# Defining "if - elseif - else" when setting up processors?

**URL:** <https://discuss.elastic.co/t/defining-if-elseif-else-when-setting-up-processors/200725>\
**Category:** Beats\
**Tags:** functionbeat\
**Created:** [September 23, 2019, 3:54pm UTC](https://discuss.elastic.co/t/defining-if-elseif-else-when-setting-up-processors/200725 "2019-09-23T15:54:56Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![TheSwede86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theswede86/32/52444_2.png) [@TheSwede86](https://discuss.elastic.co/u/TheSwede86)\
**Post date:** [September 23, 2019, 3:54pm UTC](https://discuss.elastic.co/t/defining-if-elseif-else-when-setting-up-processors/200725/1 "2019-09-23T15:54:56Z")

</div>

Hi,

Some context:  
AWS  
Log Group: MyLogGroupForEC2s  
Log Streams:  
myhost1-System #EventViewer  
myhost1-Application #EventViewer  
myhost1-CloudWatchAgent #CustomLogTxt  
and many more for the fictious "myhost1" and A LOT of different hosts.

CloudWatchAgent sends the entire raw EventViewer-event as XML into the "message"-field, OK so lets try and define a "processor" to dissect the message field but here is also my problem;

The EventViewer Application-log has the following field for EventID;  
`<EventID Qualifiers='.'>(.*?)<\/EventID>`  
While all other EventViewer-logs have the following field for EventID;  
`<EventID>(.*?)<\/EventID>`  
and as stated somewhere in the documentation regarding this, if a field is not found then no processing will occur so we need to differentiate between;  
The EventViewer Application-log (w. "Qualifiers")  
All other EventViewer-logs (w.o "Qualifiers")  
and the custom txt-logs.

I seem to be missing a third option (i.e. "if-else") to do this if I am grasping this correctly;

```
- if:
    equal:
        - regexp:
            log_stream: "*-Application"
  then:
    - dissect:
        tokenizer: "<Computer>(.*?)<\/Computer>"
        field: "message"
        target_prefix: "Computer"
    - dissect:
        tokenizer: "<Message>(.*?)<\/Message>"
        field: "message"
        target_prefix: "EventID Message"
    - dissect:
        tokenizer: "<Channel>(.+?)<\/Channel>"
        field: "message"
        target_prefix: "Channel"
     - dissect:
        tokenizer: "<Level>(.+?)<\/Level>"
        field: "message"
        target_prefix: "Level"
     - dissect:
        tokenizer: "<EventID Qualifiers='.'>(.*?)<\/EventID>"
        field: "message"
        target_prefix: "EventID"

```

The above section would catch all log-streams that end with "-Application" but then I need to take into account all other EventViewer-logs (that are without "Qualifiers") and another section to parse / dissect the custom .txt-logs such as the CloudWatchAgent-logs.

It's easier for me to handle the exceptions from the "norm" of "EventID" rather then specify all the logs that should be parsed confirming to "EventID".

Might I be better off using Logstash instead of trying to define this process in Functionbeat?

Thank you in advance for any suggestions / help - TheSwede86

Update: Oh and I know the regex I wrote don't work since it uses reserved characters, need to figure that out but thats another issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2019, 5:55am UTC](https://discuss.elastic.co/t/defining-if-elseif-else-when-setting-up-processors/200725/2 "2019-10-14T05:55:10Z")

</div>

This topic was automatically closed 20 days after the last reply. New replies are no longer allowed.
