# Efficient way of doing a complex conditional compare

**URL:** <https://discuss.elastic.co/t/efficient-way-of-doing-a-complex-conditional-compare/99808>\
**Category:** Logstash\
**Created:** [September 8, 2017, 7:27am UTC](https://discuss.elastic.co/t/efficient-way-of-doing-a-complex-conditional-compare/99808 "2017-09-08T07:27:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 8, 2017, 7:27am UTC](https://discuss.elastic.co/t/efficient-way-of-doing-a-complex-conditional-compare/99808/1 "2017-09-08T07:27:57Z")

</div>

I have a range of ranges I want to check an integer field against and I want to do something like `if "value" > 100 and "value" < "300" and "value" > "600" and "value" < "700"`. And repeat that across 6 sets of ranges.

I can just write the above out 6 times, but it seems super inefficient, if anyone has pointers on a better structure it'd be appreciated 🙂

(Also I thought of a translate table, but that seems just as painful given it'll be ~8000 unique values to compare against!)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 8, 2017, 8:23am UTC](https://discuss.elastic.co/t/efficient-way-of-doing-a-complex-conditional-compare/99808/2 "2017-09-08T08:23:29Z")

</div>

The translate plugin does support [regular expressions](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-regex), so that might shrink the config a bit.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 8, 2017, 8:52am UTC](https://discuss.elastic.co/t/efficient-way-of-doing-a-complex-conditional-compare/99808/3 "2017-09-08T08:52:12Z")

</div>

Ahh, thanks!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 8, 2017, 9:00am UTC](https://discuss.elastic.co/t/efficient-way-of-doing-a-complex-conditional-compare/99808/4 "2017-09-08T09:00:56Z")

</div>

How much it shrinks it and how efficient it is I guess depend on what your ranges look like.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 6, 2017, 9:11am UTC](https://discuss.elastic.co/t/efficient-way-of-doing-a-complex-conditional-compare/99808/5 "2017-10-06T09:11:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
