# Remove Empty String Value

**URL:** <https://discuss.elastic.co/t/remove-empty-string-value/170560>\
**Category:** Logstash\
**Created:** [March 1, 2019, 8:13pm UTC](https://discuss.elastic.co/t/remove-empty-string-value/170560 "2019-03-01T20:13:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 1, 2019, 8:13pm UTC](https://discuss.elastic.co/t/remove-empty-string-value/170560/1 "2019-03-01T20:13:08Z")

</div>

Running Logstash 6.4.1

I have a field that contains an array of numbers. I am converting the field to string values so that I can translate them to their text values with gsub. All of this works great, except that for one value which I "delete" from the array, it leaves behind an empty array value. How can I get rid of this?

Pipeline Config

```auto
  mutate {
    convert => {
    "[user][groups]" => "string"
    }
  }
  mutate {
    gsub => [
      "[user][groups]", "9439", "",
      "[user][groups]", "9427", "K4_",

```

JSON Output  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/0/e0890f3716a9d1a22809bca7471b59ce95bb7941.png)

Appearance in Kibana  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/7/f731c7f5c88e2fb849841c71435a656f8084c75f.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 8:19pm UTC](https://discuss.elastic.co/t/remove-empty-string-value/170560/2 "2019-03-01T20:19:57Z")

</div>

You could do it using a ruby filter.

```
ruby { code => 'event.set("[user][groups]", event.get("[user][groups]").reject { |x| x.empty? })' }
```

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 1, 2019, 8:25pm UTC](https://discuss.elastic.co/t/remove-empty-string-value/170560/3 "2019-03-01T20:25:42Z")

</div>

Fantastic!

Any chance you can school me on what's going on here? Looks like event.set targets a field, event.get grabs the current values and then reject...does something?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 8:59pm UTC](https://discuss.elastic.co/t/remove-empty-string-value/170560/4 "2019-03-01T20:59:27Z")

</div>

Yes, [event.get](https://www.elastic.co/guide/en/logstash/current/event-api.html) fetches the current value of the [user][groups] field. [reject](https://ruby-doc.org/core-2.6.1/Array.html#method-i-reject) is a method of the Ruby Array class, which returns a new array that contains only those array entries for which the script block returns false. That is, it rejects entries for which the script block returns true, and x.empty? returns true for empty strings.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 8:59pm UTC](https://discuss.elastic.co/t/remove-empty-string-value/170560/5 "2019-03-29T20:59:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
