# Correct formatting for using OR and WHEN condition in a processor

**URL:** <https://discuss.elastic.co/t/correct-formatting-for-using-or-and-when-condition-in-a-processor/184640>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 6, 2019, 5:45pm UTC](https://discuss.elastic.co/t/correct-formatting-for-using-or-and-when-condition-in-a-processor/184640 "2019-06-06T17:45:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joseph\_Gange](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_gange/32/45922_2.png) [@Joseph\_Gange](https://discuss.elastic.co/u/Joseph_Gange)\
**Post date:** [June 6, 2019, 5:45pm UTC](https://discuss.elastic.co/t/correct-formatting-for-using-or-and-when-condition-in-a-processor/184640/1 "2019-06-06T17:45:21Z")

</div>

My filebeat config consists of the following relevant snippet-

> Blockquote

- decode\_json\_fields:  
when:  
contains:  
docker.container.labels.com.docker.swarm.service.name: "name"  
fields: ["message"]  
process\_array: false  
max\_depth: 1  
target: ""  
overwrite\_keys: false

> Blockquote

I need to add two additional service names so that I am parsing the nested json only for those services.

The configuration above works correctly for a single service name, but I can't seem to figure out how to add the additional terms.

I have tried passing in an array of service names like this-

> docker.container.labels.com.docker.swarm.service.name: "[service name1, service name 2, service name 3]"

but that didn't work.

I also tried adding an OR operator like this-

> when:  
> or:  
> - contains:  
> docker.container.labels.com.docker.swarm.service.name: "\<service name 1\>"  
> - contains:  
> docker.container.labels.com.docker.swarm.service.name: "\<service name 2\>"  
> - contains:  
> docker.container.labels.com.docker.swarm.service.name: "\<service name 3\>"

but that didn't work either.

Can someone provide the correct syntax to accomplish this?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Joseph\_Gange](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joseph_gange/32/45922_2.png) [@Joseph\_Gange](https://discuss.elastic.co/u/Joseph_Gange)\
**Post date:** [June 6, 2019, 7:28pm UTC](https://discuss.elastic.co/t/correct-formatting-for-using-or-and-when-condition-in-a-processor/184640/2 "2019-06-06T19:28:28Z")

</div>

OK, figured out the syntax, didn't have everything lined up properly.

```
- decode_json_fields:
when:
   or:
     - contains:
          docker.container.labels.com.docker.swarm.service.name: "a"
   or:
     - contains:
          docker.container.labels.com.docker.swarm.service.name: "b"
   or:
     - contains:
          docker.container.labels.com.docker.swarm.service.name: "c"

fields: ["message"]
process_array: false
max_depth: 1
target: ""
overwrite_keys: false

```

However, it appears that only the first condition is evaluated (service.name contains 'a') in terms of applying the decode actions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 4, 2019, 7:28pm UTC](https://discuss.elastic.co/t/correct-formatting-for-using-or-and-when-condition-in-a-processor/184640/3 "2019-07-04T19:28:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
