# If conditional statement field source

**URL:** <https://discuss.elastic.co/t/if-conditional-statement-field-source/91043>\
**Category:** Logstash\
**Created:** [June 28, 2017, 5:21am UTC](https://discuss.elastic.co/t/if-conditional-statement-field-source/91043 "2017-06-28T05:21:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![elaair](https://avatars.discourse-cdn.com/v4/letter/e/6f9a4e/32.png) [@elaair](https://discuss.elastic.co/u/elaair)\
**Post date:** [June 28, 2017, 5:21am UTC](https://discuss.elastic.co/t/if-conditional-statement-field-source/91043/1 "2017-06-28T05:21:14Z")

</div>

I have defined a simple parser and would like to setup a if statement in log stash.conf to have a grok match on one of the fields. I am working towards having many log sources but am starting with only one. I have a field %{WORD:process\_name} and am wondering if I can use process\_name in an if statement like this if [process\_name == "dhcpd" {  
Will this work?  
Logstash.conf  
input {

file {  
path =\> ["/var/log/dhcpd.log"]  
type =\> "syslog"  
}  
} #Close input

filter {

if [process\_name] == "dhcpd" {  
grok {  
patterns\_dir =\> "/home/wschroed/logstash-5.4.1/patterns/"  
match =\> { "message" =\> "%{270617DHCPD}" }  
} #Close grok

} # close if

```
   } # Close filter

```

output {  
elasticsearch { hosts =\> ["10.0.1.146:9200"] }  
}

Grok  
270617DHCPD %{SYSLOGTIMESTAMP:date}%{SPACE}%{HOSTNAME:device\_hostname}%{SPACE}%{DAEMON:process\_name}%{SPACE}%{ACTION:dhcp\_request}%{SPACE}%{WORD:toss}%{SPACE}%{IP:src\_IP}%{SPACE}%{WORD:toss}%{SPACE}%{COMMONMAC:src\_mac}%{SPACE}(%{HOSTNAME:src\_hostname})%{SPACE}%{WORD:toss}%{SPACE}%{WORD:device\_interface}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 28, 2017, 5:44am UTC](https://discuss.elastic.co/t/if-conditional-statement-field-source/91043/2 "2017-06-28T05:44:32Z")

</div>

> if [process\_name] == "dhcpd" {

This is syntactically correct but won't work in this particular case since the `process_name` field is created by the grok filter inside the conditional. It's a catch-22 situation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2017, 5:44am UTC](https://discuss.elastic.co/t/if-conditional-statement-field-source/91043/3 "2017-07-26T05:44:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
