# Field reference from \_source for conditional output

**URL:** <https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [September 23, 2021, 3:46am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956 "2021-09-23T03:46:57Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![alfianaf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alfianaf/32/93192_2.png) [@alfianaf](https://discuss.elastic.co/u/alfianaf)\
**Post date:** [September 23, 2021, 4:32am UTC](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956/5 "2021-09-23T04:32:31Z")

</div>

I used the bottom one from you've recommended,  
sorry if my information before is not complete enough  
here was my config :

```auto
if "iris-uat" in [openshift][kubernetes][namespace_name] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-uat-%{+YYYY.MM}"
		}
	}
else if "iris" in [openshift][kubernetes][namespace_name] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-dev-%{+YYYY.MM}"
		}
	}

```

I think the anomaly happened because "iris" and "iris-uat" is counted as same because I used "in" conditional,  
rather I use "==" conditional to add tag and then use "in" conditional for the output

here's my code on my filter section:

```auto
		if [openshift][kubernetes][namespace_name] == "iris" {
			mutate { add_tag => "iris" }
		} else if [openshift][kubernetes][namespace_name] == "iris-uat" {
			mutate { add_tag => "iris-uat" }
		}

```

and this on my output section :

```auto
if "iris" in [tags] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-dev-%{+YYYY.MM}"
		}
	}
	else if "iris-uat" in [tags] {
		elasticsearch {
			hosts => ["xxx:9200"]
            index => "iris-uat-%{+YYYY.MM}"
		}
	}
    else {
        #stdout { codec => rubydebug }
        elasticsearch {
            hosts => ["xxx:9200"]
            index => "iris-new-%{+YYYY.MM}"
        }
    }

```

Now it is fixed, thanks for your explanation, because now I can clearly know how the syntax work

---

_[View the full topic](https://discuss.elastic.co/t/field-reference-from-source-for-conditional-output/284956)._
