# If and problem

**URL:** <https://discuss.elastic.co/t/if-and-problem/230222>\
**Category:** Logstash\
**Created:** [April 28, 2020, 5:26pm UTC](https://discuss.elastic.co/t/if-and-problem/230222 "2020-04-28T17:26:28Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [April 28, 2020, 5:26pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/1 "2020-04-28T17:26:29Z")

</div>

I have an erreur if use this condition in logstsh

```
        if [job] == "MNNATY0P02" and [statut] == "OK" {
        mutate {
        add_field => { "statut_globale" => "1" }
         }
        }
```

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [April 28, 2020, 7:20pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/2 "2020-04-28T19:20:05Z")

</div>

what's the error exactly?

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [April 28, 2020, 7:34pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/3 "2020-04-28T19:34:45Z")

</div>

i use this condition but the colonne statut\_globale not created in elastic

```
if [job] == "MNNATY0P02" and [job] == "MNNATY0P00" and [job]== "MNNATY0P00" and [job]== 
 "MNNATY0P99" and [job]== "MNNATY0P14" and [job]== "MNNATY0P13" and [job]== 
 "MNNATY0P12" and [job]== "MNNATY0P11" and [job]== "MNNATY0P10" and [job]== 
 " MNNATY0P09" and [job]== "MNNATY0P08" and [job]== "MNNATY0P07" and [job]== 
 "MNNATY0P06" and [job]== "MNNATY0P05" and [job]== "MNNATY0P03" and [job]== 
  "MNNATY0P01" and [statut] == "OK" {
 mutate {
 add_field => { "statut_globale" => "1" }
}

```

}

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [April 28, 2020, 7:39pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/4 "2020-04-28T19:39:25Z")

</div>

Is the no error in the logstash logfile? besides the fieldname statut - which could be a typo - I don't see any error with it..

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 28, 2020, 10:20pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/5 "2020-04-28T22:20:32Z")

</div>

> [@Youssef\_SBAI](#):
>
> if [job] == "MNNATY0P02" and [job] == "MNNATY0P00" and ...

That is always going to evaluate to false. If the first test is true, the second is false, and the "and" of them will always be false.

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [April 29, 2020, 8:59am UTC](https://discuss.elastic.co/t/if-and-problem/230222/6 "2020-04-29T08:59:57Z")

</div>

what is the error in this condition ?

```
if [job] == "MNNATY0P02" and [job] == "MNNATY0P00" and [job]== "MNNATY0P00" and [job]== 
 "MNNATY0P99" and [job]== "MNNATY0P14" and [job]== "MNNATY0P13" and [job]== 
 "MNNATY0P12" and [job]== "MNNATY0P11" and [job]== "MNNATY0P10" and [job]== 
 "MNNATY0P09" and [job]== "MNNATY0P08" and [job]== "MNNATY0P07" and [job]== 
 "MNNATY0P06" and [job]== "MNNATY0P05" and [job]== "MNNATY0P03" and [job]== 
 "MNNATY0P01" and [statut] == "OK" {
  mutate {
  add_field => { "statut_globale" => "1" }
 }
```

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 29, 2020, 12:10pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/7 "2020-04-29T12:10:33Z")

</div>

As @Badger suggested, the condition you've shared will be **ALWAYS** false.

The `job` cannot be at the same time be equal to `MNNATY0P02` **AND** `MNNATY0P00` **AND** `MNNATY0P13`...

Alternatives:

```auto
if ([job] == "MNNATY0P02" or [job] == "MNNATY0P00" or [job]== "MNNATY0P00" or [job]== 
 "MNNATY0P99" or [job]== "MNNATY0P14" or [job]== "MNNATY0P13" or [job]== 
 "MNNATY0P12" or [job]== "MNNATY0P11" or [job]== "MNNATY0P10" or [job]== 
 "MNNATY0P09" or [job]== "MNNATY0P08" or [job]== "MNNATY0P07" or [job]== 
 "MNNATY0P06" or [job]== "MNNATY0P05" or [job]== "MNNATY0P03" or [job]== 
 "MNNATY0P01") and [statut] == "OK" {
  mutate {
  add_field => { "statut_globale" => "1" }
 }

```

Alternatives:

```auto
if [statut] == "OK" and [job] =~ /^MNNATY0P(00|01|02|03|05|06|07|08|09|10|11|12|13|14|99)$/ {
  mutate {
    add_field => { "statut_globale" => "1" }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [April 29, 2020, 12:20pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/8 "2020-04-29T12:20:08Z")

</div>

Thank Luca i have this error your Alternative

Sending Logstash logs to C:/Users/h83710/Desktop/elastic/logstash-7.5.2/logs which is now configured via log4j2.properties  
[2020-04-29T14:18:44,383][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2020-04-29T14:18:44,599][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.5.2"}  
[2020-04-29T14:18:47,916][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "=\>" at line 14, column 4 (byte 283) after filter {\n csv {\n separator =\> ";"\n\t\tcolumns =\> ["chaine", "job", "date\_plan", "statut", "date\_debut", "date\_fin", "serveur", "numero\_passage", "application", "sous\_application"]\n\n\nif ", :backtrace=\>["C:/Users/h83710/Desktop/elastic/logstash-7.5.2/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "C:/Users/h83710/Desktop/elastic/logstash-7.5.2/logstash-core/lib/logstash/compiler.rb:49:in `compile\_graph'", "C:/Users/h83710/Desktop/elastic/logstash-7.5.2/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2584:in `map'", "C:/Users/h83710/Desktop/elastic/logstash-7.5.2/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:156:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "C:/Users/h83710/Desktop/elastic/logstash-7.5.2/logstash-core/lib/logstash/java_pipeline.rb:27:in `initialize'", "C:/Users/h83710/Desktop/elastic/logstash-7.5.2/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "C:/Users/h83710/Desktop/elastic/logstash-7.5.2/logstash-core/lib/logstash/agent.rb:326:in `block in converge\_state'"]}

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 29, 2020, 12:28pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/9 "2020-04-29T12:28:28Z")

</div>

The errors says:

```auto
Expected one of [\t\r\n], "#", "=>" at line 14, column 4 (byte 283) after filter {\n csv {\n separator => ";"\n\t\tcolumns => ["chaine", "job", "date_plan", "statut", "date_debut", "date_fin", "serveur", "numero_passage", "application", "sous_application"]\n\n\nif 

```

From the error, it seems you didn't close the brackets in the `csv` filter.

---

<div class="post-metadata">

**Author:** ![Youssef\_SBAI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/youssef_sbai/32/64242_2.png) [@Youssef\_SBAI](https://discuss.elastic.co/u/Youssef_SBAI)\
**Post date:** [April 29, 2020, 2:18pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/10 "2020-04-29T14:18:22Z")

</div>

Thank but it is possible two have all conditions met and add\_field =\> { "statut\_globale" =\> "1" }

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 29, 2020, 5:16pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/11 "2020-04-29T17:16:50Z")

</div>

Hello @Youssef_SBAI

The error is no more related to the `if` condition.  
It is a syntax error because you didn't close the `csv` filter.

Post the full pipeline file if necessary.

* * *

If you feel more comfortable to write in French, please post the question in the section [discussions en Francais](https://discuss.elastic.co/c/in-your-native-tongue/discussions-en-francais/16).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2020, 5:16pm UTC](https://discuss.elastic.co/t/if-and-problem/230222/12 "2020-05-27T17:16:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
