# Logstash nested conditional statement one with null check

**URL:** <https://discuss.elastic.co/t/logstash-nested-conditional-statement-one-with-null-check/77946>\
**Category:** Logstash\
**Created:** [March 9, 2017, 8:27am UTC](https://discuss.elastic.co/t/logstash-nested-conditional-statement-one-with-null-check/77946 "2017-03-09T08:27:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kiranilla](https://avatars.discourse-cdn.com/v4/letter/k/8e7dd6/32.png) [@kiranilla](https://discuss.elastic.co/u/kiranilla)\
**Post date:** [March 9, 2017, 8:27am UTC](https://discuss.elastic.co/t/logstash-nested-conditional-statement-one-with-null-check/77946/1 "2017-03-09T08:27:22Z")

</div>

As i am trying to write a script that as to populate the "Category" based on "Knowledge Title" contains some text called "AGSS", but here the condition is that i need to check the "Category" is null then only i have to proceed for other condition.  
Please find the code snippet:

if [Category] { /\* need to check the "Category is null \*/

```
	if "AGSS" in [Knowledge Title] {

		mutate {
			update => { "Category" => "SOFTWARE_MOD" }
		}
	}
}

```

`In the above code is not able to check for null for "Category" field`  
I tried even the following one for null check:

if [Category] == nil  
if [Category] == null  
if [Category] != nil  
if [Category] == "null"  
if [Category] == "nil"

but none of them are working,

`Can you please help me out how to check for a null` for a particular field.  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2017, 2:24pm UTC](https://discuss.elastic.co/t/logstash-nested-conditional-statement-one-with-null-check/77946/2 "2017-03-09T14:24:28Z")

</div>

How does null end up in the `Category` field?

You'll have to use a ruby filter to this kind of check. Logstash's own configuration language has no notion of "null".

---

<div class="post-metadata">

**Author:** ![kiranilla](https://avatars.discourse-cdn.com/v4/letter/k/8e7dd6/32.png) [@kiranilla](https://discuss.elastic.co/u/kiranilla)\
**Post date:** [March 13, 2017, 11:54am UTC](https://discuss.elastic.co/t/logstash-nested-conditional-statement-one-with-null-check/77946/3 "2017-03-13T11:54:03Z")

</div>

Thanks Magnus.. for your help..

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 13, 2017, 12:39pm UTC](https://discuss.elastic.co/t/logstash-nested-conditional-statement-one-with-null-check/77946/4 "2017-03-13T12:39:04Z")

</div>

I have used the following method with success...

```
if [Category] !~ /.+/ { }

```

You may want to give it a try.

> NOTE:  
> I have found this works ONLY with fields that are logstash strings. If the value is an integer (e.g. using something like...

> `mutate { convert => { "Category" => "integer" } }`

> ... the regex match will not work. Ran into this quirk just this morning.

Rob

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2017, 12:39pm UTC](https://discuss.elastic.co/t/logstash-nested-conditional-statement-one-with-null-check/77946/5 "2017-04-10T12:39:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
