# Evaluate Multiple Strings in IF Statement

**URL:** <https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355>\
**Category:** Logstash\
**Created:** [April 1, 2018, 6:40pm UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355 "2018-04-01T18:40:33Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 1, 2018, 6:40pm UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/1 "2018-04-01T18:40:33Z")

</div>

I have an IF statement like below:  
`if "tobem" in [user][url] or "foocrypt" in [user][url] or "theautomatski" in [user][url]`

I also imagine that this is going to get a bit larger as time goes on and I identify more users I want to exclude. Is it possible to shorten it down at all, something like below?

`if ("value1"|"value2"|"value3") in [field]`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 1, 2018, 8:22pm UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/2 "2018-04-01T20:22:22Z")

</div>

Yes.

```auto
if [user][url] in ["tobem" , "foocrypt", "theautomatski"] ...

```

Alternatively

```auto
if [user][url] =~ "^(tobem|foocrypt|theautomatski)$" ...

```

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 1, 2018, 10:05pm UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/3 "2018-04-01T22:05:14Z")

</div>

The field name is `[user][url]` and the values are tobem, foocrypt, and theautomatski, which makes it seem like your first suggestion wouldn't work. The second one does not work. I also tried `if ["tobem", "foocrypt", "theautomatski"] in [user][url]` and got an error, `No implicit conversion of array into string`.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 1, 2018, 11:04pm UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/4 "2018-04-01T23:04:40Z")

</div>

The first one tests whether the value of field called [user][url] is a member of the array. I though that was what you wanted.

The second probably needs the anchors removed, or / characters added.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 1, 2018, 11:28pm UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/5 "2018-04-01T23:28:41Z")

</div>

Looks like the first one is what I wanted, it just reads weird to the novice (aka, me). Seems like it's saying if value user.url is in field tobem, foocrypt, or theautomatski but it appears I am wrong. Thanks for the help Badger.

EDIT: Nope, that doesn't work. Doesn't throw any errors but it also doesn't drop the events.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 2, 2018, 12:28am UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/6 "2018-04-02T00:28:40Z")

</div>

Can you show us an event? Either 'output { stdout { codec =\> rubydebug } }' or from the JSON tab in Kibana?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 2, 2018, 12:32am UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/7 "2018-04-02T00:32:21Z")

</div>

Line 15 into 16 is the user.url field containing `tobem`

```
{
  "_index": "inteltwit-2018.04.01",
  "_type": "doc",
  "_id": "OwSJg2IBPqHGZa-TOcIb",
  "_version": 1,
  "_score": null,
  "_source": {
    "timestamp_ms": "1522625270961",
    "links": [
      "https://t.co/0qKvlh5S2U",
      "https://t.co/Ov0ROPGcBk"
    ],
    "text_original": "This book is about a cyberwar with China. This new type of war, sa https://t.co/0qKvlh5S2U #Cybersecurity #Bitcoin https://t.co/Ov0ROPGcBk",
    "@timestamp": "2018-04-01T23:27:50.000Z",
    "user": {
      "url": "http://tobem.com/cyberwar",
      "id_str": "3875339716",
      "description": null,
      "screen_name": "CyberToolsBooks",
      "time_zone": null,
      "name": "CyberWar Books"
    },
    "hashtags": [
      "#cybersecurity",
      "#bitcoin"
    ],
    "mentioned": [],
    "extended_entities": {},
    "source": "<a href=\"http://www.ajaymatharu.com/\" rel=\"nofollow\">Tweet Old Post</a>",
    "text": "This book is about a cyberwar with China. This new type of war, sa "
  },
  "fields": {
    "timestamp_ms": [
      "2018-04-01T23:27:50.961Z"
    ],
    "@timestamp": [
      "2018-04-01T23:27:50.000Z"
    ]
  },
  "highlight": {
    "text_original": [
      "This @kibana-highlighted-field@book@/kibana-highlighted-field@ is about a cyberwar with China. This new type of war, sa https://t.co/0qKvlh5S2U #Cybersecurity #Bitcoin https://t.co/Ov0ROPGcBk"
    ],
    "text.stop_analyzed": [
      "This @kibana-highlighted-field@book@/kibana-highlighted-field@ is about a cyberwar with China. This new type of war, sa"
    ],
    "text": [
      "This @kibana-highlighted-field@book@/kibana-highlighted-field@ is about a cyberwar with China. This new type of war, sa"
    ]
  },
  "sort": [
    1522625270000
  ]
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 2, 2018, 12:51am UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/8 "2018-04-02T00:51:41Z")

</div>

> [@wwalker](#):
>
> "url": "[http://tobem.com/cyberwar](http://tobem.com/cyberwar)"

Testing if [field] in array is testing for string equality between the field and each of the members of the array. Thus "foo" in ["foo", "bar"] is true. However "foo" in ["foot", "hand"] is false.

If you want to drop events from a set of domains (and BTW, it would be helpful in general to provide a description of the problem you are trying to solve when you ask us to help with the solution 🙂 ) then something like like my second suggestion is more appropriate.

```auto
if [user][url] =~ "(tobem|foocrypt|theautomatski)"

```

might do it. Or perhaps

```auto
if [user][url] =~ "\b(tobem|foocrypt|theautomatski)\b"

```

to avoid matching [notfoocrypt.com](http://notfoocrypt.com). Personally I would parse the domain name out of the URL and then match against that to avoid possibly matching those strings against the URI.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [April 2, 2018, 1:24am UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/9 "2018-04-02T01:24:10Z")

</div>

First one appears to work.

`if [user][url] =~ "(tobem|foocrypt|theautomatski)"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2018, 1:37am UTC](https://discuss.elastic.co/t/evaluate-multiple-strings-in-if-statement/126355/10 "2018-04-30T01:37:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
