# Splitting field in logstash

**URL:** <https://discuss.elastic.co/t/splitting-field-in-logstash/213184>\
**Category:** Logstash\
**Created:** [December 27, 2019, 11:51am UTC](https://discuss.elastic.co/t/splitting-field-in-logstash/213184 "2019-12-27T11:51:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nisha.MP](https://avatars.discourse-cdn.com/v4/letter/n/e95f7d/32.png) [@Nisha.MP](https://discuss.elastic.co/u/Nisha.MP)\
**Post date:** [December 27, 2019, 11:51am UTC](https://discuss.elastic.co/t/splitting-field-in-logstash/213184/1 "2019-12-27T11:51:34Z")

</div>

Hi  
I'm trying to split a particular field in CloudTrail log and this is my filter pattern  
filter{  
json{  
source =\> "message"  
}  
split{  
field =\> "resources"  
add\_tag =\> "splitted"  
} }  
This is working when the field named "resources" exists in the logs. When the logs doesn't contains this field, getting an error **[WARN][logstash.filters.split][main] Only String and Array types are splittable. field:resources is of type = NilClass**.  
I need help to rewrite the filter pattern to handle this exception and so to avoid getting the above given error log.

---

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [December 27, 2019, 1:17pm UTC](https://discuss.elastic.co/t/splitting-field-in-logstash/213184/2 "2019-12-27T13:17:08Z")

</div>

@Nisha.MP please include your sample log file

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [December 27, 2019, 3:41pm UTC](https://discuss.elastic.co/t/splitting-field-in-logstash/213184/3 "2019-12-27T15:41:12Z")

</div>

> [@Nisha.MP](#):
>
> This is working when the field named "resources" exists in the logs. When the logs doesn't contains this field, getting an error ...

So you could execute the filter inside a conditional block that checks the existence of `resources` field

```
if [resources] {
    split { ... }
}

```

---

<div class="post-metadata">

**Author:** ![Nisha.MP](https://avatars.discourse-cdn.com/v4/letter/n/e95f7d/32.png) [@Nisha.MP](https://discuss.elastic.co/u/Nisha.MP)\
**Post date:** [December 30, 2019, 6:06am UTC](https://discuss.elastic.co/t/splitting-field-in-logstash/213184/4 "2019-12-30T06:06:06Z")

</div>

Yup that worked. Thanks a bunch!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2020, 6:06am UTC](https://discuss.elastic.co/t/splitting-field-in-logstash/213184/5 "2020-01-27T06:06:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
