# Filtering in LogStash using the if..in syntax

**URL:** <https://discuss.elastic.co/t/filtering-in-logstash-using-the-if-in-syntax/213090>\
**Category:** Logstash\
**Created:** [December 26, 2019, 3:17pm UTC](https://discuss.elastic.co/t/filtering-in-logstash-using-the-if-in-syntax/213090 "2019-12-26T15:17:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RunningSmurf](https://avatars.discourse-cdn.com/v4/letter/r/0ea827/32.png) [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Post date:** [December 26, 2019, 3:17pm UTC](https://discuss.elastic.co/t/filtering-in-logstash-using-the-if-in-syntax/213090/1 "2019-12-26T15:17:34Z")

</div>

Hello,

I want to update the "tags" filed to a certain value when my "message" contains the string "Error: 18456" in it.

This is the [message] value that ends up in Kibana:  
message 2019-12-26 15:07:09.53 Logon Error: 18456, Severity: 14, State: 8.

This is my filter in Logstash:  
filter {  
if "Error: 18456" in [message] {  
mutate {  
update =\> { "tags" =\> "Error - Login failed"}  
}  
}  
}

I do not get any error when running this configuration, but the "tags" field does not get updated. Do you see a syntax or logic error in my code? Thank you!

Sincerely,

RS

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 26, 2019, 4:40pm UTC](https://discuss.elastic.co/t/filtering-in-logstash-using-the-if-in-syntax/213090/2 "2019-12-26T16:40:40Z")

</div>

If the tags field does not exist then update will not create it.

---

<div class="post-metadata">

**Author:** ![RunningSmurf](https://avatars.discourse-cdn.com/v4/letter/r/0ea827/32.png) [@RunningSmurf](https://discuss.elastic.co/u/RunningSmurf)\
**Post date:** [December 26, 2019, 7:42pm UTC](https://discuss.elastic.co/t/filtering-in-logstash-using-the-if-in-syntax/213090/3 "2019-12-26T19:42:53Z")

</div>

Hello Badger,

Thank you for your reply. The "tags" field indeed exists. In other filters, I am able to update "tags" on a "if in " statement. The only difference is that the other filters go against fields other than [message]. I am wondering if there is something special about the fact that I am going against the [message] field, which is incidentally of type \_doc.

Sincerely,

RS

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 23, 2020, 7:42pm UTC](https://discuss.elastic.co/t/filtering-in-logstash-using-the-if-in-syntax/213090/4 "2020-01-23T19:42:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
