# Filter the values based on particular string in Logstash

**URL:** <https://discuss.elastic.co/t/filter-the-values-based-on-particular-string-in-logstash/375717>\
**Category:** Logstash\
**Created:** [March 11, 2025, 2:51pm UTC](https://discuss.elastic.co/t/filter-the-values-based-on-particular-string-in-logstash/375717 "2025-03-11T14:51:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gowtham1](https://avatars.discourse-cdn.com/v4/letter/g/4da419/32.png) [@Gowtham1](https://discuss.elastic.co/u/Gowtham1)\
**Post date:** [March 11, 2025, 2:51pm UTC](https://discuss.elastic.co/t/filter-the-values-based-on-particular-string-in-logstash/375717/1 "2025-03-11T14:51:56Z")

</div>

Hi,

We have a field named "AP\_NAME" this field value contains a common names like WIRAP and WIRWM but some additional names also coming to this field so I want put a condition in logstash to get only this particular WIRAP and WIRWM naming values in the field "AP\_NAME"

Regards  
Gowtham S

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2025, 3:24pm UTC](https://discuss.elastic.co/t/filter-the-values-based-on-particular-string-in-logstash/375717/2 "2025-03-11T15:24:09Z")

</div>

You could try

```
    if [APP_NAME] not in ["WIRAP", "WIRWM"] {
        #mutate { remove_field => ["APP_NAME"] }
        mutate { replace => { "APP_NAME" => "-" } }
    }

```

---

<div class="post-metadata">

**Author:** ![Gowtham1](https://avatars.discourse-cdn.com/v4/letter/g/4da419/32.png) [@Gowtham1](https://discuss.elastic.co/u/Gowtham1)\
**Post date:** [March 11, 2025, 5:56pm UTC](https://discuss.elastic.co/t/filter-the-values-based-on-particular-string-in-logstash/375717/3 "2025-03-11T17:56:24Z")

</div>

We need to put # in the second line.Please confirm once.  
if [APP\_NAME] not in ["WIRAP", "WIRWM"] {  
#mutate { remove\_field =\> ["APP\_NAME"] }  
mutate { replace =\> { "APP\_NAME" =\> "-" } }  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2025, 6:19pm UTC](https://discuss.elastic.co/t/filter-the-values-based-on-particular-string-in-logstash/375717/4 "2025-03-11T18:19:53Z")

</div>

You need to decide what to do with events where APP\_NAME is not one of the values you want to keep.

Do you want to delete the field? In that case uncomment the first mutate and delete the second.

Or do you want a default value? In which case delete the first (commented) mutate, and pick an appropriate default value in the second.

---

<div class="post-metadata">

**Author:** ![Gowtham1](https://avatars.discourse-cdn.com/v4/letter/g/4da419/32.png) [@Gowtham1](https://discuss.elastic.co/u/Gowtham1)\
**Post date:** [March 11, 2025, 6:27pm UTC](https://discuss.elastic.co/t/filter-the-values-based-on-particular-string-in-logstash/375717/5 "2025-03-11T18:27:52Z")

</div>

We need only the value which contains WIRAP and WIRWM don't need the remaining values in the AP\_NAME field so will go with the below one and remove the values which not conains WIRAP and WIRWM in the AP\_NAME field.

if [APP\_NAME] not in ["WIRAP", "WIRWM"] {  
mutate { remove\_field =\> ["APP\_NAME"] }
