# How can I check if an object is empty?

**URL:** <https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380>\
**Category:** Logstash\
**Created:** [February 24, 2017, 10:00am UTC](https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380 "2017-02-24T10:00:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jean\_Helou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jean_helou/32/917_2.png) [@Jean\_Helou](https://discuss.elastic.co/u/Jean_Helou)\
**Post date:** [February 24, 2017, 10:00am UTC](https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380/1 "2017-02-24T10:00:10Z")

</div>

I manipulate http requests.  
my event structure looks like

```
{
 "http_body":{
   "raw":"..."
  }
}

```

I detect the content type of the requests and when it's application/json, I parse the http\_body as json and endup with

```
{
 "http_body":{
   "json":{...}
  }
}

```

I then move known information from [http\_body][json] to predetermined locations  
The json doesn't always contain only "known information" and I don't want to lose this unknown information but I would like to cleanup the other events

at the moment when all the information is known, i have events which endup with :

```
{
 "http_body":{
   "json":{}
  }
}

```

and some with

```
{
 "http_body":{}
}

```

when the json or http\_body fields are "empty" I would like to be able to remove them but I cant figure out how to detect it without resorting to a ruby filter.

`if ![http_body][json]` is false since the field _is_ defined but is empty.  
`if ![http_body][json] or [http_body][json] == {}` fails with `The given configuration is invalid. Reason: Expected one of #, ", ', -, [, / at line`  
`if ![http_body][json] or ([http_body][json] == {})` fails with `The given configuration is invalid. Reason: Expected one of #, ", ', -, [, / at line`

the only way I found for now is

```
if ![http_body][json]{
    mutate {
      remove_field => [
        "[http_body][json]"
      ]
    }
  }else{
    ruby{
      code =>'if(event.get("[http_body][json]").empty?) then
                event.remove("[http_body][json]")
              end'
    }
  }

```

which feels quite awkward .... what have I missed ?

thanks.

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [February 24, 2017, 11:01am UTC](https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380/2 "2017-02-24T11:01:04Z")

</div>

Hi Jean\_Helou,

what is if you try to add a tag if the filter failed?

```
        grok {
            match => ["message", "HTTP Filter"]
            tag_on_failure => ["_no_http"]
        }

        grok {
            match => ["message", "JSON Filter"]
            tag_on_failure => ["_no_json"]
        }

```

then use the tag\_on\_failure to remove it.

```
filter {
  if "_no_http" in [tags] {
    drop { }
  }
}

filter {
  if "_no_json" in [tags] {
    drop { }
  }
}

```

for more information, take a look [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-drop.html)

---

<div class="post-metadata">

**Author:** ![Jean\_Helou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jean_helou/32/917_2.png) [@Jean\_Helou](https://discuss.elastic.co/u/Jean_Helou)\
**Post date:** [February 24, 2017, 11:26am UTC](https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380/3 "2017-02-24T11:26:58Z")

</div>

My explanation wasn't clear : the json parsing and groking does work just fine.

Imagine I have the following events, which both parsed just fine

```
{
 "http_body":{
   "json":{
    "knownKey":"value",
    "unknownKey":"value"
   }
  }
}
{
 "http_body":{
   "json":{
    "knownKey":"value",
   }
  }
}

```

now I extract the information i am interested in with for further processing and specific indexing

```
mutate {
  rename => {["http_body"]["json"]["knownKey"] => "_knownKey"}
}

```

I am left with

```
{
 "_knownKey":"value",
 "http_body":{
   "json":{
    "unknownKey":"value"
   }
  }
}
{
 "_knownKey":"value",
 "http_body":{
   "json":{}
  }
}

```

I want to keep the `"unknownKey":"value"` in case we can identify a pattern later on and reprocess it, but in the second event I was able to process all of the http\_body so I would like to clean up.

the processing is applied to many different payloads which share some common elements and many different elements. I don't really know in advance which payloads will have unknownKeys and which won't...(otherwise it wouldn't be an unknown key 🙂 )

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [February 24, 2017, 12:02pm UTC](https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380/4 "2017-02-24T12:02:21Z")

</div>

ah ok, sorry ☹

did you try something like that -\>

> IF !([http\_body][json] =~ /.+/).

link for more information [here](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals)

---

<div class="post-metadata">

**Author:** ![Jean\_Helou](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jean_helou/32/917_2.png) [@Jean\_Helou](https://discuss.elastic.co/u/Jean_Helou)\
**Post date:** [February 24, 2017, 4:24pm UTC](https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380/5 "2017-02-24T16:24:19Z")

</div>

Thanks for the suggestion, I ended up using

`if ![http_body][json] or !([http_body][json] =~ ".+")`

which worked.

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [February 24, 2017, 4:25pm UTC](https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380/6 "2017-02-24T16:25:14Z")

</div>

Hi Jean\_Helou,

nice to hear that its working now for you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2017, 4:25pm UTC](https://discuss.elastic.co/t/how-can-i-check-if-an-object-is-empty/76380/7 "2017-03-24T16:25:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
