# Filter if condition in Logstash

**URL:** <https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484>\
**Category:** Logstash\
**Created:** [June 26, 2019, 6:34am UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484 "2019-06-26T06:34:22Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Laurent\_Beretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laurent_beretti/32/48089_2.png) [@Laurent\_Beretti](https://discuss.elastic.co/u/Laurent_Beretti)\
**Post date:** [June 26, 2019, 6:34am UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/1 "2019-06-26T06:34:22Z")

</div>

Hello,

I'm new in Elastic and now I'm trying to modify fields with if condition, but it doesn't work.  
Note that I've no error after restarting Logstash.  
I just want to create a new field (this part is ok) and then I want to update or replace (don't know the best way) my new field.  
Here is my filter :

```
filter {
  mutate {
  add_field => { "port.name" => "Port name" }
  }
  if (url.port) == "13000" {
    mutate {
    replace => { [port.name] => "Kaspersky" }
    }
  }
}

```

Someone can help me ???? Please.

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [June 26, 2019, 12:03pm UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/2 "2019-06-26T12:03:05Z")

</div>

Hi,

Can you update your if condition as below and check If it works

```
  if([url][port]== "13000"){
    mutate {
    replace => { [port][name] => "Kaspersky" }
    }
  }
```

---

<div class="post-metadata">

**Author:** ![Laurent\_Beretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laurent_beretti/32/48089_2.png) [@Laurent\_Beretti](https://discuss.elastic.co/u/Laurent_Beretti)\
**Post date:** [June 26, 2019, 12:29pm UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/3 "2019-06-26T12:29:12Z")

</div>

Thanks for your help, but it doesn't work.  
I also tried to write if condition like this :

```
if("[url][port]" == "13000"){
    mutate {
    replace => { "[port][name]" => "Kaspersky" }
    }
  }

```

by adding " but not better.

An other try I made was :

```
if("[url][port]"== 13000){
    mutate {
    replace => { "[port][name]" => "Kaspersky" }
    }
  }

```

by deleting the " of 13000 because the field url.port is an integer.

I'm turning around...

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [June 26, 2019, 12:36pm UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/4 "2019-06-26T12:36:15Z")

</div>

Please provide your input data, so that I can try on my side too

---

<div class="post-metadata">

**Author:** ![Laurent\_Beretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laurent_beretti/32/48089_2.png) [@Laurent\_Beretti](https://discuss.elastic.co/u/Laurent_Beretti)\
**Post date:** [June 26, 2019, 12:40pm UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/5 "2019-06-26T12:40:01Z")

</div>

Do you want the JSON from Kibana ?

```
{
  "_index": "heartbeat-2019.06.26",
  "_type": "_doc",
  "_id": "9mXRk2sBZ5JtzLdILpq2",
  "_score": 1,
  "_source": {
    "url": {
      "full": "tcp://example.net:13000",
      "scheme": "tcp",
      "domain": "example.net",
      "port": 13000
    },
    "@timestamp": "2019-06-26T12:44:47.044Z",
    "host": {
      "os": {
        "kernel": "4.18.0-21-generic",
        "name": "Ubuntu",
        "platform": "ubuntu",
        "version": "18.04.2 LTS (Bionic Beaver)",
        "codename": "bionic",
        "family": "debian"
      },
      "name": "example",
      "id": "123699f28ff345a28ecf7cc208e6a543",
      "architecture": "x86_64",
      "containerized": false,
      "hostname": "example"
    },
    "resolve": {
      "rtt": {
        "us": 2375
      },
      "ip": "192.168.1.2"
    },
    "ecs": {
      "version": "1.0.0"
    },
    "monitor": {
      "name": "",
      "status": "up",
      "type": "tcp",
      "duration": {
        "us": 4186
      },
      "id": "auto-tcp-0X28C61C257AAC6812-530d2ef90fbce828",
      "check_group": "0a424351-9810-11e9-a811-00155de82c05",
      "ip": "192.168.1.2"
    },
    "portname": "port name",
    "event": {
      "dataset": "uptime"
    },
    "@version": "1",
    "tcp": {
      "rtt": {
        "connect": {
          "us": 1755
        }
      }
    },
    "tags": [
      "beats_input_raw_event"
    ],
    "agent": {
      "id": "ebcd1dd7-9ac3-4695-b470-3ed56228d332",
      "ephemeral_id": "23b63eff-e498-437c-b0a5-714759fb13f6",
      "hostname": "example",
      "type": "heartbeat",
      "version": "7.1.1"
    },
    "summary": {
      "down": 0,
      "up": 1
    }
  },
  "fields": {
    "@timestamp": [
      "2019-06-26T12:44:47.044Z"
    ]
  }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2019, 12:50pm UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/6 "2019-06-26T12:50:02Z")

</div>

Try

```
if [url][port] == 13000 {
```

---

<div class="post-metadata">

**Author:** ![Laurent\_Beretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laurent_beretti/32/48089_2.png) [@Laurent\_Beretti](https://discuss.elastic.co/u/Laurent_Beretti)\
**Post date:** [June 26, 2019, 12:55pm UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/7 "2019-06-26T12:55:38Z")

</div>

Not better.  
When I try like you said, no log is send to Kibana.  
I must write like this with the quotes :

```
if "[url][port]" == 13000 {
```

---

<div class="post-metadata">

**Author:** ![Laurent\_Beretti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/laurent_beretti/32/48089_2.png) [@Laurent\_Beretti](https://discuss.elastic.co/u/Laurent_Beretti)\
**Post date:** [June 26, 2019, 1:01pm UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/8 "2019-06-26T13:01:29Z")

</div>

I appologize, I forgot to delete a bracket...oups  
Now it works !!!

Thank you @Badger you solved my problem. Also thanks to @sjabiulla for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 1:02pm UTC](https://discuss.elastic.co/t/filter-if-condition-in-logstash/187484/9 "2019-07-24T13:02:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
