# Doing mathematical ops using logstash filters

**URL:** <https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058>\
**Category:** Logstash\
**Created:** [September 26, 2015, 10:07am UTC](https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058 "2015-09-26T10:07:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Udai\_Mehra](https://avatars.discourse-cdn.com/v4/letter/u/46a35a/32.png) [@Udai\_Mehra](https://discuss.elastic.co/u/Udai_Mehra)\
**Post date:** [September 26, 2015, 10:07am UTC](https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058/1 "2015-09-26T10:07:06Z")

</div>

Hi,  
I am facing a weired issue and need help of experts. I am trying to do numerical (INT) comparison in logstash filter file. Basically, I want to register only the haproxy events ( from its log file ) which take above 500ms of time\_duration and only those calls which are less than 1000Bytes. I am using following in the logstash filter. But I see the result as given below. For now I am only using mutate, but ultimately I want to drop those events from the log before passing to elasticsearch.

====logstash filter config====  
if 'time\_duration' \< '500' {  
mutate { add\_tag =\> ["FAST"] }  
#drop { }  
} else if 'time\_duration' \>= '500' {  
mutate { add\_tag =\> ["SLOW"] }  
mutate { add\_field =\> { "\_ttl" =\> '365d' } }  
}

For Main Haproxy

if [http\_request] =~ /(?i)cmr.php/ {  
drop { }  
}  
if 'bytes\_read' \> '1000' {  
mutate { add\_tag =\> ["big"] }  
#drop { }  
} else {  
mutate { add\_tag =\> ["small"] }  
}  
I am using haproxy config, which I don't think I need to print here. But for reference, the bytes\_read and the time\_duration are INT types.

The result that I get is this. Which clearly indicates that numerical comparison is not working. I tried putting the values in single ( ' ' ) quotes, in double quotes ( " " ). But nothing worked. I tried using the square brackets ( [] ) for the bytes\_read and time\_duration too. But nothing seems to work.  
Here is the snippet of the stdout rubydebug log.

```
      "time_duration" => "11",
    "http_status_code" => "200",
          "bytes_read" => "219",

```

"captured\_request\_cookie" =\> "-",  
"captured\_response\_cookie" =\> "-",  
"termination\_state" =\> "----",  
"actconn" =\> "3349",  
"feconn" =\> "1972",  
"beconn" =\> "13",  
"srvconn" =\> "1",  
"retries" =\> "0",  
"srv\_queue" =\> "0",  
"backend\_queue" =\> "0",  
"captured\_request\_headers" =\> "text/html",  
"http\_verb" =\> "GET",  
"http\_request" =\> "/campaign/rtb/adx/cmradc.php?vid=4613155667517436106",  
"http\_version" =\> "1.1",  
"tags" =\> [  
[0] "SUCCESS",  
[1] "SLOW",  
[2] "big"  
],  
"\_ttl" =\> [  
[0] "5d",  
[1] "365d"  
],  
I would really appreciate if someone can send me some pointers to fix this issue.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 26, 2015, 10:50am UTC](https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058/2 "2015-09-26T10:50:20Z")

</div>

> if 'time\_duration' \< '500' {  
> mutate { add\_tag =\> ["FAST"]  
> }

Two problems:

- Fields are referred via the square bracket notation, i.e. `[time_duration]` in this case.
- You need fields to be integers (or doubles) for numerical comparisons to work. See below.

> I am using haproxy config, which I don't think I need to print here. But for reference, the bytes\_read and the time\_duration are INT types.

No, they're strings. That's obvious from the stdout output. The fact that a grok expression uses the predefined INT pattern merely means that the input string will be matched if it's an integer. The result will still be a string unless you add `:int`, i.e. `%{INT:time_duration:int}`. If you don't want to modify the original grok patterns you can use the mutate filter's convert option to convert string fields to integer or double fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:27am UTC](https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058/3 "2017-07-06T05:27:57Z")

</div>


