# If condition in logstash output doesn't work

**URL:** <https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276>\
**Category:** Logstash\
**Created:** [August 3, 2022, 8:37am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276 "2022-08-03T08:37:39Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![zzcpower](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zzcpower/32/109181_2.png) [@zzcpower](https://discuss.elastic.co/u/zzcpower)\
**Post date:** [August 3, 2022, 8:37am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/1 "2022-08-03T08:37:39Z")

</div>

The config file is shown as below

```auto
input {
  kafka {
    bootstrap_servers => "localhost:9092"
    group_id => "log_monitor"
    auto_offset_reset => "latest"
    consumer_threads => 1
    topics => ["test_log"]
  }
}

filter{
}
 
output {
  **if [severity] =~ "err"{**
     kafka{
      topic_id => "filtered_log"
  }

}
}

```

input data example is shown as below, which is in json format.

```auto
{"appname":"jesseddy","facility":"kern","hostname":"for.net","message":"Pretty pretty pretty good","msgid":"ID902","procid":6810,"severity":"err","timestamp":"2022-08-03T08:07:41.909Z","version":2}

```

All I want to achieve is to only push the data with severity is "err" into a new topic of kafka. But the above configuration file doesn' t work. I can not not consume any data from kafka.

If I remove the if condition in output, I can successfully consume all the data. Therefore maybe I wrote the wrong if condition. Anyone can help plz?

Comment if need more information, thanks.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 3, 2022, 10:00am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/2 "2022-08-03T10:00:21Z")

</div>

If "err" is only a value, not error, ERR, then you can use:

`if [severity] == "err" {...}`

---

<div class="post-metadata">

**Author:** ![zzcpower](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zzcpower/32/109181_2.png) [@zzcpower](https://discuss.elastic.co/u/zzcpower)\
**Post date:** [August 4, 2022, 1:46am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/3 "2022-08-04T01:46:00Z")

</div>

Hi, Rios

Yes, "err" is only a value in json. I changed the configuration as you provided, but still can not consume any data in kafka. It seems somehow dropped all the data .

```auto
input {
  kafka {
    bootstrap_servers => "localhost:9092"
    group_id => "log_monitor"
    auto_offset_reset => "latest"
    consumer_threads => 1
    topics => ["test_log"]
  }
}

filter{
}
 
output {
  if [severity] == "err"{
   kafka{
    topic_id => "filtered_log"
  }

}
}

```

---

<div class="post-metadata">

**Author:** ![zzcpower](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zzcpower/32/109181_2.png) [@zzcpower](https://discuss.elastic.co/u/zzcpower)\
**Post date:** [August 4, 2022, 2:26am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/4 "2022-08-04T02:26:24Z")

</div>

New update.

I achieved what I need by using this configuration.

```auto
input {
  kafka {
    bootstrap_servers => "localhost:9092"
    group_id => "log_monitor"
    auto_offset_reset => "latest"
    consumer_threads => 1
    topics => ["test_log"]
  }
}

filter{

}
 
output {
  **if [message] =~ /err/{**
   kafka{
    topic_id => "filtered_log"
  }

}
}

```

Although I achieved what I need, but I am still confused. If we look at my input data example, we can see that "err" is a value in "severity" not in "message". So why I can filter out the data by using 'if [message] =~ "err" ' ?  
😵‍💫

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 4, 2022, 2:48am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/5 "2022-08-04T02:48:59Z")

</div>

The [message] field contains the serialized JSON. Unless your parse that using a [json](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html) filter you will not have a [severity] field.

---

<div class="post-metadata">

**Author:** ![zzcpower](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zzcpower/32/109181_2.png) [@zzcpower](https://discuss.elastic.co/u/zzcpower)\
**Post date:** [August 4, 2022, 9:02am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/6 "2022-08-04T09:02:12Z")

</div>

Thank you.

---

<div class="post-metadata">

**Author:** ![zzcpower](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zzcpower/32/109181_2.png) [@zzcpower](https://discuss.elastic.co/u/zzcpower)\
**Post date:** [August 4, 2022, 9:20am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/7 "2022-08-04T09:20:54Z")

</div>

Is there any other default field other than [message]? Where should I look for this kind of information to study?(Totally new to logstash). Thanks in advance!

---

<div class="post-metadata">

**Author:** ![79g](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/79g/32/109191_2.png) [@79g](https://discuss.elastic.co/u/79g)\
**Post date:** [August 4, 2022, 9:25am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/8 "2022-08-04T09:25:03Z")

</div>

Take a look into [Accessing event data and fields | Logstash Reference [8.3] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html) and see some explanations about fields in Logstash. Metadata could also be useful for you.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 4, 2022, 11:05am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/9 "2022-08-04T11:05:58Z")

</div>

If you search the message filed for "err" you might get some like {..."message":"An error occured",..}

I would use:

- JSON plugin to convert the structure to the fields, as Bager recommend
- Use grok to get a value from the severity field

Add to filter:

```auto
filter {
 grok {
	 match => { "message" => "\"severity\":\"%{LOGLEVEL:[@metadata][severity]}\"" }
	 }
}
output {
  if [@metadata][severity] == "err" { ... }
}

```

Also you can use regex on the field:  
`if [@metadata][severity] =~ /err/`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2022, 11:06am UTC](https://discuss.elastic.co/t/if-condition-in-logstash-output-doesnt-work/311276/10 "2022-09-01T11:06:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
