# How to check if a field has any subfields

**URL:** <https://discuss.elastic.co/t/how-to-check-if-a-field-has-any-subfields/294482>\
**Category:** Logstash\
**Created:** [January 15, 2022, 2:53pm UTC](https://discuss.elastic.co/t/how-to-check-if-a-field-has-any-subfields/294482 "2022-01-15T14:53:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dantamsdb](https://avatars.discourse-cdn.com/v4/letter/d/e19adc/32.png) [@dantamsdb](https://discuss.elastic.co/u/dantamsdb)\
**Post date:** [January 15, 2022, 2:53pm UTC](https://discuss.elastic.co/t/how-to-check-if-a-field-has-any-subfields/294482/1 "2022-01-15T14:53:47Z")

</div>

I get input that sometimes looks like this:

```auto
{
  "baz": {
    "foo": "bar",
    "data": {}
  }
}

```

sometimes it looks like this:

```auto
{
  "baz": {
    "foo": "bar",
    "data": {
      "fizz": "buzz",
      "fizzy": "buzzy"
    }
  }
}

```

and sometimes it looks like this:

```auto
{
  "baz": {
    "foo": "bar",
    "data": {
      "fuzz": "bizz",
      "fuzzy": "bizzy"
    }
  }
}

```

I do not know the keys that could be contained in the _baz.data_ object in beforehand.

If, and only if, the _baz.data_ object contains actual content, I want to redact the original data by replacing it with the pre-prepared static object { "notice": "this data has been redacted" }, so that I end up with the following:

```auto
{
  "baz": {
    "foo": "bar",
    "data": {
      "notice": "this data has been redacted"
    }
  }
}

```

Now I figured out how to replace the content of the _baz.data_ object. The only part I haven't figured out is how to check if the _baz.data_ object is empty or not.

Currently my code looks like this:

```auto
mutate {
  add_field => { "[@metadata][redacted]" => '{ "notice": "this data has been redacted" }' }
}

if [baz][data] =~ /.+/ {
  json {
    source => "[@metadata][redacted]"
    target => "[baz][data]"
  }
}

```

The problem is that the above code will never replace the object. I am guessing it's because the _[baz][data]_ field itself is empty, even though it contains subfields.

I previously tried the following conditional:

```auto
if [baz][data] {

```

However the above code will always insert the object, apparently because the _[baz][data]_ field exists, despite not having any sub-fields.

I also tried the following:

```auto
if [baz][data] and [baz][data] != "" {

```

The above conditions always end up true, I guess because an empty object does not equal an empty string.

So how do I properly check if _[baz][data]_ has any nested subfields, when I do not know the names of the subfields?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 15, 2022, 5:03pm UTC](https://discuss.elastic.co/t/how-to-check-if-a-field-has-any-subfields/294482/2 "2022-01-15T17:03:08Z")

</div>

Personally I would use ruby

```
input { generator { count => 1 lines => ['{}', '{ "data": "" }', '{ "data": { "foo": "bar" } }', '{ "data": { } }'] codec => json } }
filter {
    ruby {
        code => '
            d = event.get("data")
            if d and d.is_a? Hash and !d.empty?
                event.set("data", { "notice" => "this data has been redacted" })
            end
        '
    }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

produces events with

```
      "data" => "",
      "data" => {
    "notice" => "this data has been redacted"
},
      "data" => {},

```

You can do the same without using ruby, but I think it is more obscure

```
    if [data] {
        mutate { add_field => { "[@metadata][JSON]" => "{}" } }
        json { source => "[@metadata][JSON]" target => "[@metadata][emptyHash]" }
        if [data] != [@metadata][emptyHash] {
            mutate { remove_field => ["data"] }
            mutate { add_field => { "[@metadata][otherJSON]" => '{ "notice": "this data has been redacted" }' } }
            json { source => "[@metadata][otherJSON]" target => "[data]" }
        }
    }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2022, 5:03pm UTC](https://discuss.elastic.co/t/how-to-check-if-a-field-has-any-subfields/294482/3 "2022-02-12T17:03:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
