# IF Statement being ignored

**URL:** <https://discuss.elastic.co/t/if-statement-being-ignored/146612>\
**Category:** Logstash\
**Created:** [August 30, 2018, 4:27am UTC](https://discuss.elastic.co/t/if-statement-being-ignored/146612 "2018-08-30T04:27:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CamTheMan](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Post date:** [August 30, 2018, 4:27am UTC](https://discuss.elastic.co/t/if-statement-being-ignored/146612/1 "2018-08-30T04:27:40Z")

</div>

Hello,

I have a (simplified) filter rule like:

```
filter {
    if "10.170.10.6" or "10.170.11.6" or "10.1.3.23" in [host] {
        grok {
            match => { "message" => [
                '^Accepted keyboard-interactive/pam for %{USERNAME:username} from %{IP:src_ip} port %{POSINT:src_port}' ] }
        }
        
        mutate {
            add_tag => ["hardware"]
        }
    
}
}

```

But for some reason logstash tags all events with the tag "hardware" EVEN if they are not listed as a host in "10.170.10.6" or "10.170.11.6" or "10.1.3.23".

Why is this happening? It's like the 'IF' statement is not being honored.

Any ideas on how to tag the messages only for the required hosts?

Thanks  
Cam

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 30, 2018, 4:33am UTC](https://discuss.elastic.co/t/if-statement-being-ignored/146612/2 "2018-08-30T04:33:24Z")

</div>

> ```
> if "10.170.10.6" or "10.170.11.6" or "10.1.3.23" in [host] {
> 
> ```

Natural language doesn't always translate into if expressions. This expression probably means "if 10.170.10.6 is a non-empty string (which is always is) or 10.170.11.6 is a non-empty string (which is always is) or 10.1.3.23 is a substring of the contents of the host field". This is what you're looking for:

```
 if [host] in ["10.170.10.6", "10.170.11.6", "10.1.3.23"] {

```

---

<div class="post-metadata">

**Author:** ![CamTheMan](https://avatars.discourse-cdn.com/v4/letter/c/3ec8ea/32.png) [@CamTheMan](https://discuss.elastic.co/u/CamTheMan)\
**Post date:** [August 30, 2018, 4:46am UTC](https://discuss.elastic.co/t/if-statement-being-ignored/146612/3 "2018-08-30T04:46:48Z")

</div>

That was fast!  
Thanks very much - That would also explain why I getting grokparsefailures from other rules that arent matching correctly!  
Thanks again

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2018, 4:46am UTC](https://discuss.elastic.co/t/if-statement-being-ignored/146612/4 "2018-09-27T04:46:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
