# Logstash conditional check if filed exist then replace timestamp value with another fileds timestamp

**URL:** <https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311>\
**Category:** Logstash\
**Created:** [January 2, 2023, 1:39pm UTC](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311 "2023-01-02T13:39:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PRASHANT\_MEHTA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prashant_mehta/32/101764_2.png) [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Post date:** [January 2, 2023, 1:39pm UTC](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311/1 "2023-01-02T13:39:20Z")

</div>

Hello All,

I'm stuck in how to implement conditional check in logstash and how would it be implemented correctly.  
Usecase:I have data coming in my index with multiple fields value,I'd like to send data to elastic  
where the **timesatmp field value should be replaced with last\_execution timestamp value** ,this is achieved ,and **should only be done if jobStatus.jobId this field exist**.

How to implement entirely sudo code:  
if(jobid field exist)  
then  
replace timestamp filed value with last\_execution timestamp.

Ruby partial code is done but not sure entirely.

```auto
ruby {
code => "event.set('@timestamp', event.get('last_execution_time'));"
}

```

config:

```auto
input {
   exec {
      command => '. ../scripts/ordermonitor/run_ordermonitor.sh'
      schedule => "0 0 * * * *"
   } 
}

filter {   
  
     ruby {
       code => "event.set('@timestamp', event.get('last_execution_time'));"
    }
  
  }

output {
   elasticsearch {
      hosts => "http://abc.com:9200"
	  ilm_pattern => "{now/d}-000001"
      ilm_rollover_alias => "tix-monitor-order"
	  ilm_policy => "tix-monitor-order-policy"
	  doc_as_upsert => true
	  document_id => "%{[order][recordUniqueId]}"
   } 
}

```

Assuming this would be part of ruby code,if yes then should it be part of filter plugin?  
Below is partial implementation of config file,would like to achieve mentioned above.

Thanx

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 2, 2023, 5:44pm UTC](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311/2 "2023-01-02T17:44:38Z")

</div>

I do not think you need ruby to do that. Assuming that [last\_execution\_time] is already a LogStash::Timestamp object (if not, add a date filter to parse it):

```
if [jobStatus][jobId] {
    mutate { replace => { "@timestamp" => "%{last_execution_time}" } }
}

```

---

<div class="post-metadata">

**Author:** ![PRASHANT\_MEHTA](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prashant_mehta/32/101764_2.png) [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Post date:** [January 3, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311/3 "2023-01-03T12:45:14Z")

</div>

Hello @Badger ,

Thanx for your time to look into this,the below worked fine.

```auto
filter {   
   if [message] =~ "^\{.*\}[\s\S]*$" {
      json {
         source => "message"
         target => "parsed_json"
         remove_field => "message"
      }

      split {
         field => "[parsed_json][OrderMonitorReponse]"
         target => "order"
         remove_field => ["parsed_json"]
      }

        if [order][Job][lastStartTime] {
             mutate {
                convert => { "[order][Job][lastStartTime]" => "string" }
            }
            date {
              match => ["[order][Job][lastStartTime]", "yyyy-MM-dd'T'HH:mm:ssZ"]
              timezone => "UTC"
              target => "@timestamp"
            }
        }
    }

 

   else {
     drop { }
   }

```

Data from logs:  
"lastStartTime":"2022-12-13T07:47:46Z"

Index template field:  
"order.job.lastStartTime": {  
"format": "yyyy-MM-dd'T'HH:mm:ssX",  
"type": "date"  
}

Many Thanx

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2023, 12:45pm UTC](https://discuss.elastic.co/t/logstash-conditional-check-if-filed-exist-then-replace-timestamp-value-with-another-fileds-timestamp/322311/4 "2023-01-31T12:45:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
