# Grok filter: check if field exists

**URL:** <https://discuss.elastic.co/t/grok-filter-check-if-field-exists/132103>\
**Category:** Logstash\
**Created:** [May 16, 2018, 11:19am UTC](https://discuss.elastic.co/t/grok-filter-check-if-field-exists/132103 "2018-05-16T11:19:55Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alessio\_Frabotta](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Alessio\_Frabotta](https://discuss.elastic.co/u/Alessio_Frabotta)\
**Post date:** [May 16, 2018, 11:19am UTC](https://discuss.elastic.co/t/grok-filter-check-if-field-exists/132103/1 "2018-05-16T11:19:55Z")

</div>

I have a log message with this structure:

```
"message" => "{    
    "@timestamp":"201856T12:54:33.347+02:00",
    "thread":"main",
    "logger_name":"org.elasticsearch.bootstrap",
    "level":"WARN",
    "message":"JNA not found. native methods will be disabled.",
    "stack_trace": "java.lang.ClassNotFoundException: ... 
}

```

As you can see, inside the message there is a stack\_trace field, but the control

```
if [message][stack_trace] {
	mutate { add_tag => ["EXCEPTION"] }
}

```

doesn't work

How can I check if "message" contains the "stack\_trace" field?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2018, 2:29pm UTC](https://discuss.elastic.co/t/grok-filter-check-if-field-exists/132103/2 "2018-05-16T14:29:02Z")

</div>

Did you parse message with a json filter or codec?

---

<div class="post-metadata">

**Author:** ![Alessio\_Frabotta](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Alessio\_Frabotta](https://discuss.elastic.co/u/Alessio_Frabotta)\
**Post date:** [May 16, 2018, 2:57pm UTC](https://discuss.elastic.co/t/grok-filter-check-if-field-exists/132103/3 "2018-05-16T14:57:24Z")

</div>

the message is generated via logstash-logback-encoder, as follow:

```
<appender name="STASH" class="net.logstash.logback.appender.LogstashTcpSocketAppender">
        <destination>localhost:5000</destination>

	<encoder class="net.logstash.logback.encoder.LoggingEventCompositeJsonEncoder">
		<providers>
			<timestamp>
				<timeZone>Europe/Berlin</timeZone>
			</timestamp>
			<callerData>
				<classFieldName>classname</classFieldName>
				<methodFieldName>method</methodFieldName>
				<fileFieldName>file</fileFieldName>
				<lineFieldName>line</lineFieldName>
			</callerData>
			<threadName>
				<fieldName>thread</fieldName>
			</threadName>
			<loggerName />
			<logLevel />
			<message />
			<stackTrace />
		</providers>
	</encoder>

```

This is the content of logstash input pipeline:

```
input {
	tcp {
    	port => 5000
    }
}

filter {
	 .....
}

output {
         .....
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2018, 3:28pm UTC](https://discuss.elastic.co/t/grok-filter-check-if-field-exists/132103/4 "2018-05-16T15:28:05Z")

</div>

> [@Alessio\_Frabotta](#):
>
> if [message][stack\_trace] {

This is the correct syntax, although if I parse that input with an xml filter the field would end up being called [message][providers][stackTrace] (or [message][providers][0][stackTrace][0] without force\_array =\> false).

---

<div class="post-metadata">

**Author:** ![Alessio\_Frabotta](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@Alessio\_Frabotta](https://discuss.elastic.co/u/Alessio_Frabotta)\
**Post date:** [May 28, 2018, 2:08pm UTC](https://discuss.elastic.co/t/grok-filter-check-if-field-exists/132103/5 "2018-05-28T14:08:29Z")

</div>

@Badger

> [@Badger](#):
>
> Did you parse message with a json filter or codec?

I added

```
json {
	source => "message"
}

```

and now the instruction

`if [message][stack_trace] { }`

works !

Sorry, but slowly I'm trying to understand logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2018, 2:08pm UTC](https://discuss.elastic.co/t/grok-filter-check-if-field-exists/132103/6 "2018-06-25T14:08:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
