# Conditional expression to test for a list of possible partial matches in a string

**URL:** <https://discuss.elastic.co/t/conditional-expression-to-test-for-a-list-of-possible-partial-matches-in-a-string/133583>\
**Category:** Logstash\
**Created:** [May 28, 2018, 6:58pm UTC](https://discuss.elastic.co/t/conditional-expression-to-test-for-a-list-of-possible-partial-matches-in-a-string/133583 "2018-05-28T18:58:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jlsam](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@jlsam](https://discuss.elastic.co/u/jlsam)\
**Post date:** [May 28, 2018, 6:58pm UTC](https://discuss.elastic.co/t/conditional-expression-to-test-for-a-list-of-possible-partial-matches-in-a-string/133583/1 "2018-05-28T18:58:21Z")

</div>

I want to select and output only the uncommon messages in a log, based on a partial match (the beginning of the message).

I can filter out _one_ message like so

```
output {
  if "foo" not in [msg] {

```

But if it try to match [msg] against multiple options like this

```
output {
  if ["this", "that", "uninteresting", "boring", "yawn"] not in [msg] {

```

I get an error:

> TypeError: no implicit conversion of Array into String

If I invert the syntax,

```
output {
  if [msg] not in ["this", "that", "received", "sent", "yawn"] {

```

I get no error, but also no filtering.

If I try the regexp operator,

```
output {
  if [msg] !~ ["this", "that", "received", "sent", "yawn"] {

```

or

```
output {
  if ["this", "that", "received", "sent", "yawn"] !~ [msg] {

```

I get a really long and ugly error about

> Expected one of #, ", ', / at line 14, column 15 (byte 202) after output {\n if [msg] !~

And again no filtering.

What would be the correct way to check if any one of a list of words/strings exists in another string? Do I have to daisy chain every single comparison with OR operators?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 28, 2018, 7:40pm UTC](https://discuss.elastic.co/t/conditional-expression-to-test-for-a-list-of-possible-partial-matches-in-a-string/133583/2 "2018-05-28T19:40:45Z")

</div>

> [@jlsam](#):
>
> Do I have to daisy chain every single comparison with OR operators?

Yes, but in a regexp that is concise. Using ^ to anchor at the beginning...

```auto
if [msg] =~ /^(this|that|received|sent|yawn)/ {

```

---

<div class="post-metadata">

**Author:** ![jlsam](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@jlsam](https://discuss.elastic.co/u/jlsam)\
**Post date:** [May 28, 2018, 10:38pm UTC](https://discuss.elastic.co/t/conditional-expression-to-test-for-a-list-of-possible-partial-matches-in-a-string/133583/3 "2018-05-28T22:38:24Z")

</div>

Thanks for the reply! But why the // to enclose the regexp instead of ""?

The example here  
[https://www.elastic.co/guide/en/logstash/current/config-examples.html#using-conditionals](https://www.elastic.co/guide/en/logstash/current/config-examples.html#using-conditionals)  
uses "".

Cheers.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 29, 2018, 12:16am UTC](https://discuss.elastic.co/t/conditional-expression-to-test-for-a-list-of-possible-partial-matches-in-a-string/133583/4 "2018-05-29T00:16:14Z")

</div>

> [@jlsam](#):
>
> But why the // to enclose the regexp instead of ""?

=~ matches against a regexp, so I choose to use the ruby syntax for a regex (i.e. /string/). Logstash is good about converting types if the interpretation of what you give it is unambiguous.

Similarly, lots of filter options that take arrays will accept hashes, and hashes may accept arrays. I guess if somehash.to\_a returns an array the filter can work with then it does not complain.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2018, 12:16am UTC](https://discuss.elastic.co/t/conditional-expression-to-test-for-a-list-of-possible-partial-matches-in-a-string/133583/5 "2018-06-26T00:16:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
