# Condition filter not working after upgrading to logstash8

**URL:** <https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300>\
**Category:** Logstash\
**Created:** [October 11, 2022, 9:16am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300 "2022-10-11T09:16:31Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![PIYUSH\_MISHRA1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_mishra1/32/111923_2.png) [@PIYUSH\_MISHRA1](https://discuss.elastic.co/u/PIYUSH_MISHRA1)\
**Post date:** [October 11, 2022, 9:16am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300/1 "2022-10-11T09:16:31Z")

</div>

Hi Team,  
I have following configuration in my logstash.conf file.  
irresepective of the value in ${ENV}, always else block is getting executed.  
Same piece of code used to work with logstash older versions (2.X and 6.x).  
Could you please help in this regard.

Thanks.

```auto

filter
{
	if "${ENV}" in [“env1”, “env2"] {
			mutate{…1}
	} else{
			mutate{…2}
        }
				
}

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 11, 2022, 9:30am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300/2 "2022-10-11T09:30:54Z")

</div>

You have to show values from "IF", pls use debug mode.

From 8.4 documentation:  
_You can use the `in` operator to test whether a field contains a specific string, key, or list element. Note that the semantic meaning of `in` can vary, based on the target type. For example, when applied to a string. `in` means "is a substring of". When applied to a collection type, `in` means "collection contains the exact value"._

---

<div class="post-metadata">

**Author:** ![PIYUSH\_MISHRA1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_mishra1/32/111923_2.png) [@PIYUSH\_MISHRA1](https://discuss.elastic.co/u/PIYUSH_MISHRA1)\
**Post date:** [October 11, 2022, 10:00am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300/3 "2022-10-11T10:00:22Z")

</div>

@Rios Yes .. I am trying to match exact value of ${ENV} in the list.  
exact values:

```auto
filter
{
	if "dev" in [“dev”, “load"] {
			mutate{…1}
	} else{
			mutate{…2}
        }
				
}

```

in this filter it should execute if section not else sections.. if i understand it correctly.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 11, 2022, 11:21am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300/4 "2022-10-11T11:21:49Z")

</div>

I would use with assigning to the field to check does a field exist in list of strings

```auto
  mutate {
	add_field => { "[@metadata][env]" => "${ENV}" 
	}
  }
if ( [@metadata][env] in ["env1", "env2"] ) {

```

**\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_**  
The sample from [documentation](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals) is valid without foo in the list:

```auto
  if !("foo" in ["hello", "world"]) {
    mutate { add_tag => "shouldexist" }
  }

```

But not valid if "foo" value exist in the list

```auto
  if !("foo" in ["hello", "world", "foo"]) {
    mutate { add_tag => "shouldexist" }
  }

```

This add tags which is not OK.

```auto
          "tags" => [
        [0] "shouldexist"

```

This should return true, but return false and not add tag

```auto
 if ("foo" in ["hello", "world", "foo"]) {
    mutate { add_tag => "shouldexist" }
  }

```

---

<div class="post-metadata">

**Author:** ![PIYUSH\_MISHRA1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/piyush_mishra1/32/111923_2.png) [@PIYUSH\_MISHRA1](https://discuss.elastic.co/u/PIYUSH_MISHRA1)\
**Post date:** [October 11, 2022, 3:44pm UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300/5 "2022-10-11T15:44:51Z")

</div>

exactly.. `"foo" in ["hello", "world", "foo"]` should return true but it returns false somehow. is that a bug?

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 12, 2022, 5:35am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300/6 "2022-10-12T05:35:52Z")

</div>

Looks like. Maybe something else has been changed in Ruby like in [Python](https://stackoverflow.com/questions/132988/is-there-a-difference-between-and-is#:~:text=%3D%3D%20is%20for%20value%20equality,refer%20to%20the%20same%20object.)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2022, 5:36am UTC](https://discuss.elastic.co/t/condition-filter-not-working-after-upgrading-to-logstash8/316300/7 "2022-11-09T05:36:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
