# Condition Section after Grok section not working

**URL:** <https://discuss.elastic.co/t/condition-section-after-grok-section-not-working/281600>\
**Category:** Logstash\
**Created:** [August 16, 2021, 8:30pm UTC](https://discuss.elastic.co/t/condition-section-after-grok-section-not-working/281600 "2021-08-16T20:30:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Athul\_Devkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/athul_devkar/32/93241_2.png) [@Athul\_Devkar](https://discuss.elastic.co/u/Athul_Devkar)\
**Post date:** [August 16, 2021, 8:30pm UTC](https://discuss.elastic.co/t/condition-section-after-grok-section-not-working/281600/1 "2021-08-16T20:30:02Z")

</div>

Hello Everyone!

I am trying to modify my pipeline to allow me to create few additional fields based on certain conditions. However, that section alone is not working and I don't see any errors in my log. I had used similar conditions before adding the Grok section and that time it had worked. Not sure what I am missing here. Any help is appreciated.

```auto
filter {
    json {
        source => message
        add_field => {
            "region" => "us-east-1" 
        }
    }
    if [message] =~ /Customer Type : ec/ {
    grok {
        match => {"message" => "Automation Type : %{DATA:AutomationTypeValue}, OrderSubmitRequest UtcTimeStamp : %{TIMESTAMP_ISO8601:timestamp}, AgentId : %{DATA:agentID}, Agent Email Address: %{DATA:agentEmail}, Division : %{DATA:Division}, Opportunity Number : %{DATA:OptyNum}, Data : %{DATA:DataFlag}, Voice : %{DATA:VoiceFlag}, Video : %{DATA:VideoFlag}, Smart Office : %{DATA:SOFlag}, Package Customer : %{DATA:PackageFlag}, Existing Services : %{DATA:ExistingService}, Account Number : %{NUMBER:AcctNumber}, Title Role: %{DATA:TitleRole}, Customer Type : %{DATA:CustomerType}, Source Type : %{DATA:SourceType}, FxBuyflowSessionId : %{DATA:SessionId}, Order Number : %{DATA:OrderNumber}, ExistingTotalMrc : %{NUMBER:ExistingTotalMRC:float}, NewTotalMrc : %{NUMBER:NewTotalMRC:float}, Correlation Id : %{NUMBER:CorrId} %{GREEDYDATA:message}"}        
    }
    }
	if ([message] =~ /Data : True/ and [message] =~ /Voice : False/ and [message] =~ /TV : False/ and [message] =~ /SO : False/) {
	 mutate {
        add_field => {"OrderLOB" => "BIOnly"}
    }}else if ([message] =~ /Data : True/ and [message] =~ /Voice : True/ and [message] =~ /TV : False/ and [message] =~ /SO : False/) {
	 mutate {
        add_field => {"OrderLOB" => "BI+BV"}
    }}else if ([message] =~ /Data : True/ and [message] =~ /Voice : True/ and [message] =~ /TV : True/ and [message] =~ /SO : False/) {
	 mutate {
        add_field => {"OrderLOB" => "BI+BV+BTV"}
    }}
    else {mutate {
        add_field => {"OrderLOB" => "None"}
    }}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 16, 2021, 8:48pm UTC](https://discuss.elastic.co/t/condition-section-after-grok-section-not-working/281600/2 "2021-08-16T20:48:25Z")

</div>

If the grok matches then [message] will be an array, so none of the rest of your references will work. You will need to change them to [message][0] if you want to match the original message, or [message][1] if you want what the GREEDYDATA at the end captured. Alternatively, use the overwrite option on the grok filter, or change the name of the capture for that GREEDYDATA.

---

<div class="post-metadata">

**Author:** ![Athul\_Devkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/athul_devkar/32/93241_2.png) [@Athul\_Devkar](https://discuss.elastic.co/u/Athul_Devkar)\
**Post date:** [August 16, 2021, 9:07pm UTC](https://discuss.elastic.co/t/condition-section-after-grok-section-not-working/281600/3 "2021-08-16T21:07:45Z")

</div>

Ahhh makes sense. Didn't notice that. Changed the name of GREEDYDATA and now the first condition works. Thanks you so much!!

However, the else conditions don't work. Even If I change the 2nd 'else if' condition to just new 'if'

```auto
if ([message] =~ /Data : True/ and [message] =~ /Voice : False/ and [message] =~ /TV : False/ and [message] =~ /SO : False/) {
	 mutate {
        add_field => {"OrderLOB" => "BIOnly"}
    }}
if ([message] =~ /Data : True/ and [message] =~ /Voice : True/ and [message] =~ /TV : False/ and [message] =~ /SO : False/) {
	 mutate {
        add_field => {"OrderLOB" => "BI+BV"}
    }}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 16, 2021, 9:13pm UTC](https://discuss.elastic.co/t/condition-section-after-grok-section-not-working/281600/4 "2021-08-16T21:13:24Z")

</div>

The second mutate requires all four patterns to match. I would suggest that if the mutate is not happening then one of the patterns does not match. Try splitting it into 4 and see if all four mutates happen.

---

<div class="post-metadata">

**Author:** ![Athul\_Devkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/athul_devkar/32/93241_2.png) [@Athul\_Devkar](https://discuss.elastic.co/u/Athul_Devkar)\
**Post date:** [August 16, 2021, 9:28pm UTC](https://discuss.elastic.co/t/condition-section-after-grok-section-not-working/281600/5 "2021-08-16T21:28:48Z")

</div>

I was adding the value to a different field. It's all good now.

Thanks again!! Appreciate the quick help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2021, 9:29pm UTC](https://discuss.elastic.co/t/condition-section-after-grok-section-not-working/281600/6 "2021-09-13T21:29:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
