# Logstash does not see a field

**URL:** <https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570>\
**Category:** Logstash\
**Created:** [April 28, 2025, 10:05am UTC](https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570 "2025-04-28T10:05:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rnx](https://avatars.discourse-cdn.com/v4/letter/r/6de8d8/32.png) [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Post date:** [April 28, 2025, 10:05am UTC](https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570/1 "2025-04-28T10:05:00Z")

</div>

I can't reprocess any field in Logstash which is ingested from Jdbc. All Fields are properly inserted into Elastic, they have proper name and data, however I can't transform them anyhow. Here is the configuration:

```auto
input {
      jdbc {
            jdbc_driver_library => "/usr/share/logstash/config/mssql-jdbc-12.10.0.jre11.jar"
            jdbc_driver_class => "com.microsoft.sqlserver.jdbc.SQLServerDriver"
            jdbc_connection_string => "jdbc:sqlserver:// ******:1433;databaseName=****** ;encrypt=true;trustServerCertificate=true;integratedSecurity=true;user= ******;password=****** ;authenticationScheme=NTLM;domain=xy;authentication=NotSpecified"
            jdbc_user => ' *****'
            jdbc_password => ' ******'
          statement => "select top 1000 x, z, y, Created, code, w, status, z, f, d, a, b from ******* where Created > :sql_last_value ORDER by Created ASC"
          tracking_column => created
          tracking_column_type => "timestamp"
          use_column_value => true
          schedule => "*/15 * * * * *"
          last_run_metadata_path => "/usr/share/logstash/data/logstash_jdbc_ms_last_run"
      }
    }
filter {
        if [status] == "60000" {
          mutate {
            add_field => { "wa_status_word" => "OK" }
          }
        } else if [status] == "60001" {
          mutate {
            add_field => { "wa_status_word" => "Nový" }
          }
        } else if [status] == "60002" {
          mutate {
            add_field => { "wa_status_word" => "Probíhá" }
          }
        } else if [status] == "60003" {
          mutate {
            add_field => { "wa_status_word" => "Hotovo" }
          }
        } else if [status] == "60004" {
          mutate {
            add_field => { "wa_status_word" => "Chyba" }
          }
        } else if [wastatus] == "60005" {
          mutate {
            add_field => { "wa_status_word" => "Upozornění" }
          }
        } 
        if "0" == [code] {
          mutate {
            add_field => { "code_word" => "aktivní" }
          }
        } else if "1" == [code] {
          mutate {
            add_field => { "code_word" => "neaktivní" }
          }
        }
    }
    output {
      stdout { codec => rubydebug }
      elasticsearch {
         xyz...
      }
     }

```

and sample data in elastic:

```auto
{
  "_index": "index-2025",
  "_id": " ****** MILHAqJKaal",
  "_version": 1,
  "_score": 0,
  "_source": {
    "b": null,
    "a": 0,
    "c": "somedata",
    "status": 60003,
    "appname": "db-crm",
    "x": 0,
    "y": "somedata",
    "created": "2025-04-26T09:27:06.000Z",
    "@timestamp": "2025-04-26T09:27:16.017386975Z",
    "@version": "1",
    "code": 0,
    "z": "somedata",
    "d": "somedata",
    "e": null,
    "f": 0
  },
  "fields": {
    "a": [
      0
    ],
    "y": [
      "somedata"
    ],
    "x.keyword": [
      "somedata"
    ],
    "@version.keyword": [
      "1"
    ],
    "appname.keyword": [
      "appnamexy"
    ],
    "code": [
      0
    ],
    "otherdata.keyword": [
      "data"
    ],
    "x": [
      0
    ],
    "created": [
      "2025-04-26T09:27:06.000Z"
    ],
    "e": [
      "somedata"
    ],
    "f": [
      0
    ],
    "w.keyword": [
      "data"
    ],
    "y.keyword": [
      "data"
    ],
    "@timestamp": [
      "2025-04-26T09:27:16.017Z"
    ],
    "appname": [
      "appnamexy"
    ],
    "@version": [
      "1"
    ],
    "status": [
      60003
    ],
    "d": [
      "data"
    ],
    "i": [
      "data"
    ]
  }
}

```

Please don't be confused from fields inconsistency compared to select and fields in elastic, I had to remove names and data by hand, important are only fields "status" and "appname".  
The problem is, the Logstash does not see the field "status" which is somehow ignored therefore the new field "wa\_status\_word" is not created. Filter is ok as it has no error in logs, and it creates field "appname" according to given condition. Any ideas what is wrong?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 28, 2025, 12:15pm UTC](https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570/2 "2025-04-28T12:15:00Z")

</div>

> [@Rnx](#):
>
> Any ideas what is wrong?

[status] is an integer field in the elasticsearch output and I suspect jdbc is creating it that way. Change all your tests of [status] to be numeric comparisons. Replace

```
    if [status] == "60000" {

```

with

```
    if [status] == 60000 {

```

---

<div class="post-metadata">

**Author:** ![Alex\_Salgado-Elastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_salgado-elastic/32/103081_2.png) [@Alex\_Salgado-Elastic](https://discuss.elastic.co/u/Alex_Salgado-Elastic)\
**Post date:** [April 28, 2025, 12:22pm UTC](https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570/3 "2025-04-28T12:22:06Z")

</div>

Additionally, I noticed a small mistake in one of your conditions: you're checking `[wastatus]` instead of `[status]`. This could also be affecting your results.

---

<div class="post-metadata">

**Author:** ![Rnx](https://avatars.discourse-cdn.com/v4/letter/r/6de8d8/32.png) [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Post date:** [April 28, 2025, 12:28pm UTC](https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570/4 "2025-04-28T12:28:36Z")

</div>

Badger nailed it. JDBC input returns field as an integer type, so nothing else works except putting value outside the quotes. Thanks!

---

<div class="post-metadata">

**Author:** ![Rnx](https://avatars.discourse-cdn.com/v4/letter/r/6de8d8/32.png) [@Rnx](https://discuss.elastic.co/u/Rnx)\
**Post date:** [April 28, 2025, 12:31pm UTC](https://discuss.elastic.co/t/logstash-does-not-see-a-field/377570/5 "2025-04-28T12:31:17Z")

</div>

thanks, this one was just a "typo" while I was making this post. I have it set properly in my setup.
