# Else conditional in ingest pipeline

**URL:** <https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [October 14, 2021, 9:14am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697 "2021-10-14T09:14:08Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [October 14, 2021, 9:14am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/1 "2021-10-14T09:14:08Z")

</div>

Hello, I want to make else conditional on my ingest pipeline, here's pipeline I've made:

```auto
PUT _ingest/pipeline/pipeline-test
{
  "processors": [
    {
      "pipeline":{
        "description": "check field1 to output to pipeline1",
        "if": "ctx?.field1 == 'value1'",
        "name": "pipeline1"
      }
    },
    {
      "pipeline": {
        "description": "check field1 to output to pipeline2",
        "if": "ctx?.field1 == 'value2'",
        "name": "pipeline2"
      }
    },
    {
      "drop": {
        "description": "drop everything else",
        "if": "ctx?.field1 != 'value1' && ctx?.field1 != 'value2'"
      }
    }
    ]
}

```

is there any solution to make else conditional so I can drop everything except the field with value1 and value2. I don't want to add more parameter inside drop processor if someday I have to add more pipeline.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [October 15, 2021, 6:21am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/2 "2021-10-15T06:21:03Z")

</div>

anyone have insight about this?

---

<div class="post-metadata">

**Author:** ![zx8086](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zx8086/32/94917_2.png) [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Post date:** [October 15, 2021, 7:07am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/3 "2021-10-15T07:07:29Z")

</div>

Hi @alfianaf

If / Else statements can be used in the Logstash Modules like this example.

> **[Use ingest pipelines for parsing | Logstash Reference \[7.15\] | Elastic](https://www.elastic.co/guide/en/logstash/current/use-ingest-pipelines.html)**

Same applies with the filter module specifically

> **[Filter plugins | Logstash Reference \[7.15\] | Elastic](https://www.elastic.co/guide/en/logstash/current/filter-plugins.html)**

---

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [October 15, 2021, 7:11am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/4 "2021-10-15T07:11:10Z")

</div>

hello, sorry before, but I dont use logstash nor filebeat. I use ingest pipeline on my Elasticsearch directly, if you want to know the reference I used is from [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest.html#conditionally-run-processor)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 15, 2021, 3:45pm UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/5 "2021-10-15T15:45:17Z")

</div>

Hi @zx8086 I think @alfianaf is referring to ingest pipelines not logstash pipelines.

@alfianaf I am not exactly clear what you are asking.

Ingest pipelines are executed in order they are defined.

> [@alfianaf](#):
>
> is there any solution to make else conditional so I can drop everything except the field with value1 and value2. I don't want to add more parameter inside drop processor if someday I have to add more pipeline.

I am not exactly clear what you are asking can you show me "pseudo" code or something what you want to accomplish?

The `drop` processor will drop the entire message not just fields... so the above drop will drop every event that that `field1` is not `value1` or `value2`

if you are looking to drop all the fields except `field1` that is something completely different.

---

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [October 18, 2021, 2:17am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/6 "2021-10-18T02:17:09Z")

</div>

hello @stephenb , exactly I want to drop the entire message, so I want to use drop that works as much as "else", I want to drop every message else than those 2 pipeline, since I saw on documentation that drop pipeline use "if", what "if" in my "drop" pipeline can I put to get "else" behaviour?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 18, 2021, 3:13am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/7 "2021-10-18T03:13:26Z")

</div>

I'm still not completely sure What you want to do but there is no `else` at the top level processor control.

The `if` is actually inside each processor not outside... so there is no concept of `else` outside / above processor itself as far as I am aware.

---

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [October 18, 2021, 3:21am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/8 "2021-10-18T03:21:20Z")

</div>

if you watch carefully what I write on the pipeline I've made, I actually made "drop" pipeline to act as "else" from another 2 pipeline, I didn't really want to use "else" outside processor, but I just want to drop every document else than the 2 pipeline mentioned above. But it is too much if I have more than 2 pipeline, so I have to write much field on my "if" inside my "drop" pipeline

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 18, 2021, 3:49am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/9 "2021-10-18T03:49:30Z")

</div>

> [@alfianaf](#):
>
> I actually made "drop" pipeline to act as "else" from another 2 pipeline,

Agree, That is why I was a bit confused in the beginning because it seemed to be doing exactly what you were describing.

I'm just explaining that the conditionals are inside the processors not outside, there is no control flow outside the processors they are simply executed in order, And there is no `else` as requested in the title of the thread

---

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [October 18, 2021, 3:55am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/10 "2021-10-18T03:55:58Z")

</div>

I see, so it is not possible to do the thing I asked, thanks for your explanation

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 15, 2021, 3:56am UTC](https://discuss.elastic.co/t/else-conditional-in-ingest-pipeline/286697/11 "2021-11-15T03:56:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
