# If/CSV Filter not working

**URL:** <https://discuss.elastic.co/t/if-csv-filter-not-working/148879>\
**Category:** Logstash\
**Created:** [September 17, 2018, 7:19pm UTC](https://discuss.elastic.co/t/if-csv-filter-not-working/148879 "2018-09-17T19:19:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [September 17, 2018, 7:19pm UTC](https://discuss.elastic.co/t/if-csv-filter-not-working/148879/1 "2018-09-17T19:19:26Z")

</div>

Running the below pipeline and my events are not being split into fields and the tag isn't being added. I would have to assume there is something wrong with my `if` statement but I'm not sure what. The tag `Exchange` is added by the filebeat agent and appears in the ElasticSearch output. The source field value is a partial match on a directory location that some of the files are being pulled from. No errors appear in the Logstash debug logs either.

```
  if "Exchange" in [tags] and [source] =~ "\\FrontEnd\\ProtocolLog\\SmtpReceive" {
    csv {
      source => "message"
      columns => ["date","connector-id","session-id","sequence-number","local-endpoint","remote-endpoint","event","data","context"]
      convert => {
       "date" => "date_time"
      }
      add_tag => ["FrontEnd SMTP Receive"]
    }
  }
```

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [September 17, 2018, 8:47pm UTC](https://discuss.elastic.co/t/if-csv-filter-not-working/148879/2 "2018-09-17T20:47:14Z")

</div>

It definitely appears to be my IF statement. The below is what I've modified it to but I am still not getting the tag applied to the events.

```
filter {
  if [tags] !~ "Exchange" {
  ...
  }
  else if [source] =~ "C:\\Program Files\\Microsoft\\Exchange Server\\V15\\TransportRoles\\Logs\\FrontEnd\\ProtocolLog\\SmtpReceive\\.*" {
    mutate {
      add_tag => ["FrontEnd SMTP Receive"]
    }
  }
}

```

I've also tried modifying the if statement to a regex without double quotes but it does not work either.

`else if [source] =~ /^C:\\Program Files\\Microsoft\\Exchange Server\\V15\\TransportRoles\\Logs\\FrontEnd\\ProtocolLog\\SmtpReceive\\.*/ {`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2018, 8:47pm UTC](https://discuss.elastic.co/t/if-csv-filter-not-working/148879/3 "2018-10-15T20:47:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
