# How to check whether fields exist?How to access the data within it?

**URL:** <https://discuss.elastic.co/t/how-to-check-whether-fields-exist-how-to-access-the-data-within-it/139152>\
**Category:** Kibana\
**Created:** [July 9, 2018, 11:36am UTC](https://discuss.elastic.co/t/how-to-check-whether-fields-exist-how-to-access-the-data-within-it/139152 "2018-07-09T11:36:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JAYESH\_PAUNIKAR](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@JAYESH\_PAUNIKAR](https://discuss.elastic.co/u/JAYESH_PAUNIKAR)\
**Post date:** [July 9, 2018, 11:36am UTC](https://discuss.elastic.co/t/how-to-check-whether-fields-exist-how-to-access-the-data-within-it/139152/1 "2018-07-09T11:36:31Z")

</div>

We have an XML which we have parsed using the XML filter. Sample of the XML is as follows;

\<?xml version="1.0" encoding="UTF-8"?\>

We have parsed the XML using the XML filter in Logstash.  
Following is the config file:

input{  
file {  
path =\> "C:\Users\Programs\ELK\logstash-6.2.3\logstash-6.2.3\xml data\results.xml"  
start\_position=\>"beginning"  
sincedb\_path =\>"/dev/null"  
codec =\> multiline {  
pattern =\> "^\<?xml .\*?\>"  
negate =\> "true"  
what =\> "previous"  
auto\_flush\_interval =\> 1  
}

```
}

```

}  
filter{  
xml{  
source =\> "message"  
target =\> "xml\_parsed"  
}  
}  
output{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "proto"   
}  
stdout{}  
}

We wanted to find the name of the test case which has failed ( here test case having name G)  
the test case having system-out passes and the test case having failure message fails. So we tried writing a script in painless but it does not work. Following is the script:

String scenario = "NA";  
for(int i = 0; i \< xml\_parsed.testcase.length; i++){  
if(xml\_parsed.testcase[i].system-out == NULL)  
return xml\_parsed.testcase[i].name;  
}  
return scenario;

We tried doc['xml\_parsed.testcase.keyword'] but xml\_parsed.testcase.keyword does not exist i guess as it is not shown in the fields when the index pattern is created. In discover xml\_parsed.testcase appears as follows;

{  
"system-out": [  
"S1.....................................passed\nS2..........................................................passed\nS3..........................................................passed"  
],  
"classname":"E",  
"name": "F",  
"time": "39.773916"  
},  
{  
"failure": [  
{  
"message": "F1"  
}  
],  
"classname": "E",  
"name": "G",  
"time": "37.785234"  
}

So how to access the fields within an index in the array for example "name" in xml\_parsed.testcase[0]?

---

<div class="post-metadata">

**Author:** ![christophilus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christophilus/32/42991_2.png) [@christophilus](https://discuss.elastic.co/u/christophilus)\
**Post date:** [July 9, 2018, 3:05pm UTC](https://discuss.elastic.co/t/how-to-check-whether-fields-exist-how-to-access-the-data-within-it/139152/2 "2018-07-09T15:05:52Z")

</div>

Hi Jayesh, It's hard to say, since the code you pasted got garbled. But if you're trying to ask: "How many documents have a testcase with name 'G'?" You can do this without needing array index access.

In Kibana's Dev Tools, you can do something like this:

```auto
GET .baz/_search
{
  "query": {
    "term": {
      "xml_parsed.testcase.name.keyword": "G"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![JAYESH\_PAUNIKAR](https://avatars.discourse-cdn.com/v4/letter/j/b3f665/32.png) [@JAYESH\_PAUNIKAR](https://discuss.elastic.co/u/JAYESH_PAUNIKAR)\
**Post date:** [July 11, 2018, 4:33am UTC](https://discuss.elastic.co/t/how-to-check-whether-fields-exist-how-to-access-the-data-within-it/139152/3 "2018-07-11T04:33:23Z")

</div>

We have an XML which we have parsed using the XML filter. Sample of the XML is as follows;

\<!?xml version="1.0" encoding="UTF-8"?\>  
\<!testsuite failures="1" name="ABCD" skipped="0" tests="2" time="115.196272"\>  
\<!testcase classname="E" name="F" time="39.773916"\>  
\<!system-out\>\<!/system-out\>  
\<!/testcase\>  
\<!testcase classname="E" name="G" time="37.785234"\>  
\<!failure message="F1"\>\<!/failure\>  
\<!/testcase\>  
\<!/testsuite\>"

Following is the config file:

input{  
file {  
path =\> "C:\Users\Programs\ELK\logstash-6.2.3\logstash-6.2.3\xml data\results.xml"  
start\_position=\>"beginning"  
sincedb\_path =\>"/dev/null"  
codec =\> multiline {  
pattern =\> "^\<?xml .\*?\>"  
negate =\> "true"  
what =\> "previous"  
auto\_flush\_interval =\> 1  
}  
}  
}  
filter{  
xml{  
source =\> "message"  
target =\> "xml\_parsed"  
}  
}  
output{  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "proto"   
}  
stdout{}  
}

We wanted to find the name of the test case which has failed ( here test case having name G).  
The test case having \<!system-out\> passes and the test case having \<!failure\> message fails. So we tried writing a script in painless but it does not work. Following is the script:

String scenario = "NA";  
for(int i = 0; i \< xml\_parsed.testcase.length; i++){  
if(xml\_parsed.testcase[i].system-out == NULL)  
return xml\_parsed.testcase[i].name;  
}  
return scenario;

We tried doc['xml\_parsed.testcase.keyword'] but xml\_parsed.testcase.keyword does not exist i guess as it is not shown in the fields when the index pattern is created. In discover xml\_parsed.testcase appears as follows;

{  
"system-out": [  
"S1.....................................passed\nS2..........................................................passed\nS3..........................................................passed"  
],  
"classname":"E",  
"name": "F",  
"time": "39.773916"  
},  
{  
"failure": [  
{  
"message": "F1"  
}  
],  
"classname": "E",  
"name": "G",  
"time": "37.785234"  
}

So how to access the fields within an index in the array for example "name" in xml\_parsed.testcase[0]?  
We want the name of the testcase which has failure field .here it is G but it can vary. So can you tell us how to do that in painless because we want to create a field and use that field to visualize.Have added ! inside the tags just to make it visible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2018, 4:33am UTC](https://discuss.elastic.co/t/how-to-check-whether-fields-exist-how-to-access-the-data-within-it/139152/4 "2018-08-08T04:33:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
