# If statement not work

**URL:** <https://discuss.elastic.co/t/if-statement-not-work/309183>\
**Category:** Logstash\
**Created:** [July 8, 2022, 8:35am UTC](https://discuss.elastic.co/t/if-statement-not-work/309183 "2022-07-08T08:35:56Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![david-a76](https://avatars.discourse-cdn.com/v4/letter/d/e480ec/32.png) [@david-a76](https://discuss.elastic.co/u/david-a76)\
**Post date:** [July 8, 2022, 8:35am UTC](https://discuss.elastic.co/t/if-statement-not-work/309183/1 "2022-07-08T08:35:56Z")

</div>

Hi all,  
I'm trying to import a sample json file:

```auto
...
{
  "id": 2,
  "timestamp": "2019-08-11T17:55:56Z",
  "paymentType": "Visa",
  "name": "Darby Dacks",
  "gender": "Female",
  "ip_address": "77.72.239.47",
  "purpose": "Shoes",
  "country": "Poland",
  "age": 55
}
{
  "id": 3,
  "timestamp": "2019-07-14T04:48:25Z",
  "paymentType": "Visa",
  "name": "Harri Cayette",
  "gender": "Female",
  "ip_address": "227.6.210.146",
  "purpose": "Sports",
  "country": "Canada",
  "age": 27
}
...

```

This is my logtash test conf:

```auto
input {
  file {
    start_position => "beginning"
    type => "json"
    path => "/tmp/json.txt"
    sincedb_path => "/dev/null"
  }
}
filter{
    if [country] == "Poland" {
        mutate {
                add_field => { "test" => "test" }
        }
    }

    json {
        source => "message"
    }

}
output {
  file {
    path => "/tmp/out.log"
  }
}

```

I would like to add a field depending on the content of an existing field (country) but the above configuration doesn't work: the field "test" is not added.  
What am I doing wrong?

Thank you all

---

<div class="post-metadata">

**Author:** ![anon90868141](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Post date:** [July 8, 2022, 11:07am UTC](https://discuss.elastic.co/t/if-statement-not-work/309183/2 "2022-07-08T11:07:14Z")

</div>

> [@david-a76](#):
>
> ```auto
> input {
> file {
> start_position => "beginning"
> type => "json"
> path => "/tmp/json.txt"
> sincedb_path => "/dev/null"
> }
> }
> filter{
> if [country] == "Poland" {
> mutate {
> add_field => { "test" => "test" }
> }
> }
> 
> json {
> source => "message"
> }
> 
> }
> output {
> file {
> path => "/tmp/out.log"
> }
> 
> ```

I think the code is indendent a level too much. Try this one:

```auto
filter {
  if [country] == "Poland" {
      mutate {
              add_field => { "test" => "test" }
      }
  }
 json {
      source => "message"
  }

}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 8, 2022, 1:18pm UTC](https://discuss.elastic.co/t/if-statement-not-work/309183/3 "2022-07-08T13:18:22Z")

</div>

Your conditional is correct and should've work, can you share the output you are getting from logstash in the `/tmp/out.log` file?

Does your source message a single line `json` or is pretty printed in your source file?

> [@anon90868141](#):
>
> I think the code is indendent a level too much

Identation makes no difference in Logstash.

---

<div class="post-metadata">

**Author:** ![david-a76](https://avatars.discourse-cdn.com/v4/letter/d/e480ec/32.png) [@david-a76](https://discuss.elastic.co/u/david-a76)\
**Post date:** [July 8, 2022, 2:26pm UTC](https://discuss.elastic.co/t/if-statement-not-work/309183/4 "2022-07-08T14:26:35Z")

</div>

This is the full original input json.txt (i used jq for pretty output):

