last\_reported": 1519897717,  
> "lon": 2.275342586850291,  
> "station\_id": 7234,  
> "xy": [  
> 48.8296843301,  
> 2.27534258685  
> ],  
> "lat": 48.8296843300915,  
> "name": "Colonel Pierre Avia",  
> "numbikesavailable": 4,  
> "capacity": 31,  
> "is\_installed": 1,  
> "numdocksavailable": 25,  
> "is\_renting": 1,  
> "is\_returning": 1  
> },  
> "geometry": {  
> "coordinates": [  
> 2.27534258685,  
> 48.8296843301  
> ],  
> "type": "Point"  
> },  
> "recordid": "u9h4f5a0874ba8dd9b3d004874d99759b3689740"  
> },  
> {  
> "fields": {  
> "last\_reported": 1519897923,  
> "station\_id": 54000632,  
> "is\_installed": 0,  
> "numbikesavailable": 26,  
> "numdocksavailable": 10,  
> "is\_renting": 0,  
> "is\_returning": 0  
> }  
> },  
> {  
> "fields": {  
> "last\_reported": 1519897923,  
> "station\_id": 54000632,  
> "is\_installed": 0,  
> "numbikesavailable": 26,  
> "numdocksavailable": 10,  
> "is\_renting": 0,  
> "is\_returning": 0  
> }  
> },  
> {  
> "fields": {  
> "last\_reported": 1519897923,  
> "station\_id": 54000632,  
> "is\_installed": 0,  
> "numbikesavailable": 26,  
> "numdocksavailable": 10,  
> "is\_renting": 0,  
> "is\_returning": 0  
> }  
> }  
> ]  
> }

I did not find how to do this with prune filter plugin,  
Do you have idea how to do this and could you help me to solve my problem please?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 19, 2018, 3:56am UTC](https://discuss.elastic.co/t/filter-records-that-contain-a-specfic-field-name/124476/2 "2018-03-19T03:56:42Z")

</div>

I think you could use IF with the drop filter....kinda hacky but I think it should work. The below basically looks for the existence of the Name field, if it doesn't exist it drops the event.

```
if [Name] {
  } else { 
  drop { }
}
```

---

<div class="post-metadata">

**Author:** ![Lemec\_Cinq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lemec_cinq/32/28949_2.png) [@Lemec\_Cinq](https://discuss.elastic.co/u/Lemec_Cinq)\
**Post date:** [March 19, 2018, 2:17pm UTC](https://discuss.elastic.co/t/filter-records-that-contain-a-specfic-field-name/124476/3 "2018-03-19T14:17:30Z")

</div>

thank you for answere , it should work with simple json data but I have an array with nested fields

the filter bellow let pass all data :

> ```
> filter {
> if [records] {
> }
> else { 
> drop { }
> }
> }
> 
> ```

but code bellow won't let pass any record through

```
> 
> filter {
> if [fields] in [records] //or if [records.fields] or if [fields]
> {
> }
> else { 
> drop { }
> }
> }

```

Could you help me to understand how to do this type of filter

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 19, 2018, 3:00pm UTC](https://discuss.elastic.co/t/filter-records-that-contain-a-specfic-field-name/124476/4 "2018-03-19T15:00:52Z")

</div>

Here's [the documentation](https://www.elastic.co/guide/en/logstash/6.2/event-dependent-configuration.html) for using IF in Logstash, but going off your example, I don't believe you can specify multiple fields, though I've never tried. Also, if you are looking for the existence of a particular value in a field, I have had more success with the below than the example in the documentation.

```
filter {
  if "John" in [Name] {
  } else {
    drop { }
  }
}

```

I've seen other filters and outputs use a pipe to separate multiple conditions, though I don't know if that would work. If you want to try, I think it would be something like:

```
filter {
  if ([Name] | [DOB]) {
  } else {
    drop { }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Lemec\_Cinq](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lemec_cinq/32/28949_2.png) [@Lemec\_Cinq](https://discuss.elastic.co/u/Lemec_Cinq)\
**Post date:** [March 19, 2018, 3:06pm UTC](https://discuss.elastic.co/t/filter-records-that-contain-a-specfic-field-name/124476/5 "2018-03-19T15:06:18Z")

</div>

thank you, I will ask a more specific question to know if I can solve my specifc issue

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2018, 3:06pm UTC](https://discuss.elastic.co/t/filter-records-that-contain-a-specfic-field-name/124476/6 "2018-04-16T15:06:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
