# Config Map condition based on the log event on child element

**URL:** <https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213>\
**Category:** Logstash\
**Created:** [February 22, 2023, 7:04pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213 "2023-02-22T19:04:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rravitech](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rravitech/32/108994_2.png) [@rravitech](https://discuss.elastic.co/u/rravitech)\
**Post date:** [February 22, 2023, 7:04pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213/1 "2023-02-22T19:04:02Z")

</div>

Here is what i am trying to achieve.

Below is my log event

```auto
 {
		  "version" : "1.0.0",
          "message" : "noisemaker draftsmanship's soundproofing grads werewolf's",
          "@version" : "1",
          "logplane" : "logs-lj",
          "pipeline_data" : [
            {
              "lumberjack_ext_lj_1" : 6
            },
            {
              "lumberjack_ext_lj_2" : 6
            }
          ],
          "@timestamp" : "2023-02-22T18:54:36.515Z"
        }

```

And here is my config map. i know that the pipeline\_data is an array, but how can I add a condition out of the child elements in that.

```auto

 if [pipeline_data][lumberjack_ext_lj_1] {
       if [pipeline_data][lumberjack_ext_lj_1] > 120 {
          exec {
            command => ""
          }
          pipeline { send_to => "droppipeline" }
        }
  {{- end }}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 22, 2023, 7:14pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213/2 "2023-02-22T19:14:33Z")

</div>

You need to access it using the index on the array, like `[pipeline_data][0][lumberjack_ext_lj_1]`.

But if the index in the array can change you may need to transform your data like using a `split` filter to create a new document for each item in the array, or writing a ruby script to create a new dynamic field for each item in the array.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2023, 8:28pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213/3 "2023-02-22T20:28:59Z")

</div>

> [@rravitech](#):
>
> ```auto
> if [pipeline_data][lumberjack_ext_lj_1] > 120 {
> exec {
> command => ""
> }
> 
> ```

There is no exec filter, you will have to do that in ruby.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 22, 2023, 8:34pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213/4 "2023-02-22T20:34:37Z")

</div>

> [@Badger](#):
>
> There is no exec filter, you will have to do that in ruby.

If I'm not wrong this is in the output block, since there is a `pipeline` output after the `exec`, which is a output plugin.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2023, 10:09pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213/5 "2023-02-22T22:09:24Z")

</div>

I think you are right. My mistake!

I did not know there was an exec output. I cannot imagine wanting to fork the JVM and exec another command for each event. It's going to be really expensive.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2023, 10:09pm UTC](https://discuss.elastic.co/t/config-map-condition-based-on-the-log-event-on-child-element/326213/6 "2023-03-22T22:09:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
