# Avoiding multiple OR conditions in if statements logstash

**URL:** <https://discuss.elastic.co/t/avoiding-multiple-or-conditions-in-if-statements-logstash/128104>\
**Category:** Logstash\
**Created:** [April 16, 2018, 6:02am UTC](https://discuss.elastic.co/t/avoiding-multiple-or-conditions-in-if-statements-logstash/128104 "2018-04-16T06:02:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesha\_Venkanna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ganesha_venkanna/32/30007_2.png) [@Ganesha\_Venkanna](https://discuss.elastic.co/u/Ganesha_Venkanna)\
**Post date:** [April 16, 2018, 6:02am UTC](https://discuss.elastic.co/t/avoiding-multiple-or-conditions-in-if-statements-logstash/128104/1 "2018-04-16T06:02:14Z")

</div>

Hi,

I am using the below code to parse only required lines from my logfile and ignore the others, though the code is working i want to avoid the multiple OR conditions,can the strings in the OR conditions be read from another CSV or properties file using placeholders?

filter {  
if ([message] =~ "SiteController Connection Accepted for SiteControllerIP=" or [message] =~ "Acknowledgement sent for SiteController Connection request for SiteControllerIP="){  
grok {  
patterns\_dir =\> ["./patterns"]  
match =\> { "message" =\> "%{PANACES\_DATE:log\_date}%{SPACE}[%{GREEDYDATA:threadname}]%{SPACE}%{WORD:module}%{SPACE}%{WORD:submodule}%{SPACE}[-]%{SPACE}::%{WORD:classname}::%{DATA:log\_message}%{SPACE}%{IP:siteControllerIP}%{SPACE}[,]%{SPACE}%{WORD:siteControllerIDKey}[=]%{SPACE}%{NUMBER:siteControllerID}" }  
}  
}  
else if ([message] =~ "Registered the agent with agentDetails:" or [message] =~ "Recieved heartBeat from the agent with the details = " or [message] =~ "Acknowledgement sent to the agent with agentDetails:" or [message] =~ "checkHealth: Disconnecting the Agent with the details " or [message] =~ "checkHealth::Agent is connected with agent details " or [message] =~"About to send heartbeat from server to agent" or [message] =~ "Successfully sent heartbeat to" or [message] =~ "rpc not possible for agent while sending heartbeat" or [message] =~ "Problem sending hb to agent" or [message] =~ "checkHealth: there where no activities on the socket for" or [message] =~"checkHealth: Disconnected the Agent with the details" or [message] =~ "checkHealth: socket.write is blocked for a while - something is really wrong - disconnecting for"){  
grok {  
patterns\_dir =\> ["./patterns"]  
match =\> { "message" =\> "%{PANACES\_DATE:log\_date}%{SPACE}[%{GREEDYDATA:threadname}]%{SPACE}%{WORD:module}%{SPACE}%{WORD:submodule}%{SPACE}[-]%{SPACE}::%{WORD:classname}::%{DATA:log\_message}%{SPACE}%{WORD:agentKey}[=]%{SPACE}%{DATA:agentname}%{SPACE}%{WORD:agentIPKey}[=]%{SPACE}%{IP:agentIpAddress}%{SPACE}%{WORD:agentIdKey}[=]%{SPACE}%{NUMBER:agentId}%{SPACE}%{WORD:siteControllerIPKey}[=]%{SPACE}%{DATA:siteControllerIP}%{WORD:siteControllerIDKey}[=]%{SPACE}%{DATA:siteControllerID}" }  
}

}  
else{   
drop { }  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}

what i mean is can the below

else if ([message] =~ "Registered the agent with agentDetails:" or [message] =~ "Recieved heartBeat from the agent with the details = " or [message] =~ "Acknowledgement sent to the agent with agentDetails:" or [message] =~ "checkHealth: Disconnecting the Agent with the details " or [message] =~ "checkHealth::Agent is connected with agent details " or [message] =~"About to send heartbeat from server to agent" or [message] =~ "Successfully sent heartbeat to" or [message] =~ "rpc not possible for agent while sending heartbeat" or [message] =~ "Problem sending hb to agent" or [message] =~ "checkHealth: there where no activities on the socket for" or [message] =~"checkHealth: Disconnected the Agent with the details" or [message] =~ "checkHealth: socket.write is blocked for a while - something is really wrong - disconnecting for")

be like

else if ([message] in $(List\_of messages))

Thanks

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [April 16, 2018, 6:30am UTC](https://discuss.elastic.co/t/avoiding-multiple-or-conditions-in-if-statements-logstash/128104/2 "2018-04-16T06:30:11Z")

</div>

Please use markdown or \</\> to format your code.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 16, 2018, 6:36am UTC](https://discuss.elastic.co/t/avoiding-multiple-or-conditions-in-if-statements-logstash/128104/3 "2018-04-16T06:36:49Z")

</div>

You should be able to use a translate filter (with the `regex` option enabled).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2018, 6:37am UTC](https://discuss.elastic.co/t/avoiding-multiple-or-conditions-in-if-statements-logstash/128104/4 "2018-05-14T06:37:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
