# Space in field reference not working as intended

**URL:** <https://discuss.elastic.co/t/space-in-field-reference-not-working-as-intended/310215>\
**Category:** Logstash\
**Created:** [July 20, 2022, 10:36pm UTC](https://discuss.elastic.co/t/space-in-field-reference-not-working-as-intended/310215 "2022-07-20T22:36:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenJeau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjeau/32/108603_2.png) [@BenJeau](https://discuss.elastic.co/u/BenJeau)\
**Post date:** [July 20, 2022, 10:36pm UTC](https://discuss.elastic.co/t/space-in-field-reference-not-working-as-intended/310215/1 "2022-07-20T22:36:14Z")

</div>

Hi,

I'd like to verify if a field (which contains a space) is present or not in a document and to drop it if its present (in the example below I just added a field to debug and see what/which statement works, but turns out none of them works). I tried different approach, all of them not working:

```auto
filter {
    if ![Total Events] {
        mutate {
            add_field => { "field_1" => True }
        }
    } 
    
    if [Total Events] {} else {
        mutate {
            add_field => { "field_2" => True }
        }
    }

    if !["Total Events"] {
        mutate {
            add_field => { "field_3" => True }
        }
    }

    if ![Total\ Events] {
        mutate {
            add_field => { "field_4" => True }
        }
    } 
}

```

In the resulting document, everything is True even on documents that do not have the field "Total Events". How would someone access the value of a field that has space in its name?

Thanks for your time 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 20, 2022, 10:51pm UTC](https://discuss.elastic.co/t/space-in-field-reference-not-working-as-intended/310215/2 "2022-07-20T22:51:15Z")

</div>

The first two work. The configuration

```
output { stdout { codec => rubydebug { metadata => false } } }
input { generator { count => 1 lines => ['{ "a": "b" }', '{ "a": "b", "Total Events": "c" }'] codec => json { } } }
filter {
    if ![Total Events] { mutate { add_field => { "field_1" => True } } }
    if [Total Events] {} else { mutate { add_field => { "field_2" => True } } }
    if !["Total Events"] { mutate { add_field => { "field_3" => True } } }
    if ![Total\ Events] { mutate { add_field => { "field_4" => True } } }
}

```

produces

```
{
   "field_1" => "True",
   "field_2" => "True",
   "field_3" => "True",
   "field_4" => "True",
         "a" => "b"
}
{
     "field_4" => "True",
     "field_3" => "True",
           "a" => "b",
"Total Events" => "c",
}

```

---

<div class="post-metadata">

**Author:** ![BenJeau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benjeau/32/108603_2.png) [@BenJeau](https://discuss.elastic.co/u/BenJeau)\
**Post date:** [July 21, 2022, 12:20am UTC](https://discuss.elastic.co/t/space-in-field-reference-not-working-as-intended/310215/3 "2022-07-21T00:20:26Z")

</div>

That is interesting - I was expecting the first two to work, so it's good to know that it works for you. The problem must be my source. I'm filtering an index, so the input is an index and the output is another index.

**Edit:** the field was misspelled and there was a problem with the source... At least it works now, thanks for trying it out 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2022, 12:21am UTC](https://discuss.elastic.co/t/space-in-field-reference-not-working-as-intended/310215/4 "2022-08-18T00:21:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
