# Logstash remove N/A field

**URL:** <https://discuss.elastic.co/t/logstash-remove-n-a-field/314002>\
**Category:** Logstash\
**Created:** [September 8, 2022, 2:20pm UTC](https://discuss.elastic.co/t/logstash-remove-n-a-field/314002 "2022-09-08T14:20:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mleg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mleg/32/110666_2.png) [@mleg](https://discuss.elastic.co/u/mleg)\
**Post date:** [September 8, 2022, 2:20pm UTC](https://discuss.elastic.co/t/logstash-remove-n-a-field/314002/1 "2022-09-08T14:20:41Z")

</div>

I am trying to remove all the fields which have N/A next to the them like "toto: N/A", I am currently removing them with a enormous IF forest which I have hard coded but I would like a better alternative, to an enormous amount of if's, let's say I have this:

toto1: N/A  
test1 {  
toto2: true  
toto3: N/A  
}

I want to transform it into :

test1 {  
toto2: true  
}

Can I do this with anything other then a Ruby filter? If not, how do I do it with Ruby?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 8, 2022, 6:29pm UTC](https://discuss.elastic.co/t/logstash-remove-n-a-field/314002/2 "2022-09-08T18:29:11Z")

</div>

> [@mleg](#):
>
> If not, how do I do it with Ruby?

You could try

```
    ruby {
        init => '
            def doSomething(object, name, event)
                #puts "doSomething called for #{name}"
                if object
                    if object.kind_of?(Hash) and object != {}
                        object.each { |k, v| doSomething(v, "#{name}[#{k}]", event) }
                    elsif object.kind_of?(Array) and object != []
                        object.each_index { |i|
                            doSomething(object[i], "#{name}[#{i}]", event)
                        }
                    else
                        if object == "N/A"
                            event.remove(name)
                        end
                    end
                end
            end
        '
        code => '
            event.to_hash.each { |k, v|
                doSomething(v, "[#{k}]", event)
            }
        '
    }

```

That modifies the event whilst iterating over it. I don't know enough about ruby function calls to know whether that has the possibility of blowing up.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2022, 6:29pm UTC](https://discuss.elastic.co/t/logstash-remove-n-a-field/314002/3 "2022-10-06T18:29:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
