# If statement within logstash

**URL:** <https://discuss.elastic.co/t/if-statement-within-logstash/234881>\
**Category:** Logstash\
**Created:** [May 29, 2020, 8:15am UTC](https://discuss.elastic.co/t/if-statement-within-logstash/234881 "2020-05-29T08:15:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ErwinEnableU](https://avatars.discourse-cdn.com/v4/letter/e/ce73a5/32.png) [@ErwinEnableU](https://discuss.elastic.co/u/ErwinEnableU)\
**Post date:** [May 29, 2020, 8:15am UTC](https://discuss.elastic.co/t/if-statement-within-logstash/234881/1 "2020-05-29T08:15:42Z")

</div>

Hi all,  
I am trying to create an if-statement within my logstash filter. If follow the documentation on [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)  
But somehow I am unable to get this working. What I am trying to do is the following:  
If field x has value a then add\_field y with value b else add\_field y with value c  
Can someone please help me? thank you

---

<div class="post-metadata">

**Author:** ![chitreshg](https://avatars.discourse-cdn.com/v4/letter/c/df705f/32.png) [@chitreshg](https://discuss.elastic.co/u/chitreshg)\
**Post date:** [May 29, 2020, 9:51am UTC](https://discuss.elastic.co/t/if-statement-within-logstash/234881/2 "2020-05-29T09:51:31Z")

</div>

if you have problem with **if-else syntax** , then try following code inside your filter plugin:

```
if [x] == "a" {
	mutate {
		add_field => {"y" => "b"}
	}
}
else {
	mutate {
		add_field => {"y" => "c"}
	}
}
```

---

<div class="post-metadata">

**Author:** ![ErwinEnableU](https://avatars.discourse-cdn.com/v4/letter/e/ce73a5/32.png) [@ErwinEnableU](https://discuss.elastic.co/u/ErwinEnableU)\
**Post date:** [May 29, 2020, 12:07pm UTC](https://discuss.elastic.co/t/if-statement-within-logstash/234881/3 "2020-05-29T12:07:16Z")

</div>

Thank you chitreshg. That almost did the trick. I have a solutions which works fine now. I want to share with the community:  
Right now I do the following: first add\_field y with value a. after that the if statement, which looks like

```auto
mutate {
	add_field => {"y" => a}
}
if [field_x] == "h" {
	mutate {
		update => {"y" => b}
	}
}
else {
	mutate {
		update => {"y" => c}
	}
}

```

---

<div class="post-metadata">

**Author:** ![chitreshg](https://avatars.discourse-cdn.com/v4/letter/c/df705f/32.png) [@chitreshg](https://discuss.elastic.co/u/chitreshg)\
**Post date:** [June 1, 2020, 4:45am UTC](https://discuss.elastic.co/t/if-statement-within-logstash/234881/4 "2020-06-01T04:45:45Z")

</div>

if you already have some value in any field then on adding any new value it appends the new value and creates array, so you can use update or replace,  
in my case I suggested for adding new value on new field, any how both will work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 29, 2020, 4:45am UTC](https://discuss.elastic.co/t/if-statement-within-logstash/234881/5 "2020-06-29T04:45:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
