# If elseif else expression in conf - how to use many of them

**URL:** <https://discuss.elastic.co/t/if-elseif-else-expression-in-conf-how-to-use-many-of-them/165357>\
**Category:** Logstash\
**Created:** [January 23, 2019, 8:45am UTC](https://discuss.elastic.co/t/if-elseif-else-expression-in-conf-how-to-use-many-of-them/165357 "2019-01-23T08:45:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [January 23, 2019, 8:45am UTC](https://discuss.elastic.co/t/if-elseif-else-expression-in-conf-how-to-use-many-of-them/165357/1 "2019-01-23T08:45:36Z")

</div>

Hi all,  
question: I want to use many if blocks:

is this statement ok or do I need always "else" to end the "if" expression?

```
	if "Resource" in [Error_Code]{
		mutate {add_tag => "Recource"}
		}
	else if "State" in [Error_Code]{
		mutate {add_tag => "Channel_Error"}
		}
	else if "Key" in [Error_Code]{
		mutate {add_tag => "LogError"}
		}
	else if "Missing" in [Error_Code]{
		mutate {add_tag => "NiceError"}
		}

```

# next

```
    if "Bla" in [Code]{
		mutate {add_tag => "Bla"}
		}
	else if "Blub" in [Code]{
		mutate {add_tag => "Blub"}
		}
	else if "Bal" in [Error_Code]{
		mutate {add_tag => "Bal"}
		}
	else if "Blo" in [Error_Code]{
		mutate {add_tag => "Blo"}
		}

```

# and so on

What I dont understand how to say if the field is empty:

```
if "" in [Error_Code]{
    		mutate {add_tag => "allgood"}
    		}

```

Further:  
It is ok to just use "if" by "if" by "if" without having any "else if" nor "else" ?  
Means how to say "if" ends here in right way?

Thanks in advance  
Regards

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [January 23, 2019, 9:13am UTC](https://discuss.elastic.co/t/if-elseif-else-expression-in-conf-how-to-use-many-of-them/165357/2 "2019-01-23T09:13:53Z")

</div>

Hi @Datakids ,

I find the [documentation](https://www.elastic.co/guide/en/logstash/6.5/event-dependent-configuration.html#conditionals) from Elastic to usually be very informative.

There you can see examples that will show that you do not _have to_ end with an `else`. There is also an example on an `if` chain (with multiple `if` and no `else if` or `else`).

Cheers,  
AB

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [January 23, 2019, 9:22am UTC](https://discuss.elastic.co/t/if-elseif-else-expression-in-conf-how-to-use-many-of-them/165357/3 "2019-01-23T09:22:38Z")

</div>

Hi,  
Cool, I haven't found it yet.  
I'm gonna dive into  
Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 20, 2019, 9:22am UTC](https://discuss.elastic.co/t/if-elseif-else-expression-in-conf-how-to-use-many-of-them/165357/4 "2019-02-20T09:22:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
