# How can I access an element in a list by index in Logstash?

**URL:** <https://discuss.elastic.co/t/how-can-i-access-an-element-in-a-list-by-index-in-logstash/199028>\
**Category:** Logstash\
**Created:** [September 11, 2019, 7:29am UTC](https://discuss.elastic.co/t/how-can-i-access-an-element-in-a-list-by-index-in-logstash/199028 "2019-09-11T07:29:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gitreseteasy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitreseteasy/32/54026_2.png) [@gitreseteasy](https://discuss.elastic.co/u/gitreseteasy)\
**Post date:** [September 11, 2019, 7:29am UTC](https://discuss.elastic.co/t/how-can-i-access-an-element-in-a-list-by-index-in-logstash/199028/1 "2019-09-11T07:29:20Z")

</div>

I want to dynamically route my logs based on the strings in the tags of an event. I can't find any documentation for accessing an index of a list. Is this possible? If so, where can I find documentation on proper syntax?

```
input {}
filter {}
output {
    if "thisIsABackendApp" in [tags] {
          pipeline {
          ## send_to => "${tags[1]}" ???
         }
    }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 11, 2019, 12:28pm UTC](https://discuss.elastic.co/t/how-can-i-access-an-element-in-a-list-by-index-in-logstash/199028/2 "2019-09-11T12:28:27Z")

</div>

> [@gitreseteasy](#):
>
> "${tags[1]}"

You can index into an array using "%{[tags][1]}", however, that requires that the reference be a place where a filter or output sprintf's the value of an option, and if I recall correctly, a pipeline output does not sprintf the name of the pipeline.

---

<div class="post-metadata">

**Author:** ![gitreseteasy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitreseteasy/32/54026_2.png) [@gitreseteasy](https://discuss.elastic.co/u/gitreseteasy)\
**Post date:** [September 12, 2019, 2:11am UTC](https://discuss.elastic.co/t/how-can-i-access-an-element-in-a-list-by-index-in-logstash/199028/3 "2019-09-12T02:11:57Z")

</div>

Hey @Badger, thanks for the reply.

Unfortunately logstash gives me this:

> [2019-09-12T12:10:05,221][WARN][org.logstash.plugins.pipeline.PipelineBus] Attempted to send event to '%{[tags][1]}' but that address was unavailable. Maybe the destination pipeline is down or stopping? Will Retry.

Same goes if i try "$[tags][1]".

I might change my strategy and add fields using processors in filebeat.

Thanks for your help anyway!

---

<div class="post-metadata">

**Author:** ![gitreseteasy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gitreseteasy/32/54026_2.png) [@gitreseteasy](https://discuss.elastic.co/u/gitreseteasy)\
**Post date:** [September 12, 2019, 3:15am UTC](https://discuss.elastic.co/t/how-can-i-access-an-element-in-a-list-by-index-in-logstash/199028/4 "2019-09-12T03:15:27Z")

</div>

I found documentation for syntax here under **Field References** :

[https://www.elastic.co/guide/en/logstash/5.3/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/5.3/event-dependent-configuration.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2019, 3:15am UTC](https://discuss.elastic.co/t/how-can-i-access-an-element-in-a-list-by-index-in-logstash/199028/5 "2019-10-10T03:15:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
