# Conditions in logstash

**URL:** <https://discuss.elastic.co/t/conditions-in-logstash/123063>\
**Category:** Logstash\
**Created:** [March 8, 2018, 12:35pm UTC](https://discuss.elastic.co/t/conditions-in-logstash/123063 "2018-03-08T12:35:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cilzzz](https://avatars.discourse-cdn.com/v4/letter/c/c67d28/32.png) [@cilzzz](https://discuss.elastic.co/u/cilzzz)\
**Post date:** [March 8, 2018, 12:35pm UTC](https://discuss.elastic.co/t/conditions-in-logstash/123063/1 "2018-03-08T12:35:47Z")

</div>

Hey everyone,

i have two fileds in a csv file dump\_status and upload\_status then i added a third field called return\_code. the values of upload\_status and dump\_status are copy complete and  
copy failed. what i need to is the assign 1 to return code when the two fields have copy complete as value and 0 to other conditions. here's my filter:

```
filter {
if [type] == "test_parser" {

csv {
    columns => ["dump","dump-status","copy","upload","up_status"]
    separator => ";"
    remove_field => ["dump","upload"]
    add_field => { "tech_return_code" => "-" }
}

if ([dump_status] == "Copy complete" and [up_status] == "Copy complete") {

mutate {
gsub => ["tech_return_code" , "-" , "1"]
}}
if ([dump_status] != "Copy complete" or [up_status] != "Copy complete") {

mutate {
gsub => ["tech_return_code" , "-" , "0"]
}}

mutate {
    convert => ["tech_return_code" , "integer"]
}

}}

```

it didn't worked when i am testing it with the 4 cases any help please

thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 8, 2018, 1:44pm UTC](https://discuss.elastic.co/t/conditions-in-logstash/123063/2 "2018-03-08T13:44:49Z")

</div>

What does an example event look like? Use a `stdout { codec => rubydebug }` output to dump the raw event.

---

<div class="post-metadata">

**Author:** ![cilzzz](https://avatars.discourse-cdn.com/v4/letter/c/c67d28/32.png) [@cilzzz](https://discuss.elastic.co/u/cilzzz)\
**Post date:** [March 8, 2018, 3:27pm UTC](https://discuss.elastic.co/t/conditions-in-logstash/123063/3 "2018-03-08T15:27:12Z")

</div>

![Capture](https://us1.discourse-cdn.com/elastic/original/3X/e/7/e7229afd40ce1948be4501976ab6235296219435.PNG)

i cannot run logstash in debug mode there is a problem in java path although i tried to export JAVA\_HOME to its right path but it didn't work although i tried

`output {stdout { codec => rubydebug }}` it didn't work. is my filter syntax correct?  
i am using logstash version 2.3.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2018, 3:27pm UTC](https://discuss.elastic.co/t/conditions-in-logstash/123063/4 "2018-04-05T15:27:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
