# Logstash - Checking if a value or field exist in an array within an object

**URL:** <https://discuss.elastic.co/t/logstash-checking-if-a-value-or-field-exist-in-an-array-within-an-object/192294>\
**Category:** Logstash\
**Created:** [July 25, 2019, 5:46pm UTC](https://discuss.elastic.co/t/logstash-checking-if-a-value-or-field-exist-in-an-array-within-an-object/192294 "2019-07-25T17:46:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [July 25, 2019, 5:46pm UTC](https://discuss.elastic.co/t/logstash-checking-if-a-value-or-field-exist-in-an-array-within-an-object/192294/1 "2019-07-25T17:46:42Z")

</div>

I am trying to check if a field exists within a pair in an array inside of a larger object. I've tried to just add the field as is to make sure i was using the proper syntax and it works. I've done

> mutate {  
> add\_field =\> ["fieldname","%{[objectName][arrayName][#][fieldName]}"]  
> }

This creates the new field while adding the proper field. However, when I attempt to check the if the field exists I either get nothing or I get an error about the syntax.

> if ! [%{[objectName][arrayName][#][fieldName]}] {  
> add\_field =\> ["fieldname","%{[objectName][arrayName][#][fieldName]}"]  
> }  
> else {  
> add\_field =\> ["fieldname",""]  
> }

For the if ! I've also changed the field to:

- %{[objectName][arrayName][#][fieldName]} : Gives syntax error
- "%{[objectName][arrayName][#][fieldName]}" : Gives syntax error
- [objectName][arrayName][#][fieldName] : gives nothing when there is and at others returns [objectName][arrayName][#][fieldName]

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [August 5, 2019, 3:16pm UTC](https://discuss.elastic.co/t/logstash-checking-if-a-value-or-field-exist-in-an-array-within-an-object/192294/2 "2019-08-05T15:16:51Z")

</div>

Got it to pull the appropriate value from the field, however, when it pulls the value even though the value doesnt exist it puts the literal name as the field value.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 5, 2019, 3:19pm UTC](https://discuss.elastic.co/t/logstash-checking-if-a-value-or-field-exist-in-an-array-within-an-object/192294/3 "2019-08-05T15:19:47Z")

</div>

That is expected. If field [foo] does not exist then

```
mutate { add_field => { "someField" => "%{foo}" } }

```

will set [someField] to "%{foo}".

---

<div class="post-metadata">

**Author:** ![edster](https://avatars.discourse-cdn.com/v4/letter/e/da6949/32.png) [@edster](https://discuss.elastic.co/u/edster)\
**Post date:** [August 5, 2019, 3:25pm UTC](https://discuss.elastic.co/t/logstash-checking-if-a-value-or-field-exist-in-an-array-within-an-object/192294/4 "2019-08-05T15:25:53Z")

</div>

Is there anyway to set it to "" if there is no value. I added an else to that statement but it didn't seem to do anything just replaced it with "%{foo}"

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 5, 2019, 4:09pm UTC](https://discuss.elastic.co/t/logstash-checking-if-a-value-or-field-exist-in-an-array-within-an-object/192294/5 "2019-08-05T16:09:37Z")

</div>

There is no elegant solution. There is an [issue](https://github.com/elastic/logstash/issues/4416) on github that talks about changing the syntax to enable defaults, but no traction on it in the last few years.

You could use

```
mutate { gsub => ["someField", "^%{.*}$", ""] }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2019, 4:21pm UTC](https://discuss.elastic.co/t/logstash-checking-if-a-value-or-field-exist-in-an-array-within-an-object/192294/6 "2019-09-02T16:21:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
