# Integer comparison not working

**URL:** <https://discuss.elastic.co/t/integer-comparison-not-working/242248>\
**Category:** Logstash\
**Created:** [July 22, 2020, 8:50pm UTC](https://discuss.elastic.co/t/integer-comparison-not-working/242248 "2020-07-22T20:50:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![opoplawski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opoplawski/32/40442_2.png) [@opoplawski](https://discuss.elastic.co/u/opoplawski)\
**Post date:** [July 22, 2020, 8:50pm UTC](https://discuss.elastic.co/t/integer-comparison-not-working/242248/1 "2020-07-22T20:50:33Z")

</div>

I'm trying to conditionally set some fields in my pipeline:

```auto
filter {
  if [log][file][path] == "/var/log/e2guardian/access.log" {
    grok {
      match => { "message" => "(?<e2_timestamp>\d\d\d\d\.\d\d\.\d\d \d\d:\d\d:\d\d)\t%{NOTSPACE:user.name}\t%{IP:client.address}\t%{NOTSPACE:url.full}\t%{NOTSPACE:event.action} ?(hw\d+: )?(?<why>[^\t]+)?\t%{WORD:http.request.method}\t%{NUMBER:http.request.bytes}\t\d+\t[^\t]+\t[^\t]+\t%{NUMBER:http.response.status_code}\t[^\t]+\t%{IP:client.ip}" }
    }
    if "_grokparsefailure" not in [tags] {
      mutate {
        remove_field => ["message"]
        add_field => { "[event][category]" => ["network", "web"] }
        add_field => { "[event][kind]" => "event" }
        convert => { "[http][response][status_code]" => "integer" }
      }
      if [http][response][status_code] and [http][response][status_code] >= 200 and [http][response][status_code] < 400 {
        mutate {
          add_field => { "[event][type]" => ["access", "connection", "allowed"] }
          add_field => { "[event][outcome]" => "success" }
        }
      } else {
        mutate {
          add_field => { "[event][type]" => ["access", "connection", "denied"] }
          add_field => { "[event][outcome]" => "failure" }
        }
      }
    }
    date {
      match => ["e2_timestamp", "yyyy.MM.dd HH:mm:ss"]
      timezone => "%{[event][timezone]}"
      remove_field => ["e2_timestamp"]
    }
  }
}

```

But entries with http.response.status code are still ending up with "denied" and "failure":

```auto
    "http.response.status_code": "200",
    "event": {
      "category": [
        "network",
        "web"
      ],
      "type": [
        "access",
        "connection",
        "denied"
      ],
      "outcome": "failure",
      "timezone": "-06:00",
      "kind": "event"
    },

```

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 22, 2020, 9:22pm UTC](https://discuss.elastic.co/t/integer-comparison-not-working/242248/2 "2020-07-22T21:22:09Z")

</div>

In your grok filter you created a field `http.response.status_code` (one field with dots in the name), not `[http][response][status_code]` (nested field). So the field you are trying to convert to integer and use in your condition simply does not exist.

---

<div class="post-metadata">

**Author:** ![opoplawski](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opoplawski/32/40442_2.png) [@opoplawski](https://discuss.elastic.co/u/opoplawski)\
**Post date:** [July 22, 2020, 10:00pm UTC](https://discuss.elastic.co/t/integer-comparison-not-working/242248/3 "2020-07-22T22:00:04Z")

</div>

Egads, somehow I believed that the two notations were equivalent. Is there any difference in how the data is stored in elasticsearch? Is there any advantage of working with one form or the other in logstash? Thank you!

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 23, 2020, 3:35am UTC](https://discuss.elastic.co/t/integer-comparison-not-working/242248/4 "2020-07-23T03:35:39Z")

</div>

Here's a quite recent discussion on that topic:

> [@When to use "Object" field datatype vs flat fieldnames](https://discuss.elastic.co/t/when-to-use-object-field-datatype-vs-flat-fieldnames/217687/2):
>
> In this context, think of JSON objects as namespaces. Related information gets stored under a common root, which makes it easier for humans to identify which bits of the data belong together. Functionally and performance-wise these 3 are equivalent: "source\_ip": "10.20.30.40" "source.ip": "10.20.30.40" "source": { "ip": "10.20.30.40"} The 3rd option groups the related fields in the \_source of a document and makes it easier to read, IMO.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2020, 3:35am UTC](https://discuss.elastic.co/t/integer-comparison-not-working/242248/5 "2020-08-20T03:35:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