```auto
{"id":1,"timestamp":"2019-09-12T13:43:42Z","paymentType":"Amex","name":"Merrill Duffield","gender":"Female","ip_address":"132.150.218.21","purpose":"Toys","country":"United Arab Emirates","age":33}
{"id":2,"timestamp":"2019-08-11T17:55:56Z","paymentType":"Visa","name":"Darby Dacks","gender":"Female","ip_address":"77.72.239.47","purpose":"Shoes","country":"Poland","age":55}
{"id":3,"timestamp":"2019-07-14T04:48:25Z","paymentType":"Visa","name":"Harri Cayette","gender":"Female","ip_address":"227.6.210.146","purpose":"Sports","country":"Canada","age":27}
{"id":4,"timestamp":"2020-02-29T12:41:59Z","paymentType":"Mastercard","name":"Regan Stockman","gender":"Male","ip_address":"139.224.15.154","purpose":"Home","country":"Indonesia","age":34}
{"id":5,"timestamp":"2019-08-03T19:37:51Z","paymentType":"Mastercard","name":"Wilhelmina Polle","gender":"Female","ip_address":"252.254.68.68","purpose":"Health","country":"Ukraine","age":51}

```

This is the full output (out.log):

```auto
{"log":{"file":{"path":"/tmp/json.txt"}},"@version":"1","timestamp":"2019-08-11T17:55:56Z","id":2,"gender":"Female","@timestamp":"2022-07-08T14:15:53.878804Z","event":{"original":"{\"id\":2,\"timestamp\":\"2019-08-11T17:55:56Z\",\"paymentType\":\"Visa\",\"name\":\"Darby Dacks\",\"gender\":\"Female\",\"ip_address\":\"77.72.239.47\",\"purpose\":\"Shoes\",\"country\":\"Poland\",\"age\":55}"},"paymentType":"Visa","host":{"name":"NBK-DAVIDD"},"type":"json","ip_address":"77.72.239.47","age":55,"purpose":"Shoes","message":"{\"id\":2,\"timestamp\":\"2019-08-11T17:55:56Z\",\"paymentType\":\"Visa\",\"name\":\"Darby Dacks\",\"gender\":\"Female\",\"ip_address\":\"77.72.239.47\",\"purpose\":\"Shoes\",\"country\":\"Poland\",\"age\":55}","name":"Darby Dacks","country":"Poland"}
{"log":{"file":{"path":"/tmp/json.txt"}},"@version":"1","timestamp":"2020-02-29T12:41:59Z","id":4,"gender":"Male","@timestamp":"2022-07-08T14:15:53.880454Z","event":{"original":"{\"id\":4,\"timestamp\":\"2020-02-29T12:41:59Z\",\"paymentType\":\"Mastercard\",\"name\":\"Regan Stockman\",\"gender\":\"Male\",\"ip_address\":\"139.224.15.154\",\"purpose\":\"Home\",\"country\":\"Indonesia\",\"age\":34}"},"paymentType":"Mastercard","host":{"name":"NBK-DAVIDD"},"type":"json","ip_address":"139.224.15.154","age":34,"purpose":"Home","message":"{\"id\":4,\"timestamp\":\"2020-02-29T12:41:59Z\",\"paymentType\":\"Mastercard\",\"name\":\"Regan Stockman\",\"gender\":\"Male\",\"ip_address\":\"139.224.15.154\",\"purpose\":\"Home\",\"country\":\"Indonesia\",\"age\":34}","name":"Regan Stockman","country":"Indonesia"}
{"log":{"file":{"path":"/tmp/json.txt"}},"@version":"1","timestamp":"2019-09-12T13:43:42Z","id":1,"gender":"Female","@timestamp":"2022-07-08T14:15:53.852279Z","event":{"original":"{\"id\":1,\"timestamp\":\"2019-09-12T13:43:42Z\",\"paymentType\":\"Amex\",\"name\":\"Merrill Duffield\",\"gender\":\"Female\",\"ip_address\":\"132.150.218.21\",\"purpose\":\"Toys\",\"country\":\"United Arab Emirates\",\"age\":33}"},"paymentType":"Amex","host":{"name":"NBK-DAVIDD"},"type":"json","ip_address":"132.150.218.21","age":33,"purpose":"Toys","message":"{\"id\":1,\"timestamp\":\"2019-09-12T13:43:42Z\",\"paymentType\":\"Amex\",\"name\":\"Merrill Duffield\",\"gender\":\"Female\",\"ip_address\":\"132.150.218.21\",\"purpose\":\"Toys\",\"country\":\"United Arab Emirates\",\"age\":33}","name":"Merrill Duffield","country":"United Arab Emirates"}
{"log":{"file":{"path":"/tmp/json.txt"}},"@version":"1","timestamp":"2019-08-03T19:37:51Z","id":5,"gender":"Female","@timestamp":"2022-07-08T14:15:53.880880Z","event":{"original":"{\"id\":5,\"timestamp\":\"2019-08-03T19:37:51Z\",\"paymentType\":\"Mastercard\",\"name\":\"Wilhelmina Polle\",\"gender\":\"Female\",\"ip_address\":\"252.254.68.68\",\"purpose\":\"Health\",\"country\":\"Ukraine\",\"age\":51}"},"paymentType":"Mastercard","host":{"name":"NBK-DAVIDD"},"type":"json","ip_address":"252.254.68.68","age":51,"purpose":"Health","message":"{\"id\":5,\"timestamp\":\"2019-08-03T19:37:51Z\",\"paymentType\":\"Mastercard\",\"name\":\"Wilhelmina Polle\",\"gender\":\"Female\",\"ip_address\":\"252.254.68.68\",\"purpose\":\"Health\",\"country\":\"Ukraine\",\"age\":51}","name":"Wilhelmina Polle","country":"Ukraine"}
{"log":{"file":{"path":"/tmp/json.txt"}},"@version":"1","timestamp":"2019-07-14T04:48:25Z","id":3,"gender":"Female","@timestamp":"2022-07-08T14:15:53.879848Z","event":{"original":"{\"id\":3,\"timestamp\":\"2019-07-14T04:48:25Z\",\"paymentType\":\"Visa\",\"name\":\"Harri Cayette\",\"gender\":\"Female\",\"ip_address\":\"227.6.210.146\",\"purpose\":\"Sports\",\"country\":\"Canada\",\"age\":27}"},"paymentType":"Visa","host":{"name":"NBK-DAVIDD"},"type":"json","ip_address":"227.6.210.146","age":27,"purpose":"Sports","message":"{\"id\":3,\"timestamp\":\"2019-07-14T04:48:25Z\",\"paymentType\":\"Visa\",\"name\":\"Harri Cayette\",\"gender\":\"Female\",\"ip_address\":\"227.6.210.146\",\"purpose\":\"Sports\",\"country\":\"Canada\",\"age\":27}","name":"Harri Cayette","country":"Canada"}

```

How you can see there is no "test" field in the output file.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 8, 2022, 2:56pm UTC](https://discuss.elastic.co/t/if-statement-not-work/309183/5 "2022-07-08T14:56:18Z")

</div>

Oh, I thought you had `codec => "json"` in your input, but it is `type => "json"`.

Your `if` is not working because the field `country` is not present in the document when your event arrives in that conditional, you are parsing the message just after the conditional, it is only after you parse the `message` field that the field `country` will be present in your document and you would be able to use it for conditionals.

Change the order and it will work:

