# Field reference from \_source for conditional output

**URL:** <https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [September 23, 2021, 3:46am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956 "2021-09-23T03:46:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [September 23, 2021, 3:46am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/1 "2021-09-23T03:46:57Z")

</div>

hello, I'm new to logstash conditional, I want to make different index output based on some field reference on my logstash

here is my index example :

```auto
{
  "_index": "iris-new-2021.09",
  "_type": "_doc",
  "_id": "EKS5EHwBUrXRxI7i7tvA",
  "_version": 1,
  "_score": null,
  "_source": {
    "input": {
      "type": "syslog"
    },
    "@timestamp": "2021-09-23T03:36:30.421Z",
    "tags": [
      "beats_input_codec_plain_applied"
    ],
    "openshift": {
      "message": "\tat com.zaxxer.hikari.pool.HikariPool.checkFailFast(HikariPool.java:554)",
      "level": "unknown",
      "viaq_msg_id": "YTlkYzdhNzItM2U2NC00NmRiLWFmZTItNDc2M2FiZWExZTJj",
      "kubernetes": {
        "container_image_id": "image-registry.openshift-image-registry.svc:5000/iris-uat/iris-batch-swcon-prod@sha256:d4d74861c96f728af3cb953aa77e0f4c7d220541fb82a048a76f546b4e5a3c94",
        "pod_id": "96a3657c-a2e7-4918-9f83-10be97123270",
        "container_name": "iris-batch-swcon-prod",
        "master_url": "https://kubernetes.default.svc",
        "container_image": "image-registry.openshift-image-registry.svc:5000/iris-uat/iris-batch-swcon-prod@sha256:d4d74861c96f728af3cb953aa77e0f4c7d220541fb82a048a76f546b4e5a3c94",
        "host": "devocpworker04.ocpdev.dti.co.id",
        "pod_name": "iris-batch-swcon-prod-1-s57zc",
        "flat_labels": [
          "app=iris-batch-swcon-prod",
          "deployment=iris-batch-swcon-prod-1",
          "deploymentconfig=iris-batch-swcon-prod"
        ],
        "namespace_name": "iris-uat",
        "namespace_id": "0da8b310-ceaf-4446-a645-11f3b792d572"
      },
      "pipeline_metadata": {
        "collector": {
          "ipaddr4": "10.58.81.34",
          "name": "fluentd",
          "version": "1.7.4 1.6.0",
          "received_at": "2021-08-01T03:23:39.492821+00:00",
          "inputname": "fluent-plugin-systemd"
        }
      },
      "docker": {
        "container_id": "5001c9085439a436eb3ef1f146b0e390003e01f93dda1a269b9d2fae3a8a4286"
      },
      "hostname": "devocpworker04.ocpdev.dti.co.id",
      "@timestamp": "2021-08-01T03:23:38.794143+00:00"
    }
  },
  "fields": {
    "openshift.@timestamp": [
      "2021-08-01T03:23:38.794Z"
    ],
    "openshift.pipeline_metadata.collector.received_at": [
      "2021-08-01T03:23:39.492Z"
    ],
    "@timestamp": [
      "2021-09-23T03:36:30.421Z"
    ]
  },
  "sort": [
    1632368190421
  ]
}

```

I want to use [\_source][openshift][kubernetes][namespace\_name] as reference to make index output

here's what I've tried :  
1.

```auto
if "iris-uat" in "%{[openshift][kubernetes][namespace_name]}" {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-uat-%{+YYYY.MM}"
		}
	}

```

1. 

```auto
if "iris-uat" in "[openshift][kubernetes][namespace_name]" {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-uat-%{+YYYY.MM}"
		}
	}

```

1. 

```auto
if "iris-uat" in [openshift][kubernetes][namespace_name] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-uat-%{+YYYY.MM}"
		}
	}

```

am I missing something, I've also tried delete the [openshift] and only use the rest of sub field instead, but I still couldn't get the output

feel free to ask for more information regarding my question if you don't understand about what I'm asking

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 23, 2021, 4:11am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/2 "2021-09-23T04:11:49Z")

</div>

> [@alfianaf](#):
>
> here's what I've tried :

> if "iris-uat" in "%{[openshift][kubernetes][namespace\_name]}" {

You [cannot](https://discuss.elastic.co/t/logstash-if-condition/250689/2) use a sprintf reference in a conditional. This is a substring match.

> if "iris-uat" in "[openshift][kubernetes][namespace\_name]" {

That is a also substring match against a string, so `if "ift][kuber" in "[openshift][kubernetes][namespace_name]" {` would evaluate to true, but that never will.

> if "iris-uat" in [openshift][kubernetes][namespace\_name] {

I would expect that to work. Instead of showing us the result from an index search can you show us an event output from logstash with

```
output { stdout { codec => rubydebug } }

```

---

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [September 23, 2021, 4:15am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/3 "2021-09-23T04:15:41Z")

</div>

fyi, I make a else conditional to output to other index, from every conditional I've used, it is forwarded to the "else" condition, so to make it clear, the "if" condition was not met

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 23, 2021, 4:19am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/4 "2021-09-23T04:19:34Z")

</div>

Yes, I understood that. It is an unexpected result. That is why I asked for additional data.

---

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [September 23, 2021, 4:32am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/5 "2021-09-23T04:32:31Z")

</div>

I used the bottom one from you've recommended,  
sorry if my information before is not complete enough  
here was my config :

```auto
if "iris-uat" in [openshift][kubernetes][namespace_name] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-uat-%{+YYYY.MM}"
		}
	}
else if "iris" in [openshift][kubernetes][namespace_name] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-dev-%{+YYYY.MM}"
		}
	}

```

I think the anomaly happened because "iris" and "iris-uat" is counted as same because I used "in" conditional,  
rather I use "==" conditional to add tag and then use "in" conditional for the output

here's my code on my filter section:

```auto
		if [openshift][kubernetes][namespace_name] == "iris" {
			mutate { add_tag => "iris" }
		} else if [openshift][kubernetes][namespace_name] == "iris-uat" {
			mutate { add_tag => "iris-uat" }
		}

```

and this on my output section :

```auto
if "iris" in [tags] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-dev-%{+YYYY.MM}"
		}
	}
	else if "iris-uat" in [tags] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-uat-%{+YYYY.MM}"
		}
	}
    else {
        #stdout { codec => rubydebug }
        elasticsearch {
            hosts => ["xxx:9200"]
            index => "iris-new-%{+YYYY.MM}"
        }
    }

```

Now it is fixed, thanks for your explanation, because now I can clearly know how the syntax work

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2021, 4:33am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/6 "2021-10-21T04:33:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
