# If Condition in JSON filter

**URL:** <https://discuss.elastic.co/t/if-condition-in-json-filter/311456>\
**Category:** Logstash\
**Created:** [August 4, 2022, 6:08pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456 "2022-08-04T18:08:33Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sta02](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@sta02](https://discuss.elastic.co/u/sta02)\
**Post date:** [August 4, 2022, 6:08pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456/1 "2022-08-04T18:08:33Z")

</div>

Hello,

I am ingesting JSON data to logstash, and I am using JSON filter.  
In the JSON data, when the KEY is either Value 1 or Value 2, I should add a field, and if this key is missing in the logs, I will have to drop it. Please advise on how to code this.

Below is code, and its not effective.

```auto
 if "true" in ["adf"] {
                mutate {
                        add_field => {"TrueCondition" => "Test True" }
                }
        }
         if "false" in ["adf"] {
                mutate {
                        add_field => {"FalseCondition" => "Test False" }
                }
        }

```

Data captured in the **JSON event: "adf": false or "adf": true**  
Thanks in Advance.

--  
Siddarth

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 4, 2022, 6:12pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456/2 "2022-08-04T18:12:49Z")

</div>

> [@sta02](#):
>
> `if "true" in ["adf"] {`

`in` has two uses, one is an array membership test, the other is testing whether a substring exists in a string.

If your JSON contains `"adf": true` then I would expect [adf] to be a boolean in logstash and you can just use

```
if [adf] {
    mutate { add_field => {"TrueCondition" => "Test True" }
} else {
    mutate { add_field => {"FalseCondition" => "Test False" }
}

```

If you use `output { stdout { codec => rubydebug } }` then what does the [adf] field look like?

---

<div class="post-metadata">

**Author:** ![sta02](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@sta02](https://discuss.elastic.co/u/sta02)\
**Post date:** [August 4, 2022, 6:36pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456/3 "2022-08-04T18:36:34Z")

</div>

@Badger , Below is my configuration file

```auto
  syslog {
    port => 1555
        syslog_field => "message"
        grok_pattern => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname}%{GREEDYDATA:message}"
        }
}
filter {
        json {
                 source => "message"
      }
        mutate {
                remove_field => ["devTimeFormat","log","event","message"]
                }
        if "adf" in [message] {
                mutate {
                        add_field => {"deviceProduct" => "TEST.AVI"}
                        }
                }
        }
output {
        stdout {}
}

```

I am using STDOUT to check if the output is as expected.

My objective is - if the **Syslog** message has the field " **adf**", then I will perform " **add\_field**", else I should **drop** the event and not process the event.  
Please advise on how to configure this.

The whole code is working except for the **IF** condition., and I have not implemented the drop condition.

## Thanks in advance.

Siddarth

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 4, 2022, 6:51pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456/4 "2022-08-04T18:51:14Z")

</div>

If you want to test whether the [adf] field exists then use

```
if [adf] {
    mutate { ... }
} else {
    drop {}
}

```

---

<div class="post-metadata">

**Author:** ![sta02](https://avatars.discourse-cdn.com/v4/letter/s/5f8ce5/32.png) [@sta02](https://discuss.elastic.co/u/sta02)\
**Post date:** [August 4, 2022, 7:28pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456/5 "2022-08-04T19:28:39Z")

</div>

@Badger , yes, my objective is the ADF field is present in the JSON log, then I will **mutate** and **add\_field** , else I will drop the event.

But the **IF** condition is not working. Am I calling a Wrong field in **IF**?  
Because when I just add IF, there is change in output, but when I add **DROP** condition, then the event is being sent to a different port and there by dropped.

Below is the updated configuration

```auto
syslog {
   port => 1555
       syslog_field => "message"
       grok_pattern => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname}%{GREEDYDATA:message}"
       }
}
filter {
       json {
                source => "message"
     }
       mutate {
               remove_field => ["devTimeFormat","log","event","message"]
               }
       if [adf] {
               mutate {
                       add_field => {"deviceProduct" => "TEST.AVI"}
                       }
               }
       }
output {
       stdout {}
}

```

Below is the STDOUT when I add **DROP** condition

```auto
[INFO] 2022-08-04 19:14:46.428 [Ruby-0-Thread-16: :1] syslog - new connection {:client=>"10.1.0.4:44850"}

```

Below is a sample event

```auto
'Jul 29 10:28:49 192.168.153.101 {"adf": false,"significant":0,"udf":false,.....}' 

```

--  
Thanks in advance  
Siddarth

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 4, 2022, 8:10pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456/6 "2022-08-04T20:10:15Z")

</div>

The logstash configuration language does not provide a way to directly test whether a boolean field exists. There is an [open issue](https://github.com/elastic/logstash/issues/1867) for that. "if [adf]" will evaluate false is [adf] does not exists, but also when [adf] is a boolean with the value false.

The trick is to set a metadata field, then only overwrite it if [adf] exists, then test whether the metadata field was modified.

```
    mutate { add_field => { "[@metadata][test_field_check]" => "someValue" } }
    mutate { copy => { "adf" => "[@metadata][test_field_check]" } }
    if [@metadata][test_field_check] == "someValue" {
        mutate { add_field => { "field_did_not_exist" => true }}
    } else {
        mutate { add_field => { "field_did_exist" => true }}
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2022, 8:10pm UTC](https://discuss.elastic.co/t/if-condition-in-json-filter/311456/7 "2022-09-01T20:10:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
