# If clause seems not to be working

**URL:** <https://discuss.elastic.co/t/if-clause-seems-not-to-be-working/66757>\
**Category:** Logstash\
**Created:** [November 21, 2016, 5:09pm UTC](https://discuss.elastic.co/t/if-clause-seems-not-to-be-working/66757 "2016-11-21T17:09:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kernel\_Panic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kernel_panic/32/12294_2.png) [@Kernel\_Panic](https://discuss.elastic.co/u/Kernel_Panic)\
**Post date:** [November 21, 2016, 5:09pm UTC](https://discuss.elastic.co/t/if-clause-seems-not-to-be-working/66757/1 "2016-11-21T17:09:12Z")

</div>

Hi guys.  
I'm just wanting to log different event to different indexes and I'm trying to achieve it by using tags.

```
input {
  udp {
    port => 25826
    type => "collectd"
    buffer_size => 1452
    codec => collectd { }
  }
}

input {
    udp {
      port => 5514
      codec => "json"
      type => "sensu"
      tags => "sensu"
  }
}

```

Output Filter:

```
output {
  if [@metadata][beat] {
    elasticsearch {
      hosts => ["server"]
      sniffing => true
      manage_template => false
      index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
      document_type => "%{[@metadata][type]}"
    }
  } else {
    elasticsearch {
      hosts => ["server"]
      sniffing => true
      manage_template => false
      index => "collectd-%{+YYYY.MM.dd}"
      document_type => "collectd"
    }
  }
}

```

Separate filter for sensu:

```
output {
   if "sensu" in [tags] {
elasticsearch {
  hosts => ["server"]
  sniffing => true
  manage_template => false
  index => "sensu-%{+YYYY.MM.dd}"
  document_type => "sensu"
  }
 }
}

```

When I restart the service I cannot see the data anymore in sensu index, if I remove the if clouse if works , what' wrong, I've already define the tag sensu in the input filter, doesn't it work that way?

What am I doing wrong?  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [November 22, 2016, 12:13am UTC](https://discuss.elastic.co/t/if-clause-seems-not-to-be-working/66757/2 "2016-11-22T00:13:18Z")

</div>

Can you try inserting as an output `stdout { codec => rubydebug }`.? That will show you the full event data and let us see if the `sensu` tag is being deleted somehow. Could a filter be mangling it somewhere?

---

<div class="post-metadata">

**Author:** ![Kernel\_Panic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kernel_panic/32/12294_2.png) [@Kernel\_Panic](https://discuss.elastic.co/u/Kernel_Panic)\
**Post date:** [November 22, 2016, 8:31pm UTC](https://discuss.elastic.co/t/if-clause-seems-not-to-be-working/66757/3 "2016-11-22T20:31:19Z")

</div>

> [@Kernel\_Panic](#):
>
> if "sensu" in [tags] {

Hi Andrew,  
Yeah, there was a filter that was the culprit, now I'm able to send the data to separate indexes including sensu

I left the beat output like this:

```
output {
  if [@metadata][beat] {
    elasticsearch {
      hosts => ["server"]
      sniffing => true
      manage_template => false
      index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
      document_type => "%{[@metadata][type]}"
    }
  }
}

```

Created a new one for collectd:

```
output {
    if "collectd" in [tags] {
    elasticsearch {
      hosts => ["server"]
      sniffing => true
      manage_template => false
      index => "collectd-%{+YYYY.MM.dd}"
      document_type => "collectd"
    }
  }
}

```

And this one for sensu:

```
output {
    stdout { codec => rubydebug }
    if "sensu" in [tags] {
    elasticsearch {
      hosts => ["server"]
      sniffing => true
      manage_template => false
      index => "sensu-%{+YYYY.MM.dd}"
      document_type => "sensu"
     }
    }
  }

```

Now I can see in the logs:

```
 "last_ok" => 1479846616,
                 "silenced" => false,
              "silenced_by" => [],
                 "@version" => "1",
               "@timestamp" => "2016-11-22T20:30:16.382Z",
                     "tags" => [
        [0] "sensu"
    ],
                     "host" => "x.x.x.x"
}

```

Thank you very much for your time and support  
Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2016, 8:31pm UTC](https://discuss.elastic.co/t/if-clause-seems-not-to-be-working/66757/4 "2016-12-20T20:31:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
