# Set a default value if nil

**URL:** <https://discuss.elastic.co/t/set-a-default-value-if-nil/228319>\
**Category:** Logstash\
**Created:** [April 16, 2020, 1:03pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319 "2020-04-16T13:03:21Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yaniv\_Nuriel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaniv_nuriel/32/66359_2.png) [@Yaniv\_Nuriel](https://discuss.elastic.co/u/Yaniv_Nuriel)\
**Post date:** [April 16, 2020, 1:03pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/1 "2020-04-16T13:03:21Z")

</div>

Hey,

I know it has been asked a lot, but I tried every solution and nothing works for me.  
I have a field that sometimes is empty (,,) so I want to set "ebay" in that case.

Here it is how it looks like when it is nil:

```auto
    "marketplace" => nil ,

```

And when I set the conf file as follow it is still nil

```auto
    if [!marketplace] {
        mutate {add_field => {"marketplace" => "ebay"} }
    }

```

What am I doing wrong?

Thanks!!  
Yaniv

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2020, 1:43pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/2 "2020-04-16T13:43:21Z")

</div>

> [@Yaniv\_Nuriel](#):
>
> if [!marketplace] {

That should be

```
if ! [marketplace] {

```

---

<div class="post-metadata">

**Author:** ![Yaniv\_Nuriel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaniv_nuriel/32/66359_2.png) [@Yaniv\_Nuriel](https://discuss.elastic.co/u/Yaniv_Nuriel)\
**Post date:** [April 16, 2020, 1:56pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/3 "2020-04-16T13:56:25Z")

</div>

Thanks, it looks much better, but now the value set it this:

```auto
    "marketplace" => [
        [0] "ebay"
    ],

```

instead of

```auto
     "marketplace" => "ebay",

```

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [April 16, 2020, 2:35pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/4 "2020-04-16T14:35:42Z")

</div>

Doing this

```
if ![marketplace] {
  mutate {add_field => {"marketplace" => "ebay"} }
}

```

adds you the value as an array out of the pipeline? Not possible, there must be something you are omitting:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/3/9326ab58310d17fb37ab660f748f8b487fc3e37c.png)

Please post here your whole pipeline and a sample of input (generated by the run of the pipeline without the filter section and with the stdout{} as output).

---

<div class="post-metadata">

**Author:** ![Yaniv\_Nuriel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaniv_nuriel/32/66359_2.png) [@Yaniv\_Nuriel](https://discuss.elastic.co/u/Yaniv_Nuriel)\
**Post date:** [April 16, 2020, 2:49pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/5 "2020-04-16T14:49:58Z")

</div>

Here is the full pipeline:

```auto
{
                    "@version" => "1",
                   "date/time" => "Feb 2, 2020 3:12:55 AM PST",
        "giftwrap credits tax" => 0.0,
                "order postal" => nil,
                    "quantity" => nil,
                        "type" => "Service Fee",
                    "fba fees" => 0.0,
                 "description" => "Cost of Advertising",
                        "tags" => [
        [0] "_mutate_error"
    ],
                        "path" => "/Users/yanivnuriel/logstash/data/transactions/all-14.txt",
            "shipping credits" => 0.0,
                       "total" => -122.32,
                     "message" => "\"Feb 2, 2020 3:12:55 AM PST\",12578696491,Service Fee,,,Cost of Advertising,,,,,,,,0,0,0,0,0,0,0,0,0,0,0,-122.32,0,-122.32\r",
                  "order city" => nil,
        "tax collection model" => nil,
               "product sales" => 0.0,
        "shipping credits tax" => 0.0,
      "other transaction fees" => -122.32,
           "gift wrap credits" => 0.0,
                 "order state" => nil,
     "promotional rebates tax" => 0.0,
                "selling fees" => 0.0,
         "promotional rebates" => 0.0,
           "product sales tax" => 0.0,
                 "fulfillment" => nil,
    "marketplace withheld tax" => 0.0,
               "settlement id" => "12578696491",
                       "other" => 0.0,
                    "order id" => nil,
                 "marketplace" => [
        [0] "ebay"
    ],
                        "host" => "Yanivs-MBP",
                         "sku" => nil,
                  "@timestamp" => 2020-02-02T11:12:55.000Z
}

```

Here is the only mutate part in config:

```auto
    if ! [marketplace] {
        mutate {add_field => {"marketplace" => "ebay"} }
    }

```

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [April 16, 2020, 2:54pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/6 "2020-04-16T14:54:34Z")

</div>

Well that's not the pipeline, that's the result of your pipeline. The pipeline is what is inside the conf file. For example, from your result I see there's a \_mutate\_error in the tags. Where does that come from?

Please, post here 2 things:

1 - An example of an input. It is something similar to what you posted in your previous post but without the filter section applied. So comment it out and run logstash only with the input section and the stdout{} part in the output section. This is useful for us to see how Logstash is treating your input data.

2 - Your whole pipeline (i.e. conf file). This is needed to see where you are creating that array.

---

<div class="post-metadata">

**Author:** ![Yaniv\_Nuriel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaniv_nuriel/32/66359_2.png) [@Yaniv\_Nuriel](https://discuss.elastic.co/u/Yaniv_Nuriel)\
**Post date:** [April 16, 2020, 4:40pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/7 "2020-04-16T16:40:58Z")

</div>

Thanks for the prompt respond.  
I think I found the problem, in one hand the value is nil, but then I understood that if I get array than it might existed .. weird..  
So I decided to change the add\_field to replace:

```auto
    if ![marketplace] {
        mutate {replace => {"marketplace" => "ebay"} }
    }

```

Now it works..

```auto
    "selling fees" => 0.0,
    "marketplace" => "ebay",
    "type" => "Adjustment",
    "shipping credits" => 0.0,

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2020, 7:29pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/8 "2020-04-16T19:29:38Z")

</div>

Interesting

```
input { generator { count => 1 lines => [''] } }
filter {
    ruby { code => 'event.set("someField", nil)' }
    if ! [someField] {
        mutate { add_field => { "someField" => "someValue" } }
    }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

produces

```
 "someField" => [
    [0] "someValue"
]

```

That is, if the field exists but is nil, then add\_field adds the single value as an array. I would argue that that is a bug.

---

<div class="post-metadata">

**Author:** ![Yaniv\_Nuriel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaniv_nuriel/32/66359_2.png) [@Yaniv\_Nuriel](https://discuss.elastic.co/u/Yaniv_Nuriel)\
**Post date:** [April 16, 2020, 8:26pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/9 "2020-04-16T20:26:24Z")

</div>

Thanks for you time and guidelines

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2020, 8:26pm UTC](https://discuss.elastic.co/t/set-a-default-value-if-nil/228319/10 "2020-05-14T20:26:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
