# Doing mathematical ops using logstash filters

**URL:** https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058
**Category:** Logstash
**Created:** [September 26, 2015, 10:07am UTC](https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058 "2015-09-26T10:07:06Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 26, 2015, 10:50am UTC](https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058/2 "2015-09-26T10:50:20Z")

</div>

> if 'time\_duration' \< '500' {  
> mutate { add\_tag =\> ["FAST"]  
> }

Two problems:

- Fields are referred via the square bracket notation, i.e. `[time_duration]` in this case.
- You need fields to be integers (or doubles) for numerical comparisons to work. See below.

> I am using haproxy config, which I don't think I need to print here. But for reference, the bytes\_read and the time\_duration are INT types.

No, they're strings. That's obvious from the stdout output. The fact that a grok expression uses the predefined INT pattern merely means that the input string will be matched if it's an integer. The result will still be a string unless you add `:int`, i.e. `%{INT:time_duration:int}`. If you don't want to modify the original grok patterns you can use the mutate filter's convert option to convert string fields to integer or double fields.

---

_[View the full topic](https://discuss.elastic.co/t/doing-mathematical-ops-using-logstash-filters/30058)._
