# Conditional statement in output

**URL:** https://discuss.elastic.co/t/conditional-statement-in-output/74672
**Category:** Logstash
**Created:** [February 10, 2017, 2:41pm UTC](https://discuss.elastic.co/t/conditional-statement-in-output/74672 "2017-02-10T14:41:10Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![andrew-waters](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew-waters/32/15427_2.png) [@andrew-waters](https://discuss.elastic.co/u/andrew-waters)
#### Post date: [February 10, 2017, 2:41pm UTC](https://discuss.elastic.co/t/conditional-statement-in-output/74672/1 "2017-02-10T14:41:10Z")

</div>

I have a logstash configuration file (5.2:alpine) and want to use the same file for development and production environments.

I have loaded in environment variables and confirmed they exist.

However, when trying to change the output based on the environment variable (in this example [environment] is configured in the filter), the elasticsearch configuration combines both declarations and does not see them as unique settings, causing development to fail:

```auto
output {

    if [environment] == "development" {

        elasticsearch {
            hosts => ["${ELS_HOSTNAME}:${ELS_PORT}"]
            index => "%{els_index}"
            action => "%{els_action}"
            document_type => "%{type}"
            document_id => "%{id}"
        }
        stdout {
            codec => rubydebug
        }

    } else {

        elasticsearch {
            hosts => ["${ELS_HOSTNAME}:${ELS_PORT}"]
            ssl => "${ELS_SSL:false}"
            ssl_certificate_verification => "${ELS_SSL_VERIFY:false}"
            healthcheck_path => "https://${ELS_USERNAME:guest}:${ELS_PASSWORD:guest}@${ELS_HOSTNAME}:${ELS_PORT}/"
            absolute_healthcheck_path => "true"
            user => "${ELS_USERNAME:guest}"
            password => "${ELS_PASSWORD:guest}"
            index => "%{els_index}"
            action => "%{els_action}"
            document_type => "%{type}"
            document_id => "%{id}"
        }

    }
}

```

Is my approach to this incorrect or is this a potential bug?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 12, 2017, 6:34pm UTC](https://discuss.elastic.co/t/conditional-statement-in-output/74672/2 "2017-02-12T18:34:02Z")

</div>

You mean both elasticsearch outputs are used as if the `if` and `else` lines had just been commented out?

---

<div class="post-metadata">

### Author: ![andrew-waters](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew-waters/32/15427_2.png) [@andrew-waters](https://discuss.elastic.co/u/andrew-waters)
#### Post date: [February 12, 2017, 7:26pm UTC](https://discuss.elastic.co/t/conditional-statement-in-output/74672/3 "2017-02-12T19:26:02Z")

</div>

Hi @magnusbaeck, yes - the output is analogous to the following declaration:

```auto
output {

    elasticsearch {
        hosts => ["${ELS_HOSTNAME}:${ELS_PORT}"]
        index => "%{els_index}"
        ssl => "${ELS_SSL:false}"
        ssl_certificate_verification => "${ELS_SSL_VERIFY:false}"
        healthcheck_path => "https://${ELS_USERNAME:guest}:${ELS_PASSWORD:guest}@${ELS_HOSTNAME}:${ELS_PORT}/"
        absolute_healthcheck_path => "true"
        user => "${ELS_USERNAME:guest}"
        password => "${ELS_PASSWORD:guest}"
        action => "%{els_action}"
        document_type => "%{type}"
        document_id => "%{id}"
    }
    stdout {
        codec => rubydebug
    }

}

```

It's as if the conditional statement is all interpreted and the last variable through wins...

---

<div class="post-metadata">

### Author: ![joniba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joniba/32/136103_2.png) [@joniba](https://discuss.elastic.co/u/joniba)
#### Post date: [February 18, 2017, 8:59am UTC](https://discuss.elastic.co/t/conditional-statement-in-output/74672/4 "2017-02-18T08:59:00Z")

</div>

Just wondering if you found a way to resolve this? I'm running into the same issue. It seems like the conditionals are completely ignored in this case.

---

<div class="post-metadata">

### Author: ![joniba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joniba/32/136103_2.png) [@joniba](https://discuss.elastic.co/u/joniba)
#### Post date: [February 18, 2017, 9:07am UTC](https://discuss.elastic.co/t/conditional-statement-in-output/74672/5 "2017-02-18T09:07:26Z")

</div>

Apparently there is [an issue open on this, and also a workaround](https://github.com/elastic/logstash/issues/5115) (though I personally cannot get it to work).

E.g.,

mutate {  
add\_field =\> { "[@metadata][LS\_ENDP\_JDBC]" =\> "${LS\_ENDP\_JDBC:a}" }  
}

if [@metadata][LS\_ENDP\_JDBC] == "a" {  
...  
}

---

<div class="post-metadata">

### Author: ![andrew-waters](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew-waters/32/15427_2.png) [@andrew-waters](https://discuss.elastic.co/u/andrew-waters)
#### Post date: [February 18, 2017, 9:46am UTC](https://discuss.elastic.co/t/conditional-statement-in-output/74672/6 "2017-02-18T09:46:55Z")

</div>

Thanks @joniba , my workaround is to use two logstash configuration files - and use the ENV var in a Dockerfile to copy the correct one across depending on the build pipeline.

I don't mind maintaining that for a little while but it's obviously a lot of superfluous code and prone to mistakes when a larger team maintains it. I'll keep an eye on that issue, thanks for the link - good to know I'm not going crazy over here...

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 18, 2017, 9:47am UTC](https://discuss.elastic.co/t/conditional-statement-in-output/74672/7 "2017-03-18T09:47:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
