# Sql query returns nothing , but output file udpated

**URL:** <https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622>\
**Category:** Logstash\
**Created:** [December 19, 2023, 6:16am UTC](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622 "2023-12-19T06:16:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gayatri\_SN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gayatri_sn/32/105321_2.png) [@gayatri\_SN](https://discuss.elastic.co/u/gayatri_SN)\
**Post date:** [December 19, 2023, 6:16am UTC](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622/1 "2023-12-19T06:16:15Z")

</div>

Hi,  
I'm using jdbc input streaming filter to get the data from query. but in some cases query returns empty or null value.  
\<  
last\_run\_metadata\_path =\> \<filepath/sql\_last\_value.yml  
statement\_filepath =\> \<filepath/query.sql\>  
target =\> "test"  
/\>  
below is the query result if data not empty  
\<  
{"created"=\>"2023-12-19"}  
/\>  
and in output plugin writing this date in file  
\<  
file {  
path =\> \<filepath/sql\_last\_value.yml\>  
codec =\> line { format =\> "datetime '%{created}'"}  
write\_behavior =\> "overwrite"  
}  
/\>  
I dont want to set/update file if sql query not returning anything. I have tried below code but it is not working. still its updating file with datetime at what pipeline executing.  
\<  
if [test] {  
file {  
path =\> \<filepath/sql\_last\_value.yml\>  
codec =\> line { format =\> "datetime '%{created}'"}  
write\_behavior =\> "overwrite"  
}  
}  
/\>  
can anybody tell me how to handle this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 19, 2023, 5:55pm UTC](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622/2 "2023-12-19T17:55:42Z")

</div>

> [@gayatri\_SN](#):
>
> I'm using jdbc input streaming filter

I'm going to assume that you are using a jdbc\_streaming filter rather than a jdbc input.

When there is no match in the jdbc\_streaming filter then the target is set to a [default\_hash](https://www.elastic.co/guide/en/logstash/current/plugins-filters-jdbc_streaming.html#plugins-filters-jdbc_streaming-default_hash). Thus [test] will always exist, although if there is no match it will just be an empty hash.

Try `if [test][created]`.

---

<div class="post-metadata">

**Author:** ![gayatri\_SN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gayatri_sn/32/105321_2.png) [@gayatri\_SN](https://discuss.elastic.co/u/gayatri_SN)\
**Post date:** [December 20, 2023, 5:18am UTC](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622/3 "2023-12-20T05:18:23Z")

</div>

Thanks. But if i use jdbc\_input instead of jdbc\_streaming then how to achieve this ? after execution of every pipeline schedule the output file is updating even though result is empty. Why it is updating?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 20, 2023, 5:28am UTC](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622/4 "2023-12-20T05:28:21Z")

</div>

A quick Googling suggests that the same answer applies to the jdbc input. Creating a new event probably results in an [empty hash](https://github.com/logstash-plugins/logstash-mixin-event_support/blob/fcd1ad8cbc6a9985f18ebfe189276dda0e7d2727/lib/logstash/plugin_mixins/event_support/event_factory_adapter/fallback_impl.rb#L49) as the target.

Try it, let us know.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2024, 5:28am UTC](https://discuss.elastic.co/t/sql-query-returns-nothing-but-output-file-udpated/349622/5 "2024-01-17T05:28:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
