# Check input contains.message failed

**URL:** <https://discuss.elastic.co/t/check-input-contains-message-failed/270372>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 16, 2021, 10:10am UTC](https://discuss.elastic.co/t/check-input-contains-message-failed/270372 "2021-04-16T10:10:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![joepkemel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joepkemel/32/87176_2.png) [@joepkemel](https://discuss.elastic.co/u/joepkemel)\
**Post date:** [April 16, 2021, 10:10am UTC](https://discuss.elastic.co/t/check-input-contains-message-failed/270372/1 "2021-04-16T10:10:04Z")

</div>

Hi, I am trying to make an if contains /else dissect statement. But I can't really figure it out. This is because a log file contains an extra '|' inside a wanted field. For example 'type|timestamp|IP[xx.xx| port]|-' and I want to ignore the | in between the ip and port. Note this is just a fast example.  
My idea was to do this by using a if else and when this is present use a different dissect method.

This is what I have:  
Error: 'Exiting: Failed to start crawler: starting input failed: Error while initializing input: missing or invalid condition'  
Note: for now the dissects are the same

```auto

  processors:

  - if:
    contains.message: 'path:[IP'
    then:
      - dissect:
        tokenizer: "%{service.type}|%{ID}|%{@timestamp}|%{time}|%{log.level}|%{file.path}|%{function}|%{message}|%{details}"
        field: "message"
        target_prefix: "logdata"
    else:
      - dissect:
        tokenizer: "%{service.type}|%{ID}|%{@timestamp}|%{time}|%{log.level}|%{file.path}|%{function}|%{message}|%{details}"
        field: "message"
        target_prefix: "logdata"

```

I hope this explains my problem enough, thanks for reading!

---

<div class="post-metadata">

**Author:** ![joepkemel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joepkemel/32/87176_2.png) [@joepkemel](https://discuss.elastic.co/u/joepkemel)\
**Post date:** [April 16, 2021, 2:33pm UTC](https://discuss.elastic.co/t/check-input-contains-message-failed/270372/2 "2021-04-16T14:33:09Z")

</div>

I found what I needed to do,  
First indentation needed to be correct.  
Second in the tokenizer I could use and extra |%{+message}  
To combine the 2 messages.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2021, 4:34pm UTC](https://discuss.elastic.co/t/check-input-contains-message-failed/270372/3 "2021-05-14T16:34:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
