# Logstash aggregating through different events

**URL:** <https://discuss.elastic.co/t/logstash-aggregating-through-different-events/305492>\
**Category:** Logstash\
**Created:** [May 24, 2022, 11:22am UTC](https://discuss.elastic.co/t/logstash-aggregating-through-different-events/305492 "2022-05-24T11:22:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![alyafeai](https://avatars.discourse-cdn.com/v4/letter/a/dc4da7/32.png) [@alyafeai](https://discuss.elastic.co/u/alyafeai)\
**Post date:** [May 24, 2022, 11:22am UTC](https://discuss.elastic.co/t/logstash-aggregating-through-different-events/305492/1 "2022-05-24T11:22:42Z")

</div>

Hello,

I have a question regarding aggregating with logstash  
my usecase is that I a csv file with specific attrbuites but some of the attrbuites come empty  
then I receive another file that contain these missing attrbuite  
so my question is how can I approach this + if I don't have a unique field what can I do

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 25, 2022, 8:06pm UTC](https://discuss.elastic.co/t/logstash-aggregating-through-different-events/305492/2 "2022-05-25T20:06:51Z")

</div>

Missing or empty field you can fill with null or "" or delete, it's up to you. I would make decision to unify for all field base on file content, what is important for the visualization or search. With few IFs you can handle several cases:

```auto
if ![fieldA] { #if no exist, add field without value
mutate { add_field => { "fieldA" => "" } }
}
if ![fieldA] { #if no exist, add field with null 
ruby { code => "event['fieldA'] = nil" }
}
if [fieldA]=="" { #if is empty, set fieldA to null 
ruby { code => "event['fieldA'] = nil" }
}

```

If unique value doesn't exist, use fingerprint plugin with method MD5 or UUID on the message. You can use 1 or more fields to make an unique field with value for document\_id =\> "%{fingerprintuuid}".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2022, 8:07pm UTC](https://discuss.elastic.co/t/logstash-aggregating-through-different-events/305492/3 "2022-06-22T20:07:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
