# Help adding field if a condition exists

**URL:** <https://discuss.elastic.co/t/help-adding-field-if-a-condition-exists/85134>\
**Category:** Logstash\
**Created:** [May 9, 2017, 4:49pm UTC](https://discuss.elastic.co/t/help-adding-field-if-a-condition-exists/85134 "2017-05-09T16:49:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tim\_Flowers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_flowers/32/18081_2.png) [@Tim\_Flowers](https://discuss.elastic.co/u/Tim_Flowers)\
**Post date:** [May 9, 2017, 4:49pm UTC](https://discuss.elastic.co/t/help-adding-field-if-a-condition-exists/85134/1 "2017-05-09T16:49:14Z")

</div>

Noob to logstash here, I am trying to do something that I thought would be easy but I am having trouble. I just want to add a field if the syslog\_hostname equals a string or ip address. Here is what I have and when i use this logstash will crash.

filter {  
if [syslog\_hostname] == "10.145.252.1" {  
mutate {  
add\_field =\> { "vendor", "some\_vendor" }  
}  
}  
}

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![orhiee](https://avatars.discourse-cdn.com/v4/letter/o/eb9ed0/32.png) [@orhiee](https://discuss.elastic.co/u/orhiee)\
**Post date:** [May 9, 2017, 5:19pm UTC](https://discuss.elastic.co/t/help-adding-field-if-a-condition-exists/85134/2 "2017-05-09T17:19:11Z")

</div>

it shout be like

add\_field =\> ["received\_at", "ssss"]

---

<div class="post-metadata">

**Author:** ![Tim\_Flowers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_flowers/32/18081_2.png) [@Tim\_Flowers](https://discuss.elastic.co/u/Tim_Flowers)\
**Post date:** [May 9, 2017, 5:57pm UTC](https://discuss.elastic.co/t/help-adding-field-if-a-condition-exists/85134/3 "2017-05-09T17:57:22Z")

</div>

I did try it with the [] instead of the { } and had the same issue. The only way I can modify this to not crash logstash is:

filter {  
if [syslog\_hostname] == "10.145.252.1" {  
mutate {  
add\_field =\> ["vendor", "some\_vendor"]  
}  
}  
}

Unfortunately the filter does not work when I do that. The error I get in my log files when I do have it configured like above is:

Error: Expected one of #, in, not , ==, !=, \<=, \>=, \<, \>, =~, !~, and, or, xor, nand, { at line 483, column 26 (byte 11065) after filter {\n if [type] == "syslog" {\n grok {\n match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:\[%{POSINT:syslog\_pid}\])?: %{GREEDYDATA:syslog\_message}" }\n add\_field =\> ["received\_at", "%{@timestamp}"]\n add\_field =\> ["received\_from", "%{host}"]\n }\n date {\n match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]\n }\n\n if [syslog\_hostname] ", :level=\>:error}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 9, 2017, 6:21pm UTC](https://discuss.elastic.co/t/help-adding-field-if-a-condition-exists/85134/4 "2017-05-09T18:21:57Z")

</div>

Please show your full configuration.

---

<div class="post-metadata">

**Author:** ![Tim\_Flowers](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_flowers/32/18081_2.png) [@Tim\_Flowers](https://discuss.elastic.co/u/Tim_Flowers)\
**Post date:** [May 9, 2017, 6:36pm UTC](https://discuss.elastic.co/t/help-adding-field-if-a-condition-exists/85134/5 "2017-05-09T18:36:38Z")

</div>

I found the issue, I had one too many } at the end. Thanks for looking at this guys, I guess I just need to step away from the computer for a few minutes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2017, 6:46pm UTC](https://discuss.elastic.co/t/help-adding-field-if-a-condition-exists/85134/6 "2017-06-06T18:46:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
