# If statement not working with gsub

**URL:** <https://discuss.elastic.co/t/if-statement-not-working-with-gsub/215030>\
**Category:** Logstash\
**Created:** [January 14, 2020, 6:27pm UTC](https://discuss.elastic.co/t/if-statement-not-working-with-gsub/215030 "2020-01-14T18:27:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nino](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@nino](https://discuss.elastic.co/u/nino)\
**Post date:** [January 14, 2020, 6:27pm UTC](https://discuss.elastic.co/t/if-statement-not-working-with-gsub/215030/1 "2020-01-14T18:27:39Z")

</div>

Hello all,

i want to remove "ZC" in a field and converted in a negative float

```
 "account_value" => "767.19ZC",
 "@timestamp" => 2020-01-06T23:00:00.000Z

```

why this statement is not working?

```
 filter{
      if "ZC" in "field" {
        mutate {
          gsub => [
            "field","ZC",""
          ]
        }  
     }
}

```

without "if" statement works

```
filter{
    mutate {
      gsub => [
        "field","ZC",""
      ]
    }  
}
```

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 15, 2020, 10:33am UTC](https://discuss.elastic.co/t/if-statement-not-working-with-gsub/215030/2 "2020-01-15T10:33:56Z")

</div>

Hi,

The if statement does not look for field string content but exact value,

for example you can use this if your field was array and ZC was one of the value of that array

array = ['ZC' , 'foo' , 'bar']

the **IN** statement implies to match the exact value you can use regular expressions with:  
**if "field" =~ "REGEXP"**

---

<div class="post-metadata">

**Author:** ![nino](https://avatars.discourse-cdn.com/v4/letter/n/b9bd4f/32.png) [@nino](https://discuss.elastic.co/u/nino)\
**Post date:** [January 15, 2020, 10:53am UTC](https://discuss.elastic.co/t/if-statement-not-working-with-gsub/215030/3 "2020-01-15T10:53:21Z")

</div>

Hello grumo35,

thank you but i've solved. The problem was syntax. Change "field" for [field], it works perfectly now.

```
filter{
      if "ZC" in [field] {
        mutate {
          gsub => [
            "field","ZC",""
          ]
        }  
     }
}
```

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [January 15, 2020, 11:36am UTC](https://discuss.elastic.co/t/if-statement-not-working-with-gsub/215030/4 "2020-01-15T11:36:51Z")

</div>

Well, I would say that is the most frequent case:  
`if [field] in ["apples","oranges","pineapples"] { # looks for exact match between the complete field and any of the array elements `

but, checking carefully the documentation on conditionals: [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals)  
It also allows looking for "string in field", equivalent to the regex example you posted.

`if "apple" in [field] { # will match both "apples" and "pineapples"`

I would add that, working with `in` conditionals, there is a **bug** that has to be taken into account: one-element array comparison doesn't work.

`if [field] in ["apples"] { # won't match even if field = "apples"`

> <https://github.com/elastic/logstash/issues/5591>
>
> Version:
> Ubuntu 16.04 LTS
> Logstash 2.3.2
> Hi
> I have found that multiple people ran into the issue where the in check gets confused as to...

* * *

@nino  
Thanks for adding your working configuration 🙂

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 15, 2020, 12:23pm UTC](https://discuss.elastic.co/t/if-statement-not-working-with-gsub/215030/5 "2020-01-15T12:23:11Z")

</div>

wow didnt knew this could work like this, thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 12, 2020, 12:24pm UTC](https://discuss.elastic.co/t/if-statement-not-working-with-gsub/215030/6 "2020-02-12T12:24:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