```auto
json {
        source => "message"
}
if [country] == "Poland" {
        mutate {
                add_field => { "test" => "test" }
        }
}

```

---

<div class="post-metadata">

**Author:** ![david-a76](https://avatars.discourse-cdn.com/v4/letter/d/e480ec/32.png) [@david-a76](https://discuss.elastic.co/u/david-a76)\
**Post date:** [July 8, 2022, 4:54pm UTC](https://discuss.elastic.co/t/if-statement-not-work/309183/6 "2022-07-08T16:54:18Z")

</div>

Thank You Leandro. It's work but i preferred to use "codec" instead of "type" as you suggested so i changed my conf in this way:

```auto
input {
  file {
    start_position => "beginning"
    codec => json
    path => "/tmp/json.txt"
    sincedb_path => "/dev/null"
  }
}
filter{
    if [country] == "Poland" {
        mutate {
                add_field => { "test" => "test" }
        }
    }
}

```

Is this the best practice?

Thank you again

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 8, 2022, 6:13pm UTC](https://discuss.elastic.co/t/if-statement-not-work/309183/7 "2022-07-08T18:13:32Z")

</div>

Those are different things.

Using `type => "json"` in the input will add a field named `type` to your event, you can then use this field to filtering

Using `codec => "json"` in the input will tell logstash that your message is a json document and it will parse directly in the input stage.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2022, 6:14pm UTC](https://discuss.elastic.co/t/if-statement-not-work/309183/8 "2022-08-05T18:14:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
