# How to check length of an array field in logstash

**URL:** <https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625>\
**Category:** Logstash\
**Created:** [March 14, 2023, 5:06am UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625 "2023-03-14T05:06:09Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 14, 2023, 5:06am UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/1 "2023-03-14T05:06:09Z")

</div>

Hey everyone, can you give me some example about pipeline config to check if an array field is not null? and how i combine it with if else?

i already made config like this  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d11feb2083e612e4a0e595c14a75086745439429.png)

and i want to create some if statement under _if [tries]_ to check the length of the tries field. so if tries field like this `"tries" : []` it will bypass those actions. Thanks

fyi, i use v7.17.0

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 14, 2023, 3:03pm UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/2 "2023-03-14T15:03:22Z")

</div>

If you want to check whether an array is empty you can use

```
if [tries] and [tries][0] { ... it is not empty

```

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 15, 2023, 9:57am UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/3 "2023-03-15T09:57:15Z")

</div>

it is equal to `== 0` condition right? if i want to create the reverse like `!= 0` how i made it? will it be like this?

`if [tries] and [tries]![0] `  
or  
`if [tries] and !([tries][0])`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 15, 2023, 3:24pm UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/4 "2023-03-15T15:24:43Z")

</div>

> [@yuswanul](#):
>
> if i want to create the reverse like `!= 0`

I showed you how to check if [tries] is a non-empty array. What do you want to check now? That it is an empty array?

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 15, 2023, 4:58pm UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/5 "2023-03-15T16:58:13Z")

</div>

Yes, there is an empty array on logs. So i want to make a condition to check if the array field is not empty. I already made like this  
 ![IMG-20230315-WA0001](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f6bcb32ed71928d5a52137c2c5d55ec6266c0d82.jpeg)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 15, 2023, 5:38pm UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/6 "2023-03-15T17:38:52Z")

</div>

> [@yuswanul](#):
>
> i want to make a condition to check if the array field is not empty

I showed you how to do that in my first answer.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 15, 2023, 11:18pm UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/7 "2023-03-15T23:18:54Z")

</div>

Can you explain the logic? Because when i see it at the first time, i think its equal to ` == 0` Because there is 0 on condition and there is no `!` or something like that to make it reverse. Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 16, 2023, 12:22am UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/8 "2023-03-16T00:22:24Z")

</div>

> [@yuswanul](#):
>
> Can you explain the logic?

`if [tries]` tests whether the [tries] field exists. If it does not this short-circuits (prevents) the execution of the `and [tries][0]` which would get an exception if the field does not exist. `and [tries][0]` tests if the first entry in the [tries] array exists.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [March 16, 2023, 1:12am UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/9 "2023-03-16T01:12:14Z")

</div>

I just remember that array started at 0 right? Now everything makes sense. Thanks

Pada tanggal Kam, 16 Mar 2023 07.32, Badger via Discuss the Elastic Stack \<[notifications@elastic.discoursemail.com](mailto:notifications@elastic.discoursemail.com)\> menulis:

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2023, 1:12am UTC](https://discuss.elastic.co/t/how-to-check-length-of-an-array-field-in-logstash/327625/10 "2023-04-13T01:12:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
