# How to remove/drop entire logs after checking a condition in nested json fields

**URL:** <https://discuss.elastic.co/t/how-to-remove-drop-entire-logs-after-checking-a-condition-in-nested-json-fields/309322>\
**Category:** Logstash\
**Created:** [July 11, 2022, 1:04pm UTC](https://discuss.elastic.co/t/how-to-remove-drop-entire-logs-after-checking-a-condition-in-nested-json-fields/309322 "2022-07-11T13:04:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anusha\_Kusanghi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anusha_kusanghi/32/98109_2.png) [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Post date:** [July 11, 2022, 1:04pm UTC](https://discuss.elastic.co/t/how-to-remove-drop-entire-logs-after-checking-a-condition-in-nested-json-fields/309322/1 "2022-07-11T13:04:55Z")

</div>

Hie ,

Im trying to check a condition for nested json fields and if the condition is met I want to drop the entire data , but it is not working

Source:

"Data" =\> [  
[0] {  
"Scales" =\> [  
[0] {  
"TaskInfos" =\> [  
[0] {  
"Text1" =\> "",  
"Text2" =\> ""  
}  
],  
"HasErrorState" =\> true  
}  
]  
}  
]

Logstash script:  
filter{  
if [type] == "digital"  
{  
if [Data][Scales][HasErrorState] == "true"  
{  
mutate {  
remove\_field =\> ["Data"]  
}

}  
}  
}

Can you please help me with the solution

TIA  
Anusha

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 11, 2022, 2:07pm UTC](https://discuss.elastic.co/t/how-to-remove-drop-entire-logs-after-checking-a-condition-in-nested-json-fields/309322/2 "2022-07-11T14:07:52Z")

</div>

> [@Anusha\_Kusanghi](#):
>
> if [Data][Scales][HasErrorState] == "true"

The first two fields are arrays. Try [Data][0][Scales][0][HasErrorState]

---

<div class="post-metadata">

**Author:** ![Anusha\_Kusanghi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anusha_kusanghi/32/98109_2.png) [@Anusha\_Kusanghi](https://discuss.elastic.co/u/Anusha_Kusanghi)\
**Post date:** [July 12, 2022, 10:38am UTC](https://discuss.elastic.co/t/how-to-remove-drop-entire-logs-after-checking-a-condition-in-nested-json-fields/309322/3 "2022-07-12T10:38:29Z")

</div>

Yes that in deed works , but how can we do it with more entries than one ? dynamically

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 12, 2022, 1:43pm UTC](https://discuss.elastic.co/t/how-to-remove-drop-entire-logs-after-checking-a-condition-in-nested-json-fields/309322/4 "2022-07-12T13:43:46Z")

</div>

Write a ruby filter that iterates over the arrays.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2022, 1:44pm UTC](https://discuss.elastic.co/t/how-to-remove-drop-entire-logs-after-checking-a-condition-in-nested-json-fields/309322/5 "2022-08-09T13:44:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
