# If condition matching json with "in"

**URL:** <https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946>\
**Category:** Logstash\
**Created:** [June 19, 2017, 2:12pm UTC](https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946 "2017-06-19T14:12:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Enrico\_Maria\_Fusi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/enrico_maria_fusi/32/19258_2.png) [@Enrico\_Maria\_Fusi](https://discuss.elastic.co/u/Enrico_Maria_Fusi)\
**Post date:** [June 19, 2017, 2:12pm UTC](https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946/1 "2017-06-19T14:12:30Z")

</div>

Hello all,

I have problem with a configuration which is supposed to select only lines containing a specific text inside. The source is a json\_line file. What I want is that only the messages matching a given string are processed, like:

```
filter {

    if ("PUSH_BODY" in [message] ) {

        mutate { add_field => { "object_key" => "%{[@metadata][s3][key]}" }
                 add_field => { "topic" => "whatever" }
                 add_field => { "source_host" => "whatever.com" }
        }

                } else {
                drop{}
                }

}

```

so this should take only lines containing the string PUSH\_BODY and drop everything else.

What could go wrong here? The input is a json formatted text file in custom format, which contains the following pattern:

> "type":"PUSH\_BODY"}

why this filter is not working?

thanks in advance,

FEM.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 19, 2017, 2:18pm UTC](https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946/2 "2017-06-19T14:18:58Z")

</div>

So the `type` field is "PUSH\_BODY"? Then then conditional should look like this:

```
if [type] == "PUSH_BODY" {

```

Otherwise, please show what an event that doesn't match the conditional actually looks like. Use a `stdout { codec => rubydebug }` output or copy/paste from the JSON tab in Kibana's Discover panel.

---

<div class="post-metadata">

**Author:** ![Enrico\_Maria\_Fusi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/enrico_maria_fusi/32/19258_2.png) [@Enrico\_Maria\_Fusi](https://discuss.elastic.co/u/Enrico_Maria_Fusi)\
**Post date:** [June 19, 2017, 2:28pm UTC](https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946/3 "2017-06-19T14:28:26Z")

</div>

Hi Magnus,

first, thank for the answer. 🙂

The JSON looks like this:

{"id":"some-uuid","offset":"125018457","occurred":"2017-04-28T19:37:19.249Z","processed":"2017-04-28T19:37:20.362Z","body":{"payload":"somestring=","push\_id":"someUUID","resource":"PUSH","trimmed":false},"type":"PUSH\_BODY"}

I removed relevant data because is traffic from real users, sorry for that. I can confirm there is no other record containing "PUSH\_BODY" . Basically I tried to use the message as a whole line, which should be possible even if the codec is json. For completeness, the input looks like:

```
input {
        s3 {
                bucket => "mybucket"
                codec => "json"
                region => "us-east-1"
                sincedb_path => "/somewhere/.sincedb_PUSHBODY"
                interval => 10
        }

```

}

regards,

FEM

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 19, 2017, 2:35pm UTC](https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946/4 "2017-06-19T14:35:19Z")

</div>

> Basically I tried to use the message as a whole line, which should be possible even if the codec is json.

If you've used the json or json\_lines codec to deserialize a JSON string into discrete fields the original JSON string won't get preserved unless you make a copy of the field first.

---

<div class="post-metadata">

**Author:** ![Enrico\_Maria\_Fusi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/enrico_maria_fusi/32/19258_2.png) [@Enrico\_Maria\_Fusi](https://discuss.elastic.co/u/Enrico_Maria_Fusi)\
**Post date:** [June 19, 2017, 2:56pm UTC](https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946/5 "2017-06-19T14:56:02Z")

</div>

> [@magnusbaeck](#):
>
> stdout { codec =\> rubydebug }

Hi Magnus,

thanks again for the prompt answer... to my understanding: you mean the %{message} variable is emptied before of the filter , when the input has a codec of json?

Enrico

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 19, 2017, 9:00pm UTC](https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946/6 "2017-06-19T21:00:08Z")

</div>

Yes. See for yourself.

If you have a discrete field with the exact value you're looking for you shouldn't be doing substring matching against the JSON string anyway.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2017, 9:00pm UTC](https://discuss.elastic.co/t/if-condition-matching-json-with-in/89946/7 "2017-07-17T21:00:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
