# Field reference from \_source for conditional output

**URL:** <https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [September 23, 2021, 3:46am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956 "2021-09-23T03:46:57Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 23, 2021, 4:11am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/2 "2021-09-23T04:11:49Z")

</div>

> [@alfianaf](#):
>
> here's what I've tried :

> if "iris-uat" in "%{[openshift][kubernetes][namespace\_name]}" {

You [cannot](https://discuss.elastic.co/t/logstash-if-condition/250689/2) use a sprintf reference in a conditional. This is a substring match.

> if "iris-uat" in "[openshift][kubernetes][namespace\_name]" {

That is a also substring match against a string, so `if "ift][kuber" in "[openshift][kubernetes][namespace_name]" {` would evaluate to true, but that never will.

> if "iris-uat" in [openshift][kubernetes][namespace\_name] {

I would expect that to work. Instead of showing us the result from an index search can you show us an event output from logstash with

```
output { stdout { codec => rubydebug } }

```

---

_[View the full topic](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956)._
