# Find Out empty field

**URL:** <https://discuss.elastic.co/t/find-out-empty-field/280576>\
**Category:** Logstash\
**Created:** [August 5, 2021, 6:08pm UTC](https://discuss.elastic.co/t/find-out-empty-field/280576 "2021-08-05T18:08:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![YASH\_SHARMA7766](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yash_sharma7766/32/91989_2.png) [@YASH\_SHARMA7766](https://discuss.elastic.co/u/YASH_SHARMA7766)\
**Post date:** [August 5, 2021, 6:08pm UTC](https://discuss.elastic.co/t/find-out-empty-field/280576/1 "2021-08-05T18:08:00Z")

</div>

I have a data set of 4-5 fields.I want to check if any data field is empty , Iogstash add a field name incomplete data and add value of field name in that.Sample data and code is attached below.

![image](https://us1.discourse-cdn.com/elastic/original/3X/6/6/667acd8f75e8c6da19c55eee6228252c3c35a246.png)

As shown in image,service column has some empty data fields.

Code I am using for this is as follows :

```auto

input

{

    file

    {

        path=> "C:/elastic_stack/HPAM/incomplete data/ipdata1.csv"

        start_position => "beginning"

        sincedb_path => "NULL"

    }

}

filter

{

    csv

    {

        separator => ","

        columns => ["IP","Host","Service","Status"]

    }

    

# if [Service] == " " 

# {

# mutate

# {

# add_field => { "data_incomplete" => "service" }

# }

# }

}

output {

    elasticsearch{

        hosts => "http://localhost:9200/"

        index => "empty"

    }

    stdout{}

} 

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 5, 2021, 6:32pm UTC](https://discuss.elastic.co/t/find-out-empty-field/280576/2 "2021-08-05T18:32:01Z")

</div>

> [@YASH\_SHARMA7766](#):
>
> `sincedb_path => "NULL"`

That should be "NUL", not "NULL". If you use "NULL" then the in-memory sincedb will be persisted to a file called NULL in whatever the working directory of logstash is.

To test for an empty field you can use

```
if ! [service] {

```

---

<div class="post-metadata">

**Author:** ![YASH\_SHARMA7766](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yash_sharma7766/32/91989_2.png) [@YASH\_SHARMA7766](https://discuss.elastic.co/u/YASH_SHARMA7766)\
**Post date:** [August 5, 2021, 7:09pm UTC](https://discuss.elastic.co/t/find-out-empty-field/280576/3 "2021-08-05T19:09:09Z")

</div>

@Badger Thank You for your valuable help and time.It works perfectly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2021, 7:09pm UTC](https://discuss.elastic.co/t/find-out-empty-field/280576/4 "2021-09-02T19:09:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
