# Issue with conditional in output definition

**URL:** <https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612>\
**Category:** Logstash\
**Created:** [January 31, 2019, 4:46pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612 "2019-01-31T16:46:38Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![wanexa](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@wanexa](https://discuss.elastic.co/u/wanexa)\
**Post date:** [January 31, 2019, 4:46pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/1 "2019-01-31T16:46:38Z")

</div>

trying to put two conditions on my output for grok or geopip failure  
I tried :  
if ("\_grokparsefailure" not in [tags] or "\_geoip\_lookup\_failure" not in [tags])  
if "\_grokparsefailure" not in [tags] or "\_geoip\_lookup\_failure" not in [tags]  
if "\_grokparsefailure" or "\_geoip\_lookup\_failure" not in [tags]  
if ("\_grokparsefailure" or "\_geoip\_lookup\_failure" not in [tags])  
if "\_grokparsefailure" not in [tags] {  
...  
}  
else if "\_geoip\_lookup\_failure" not in [tags] [  
..  
}

stiil get "Invalid index name [xxx,\_geoip\_lookup\_failure-2019.01.31]

Can you help me please

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2019, 4:53pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/2 "2019-01-31T16:53:19Z")

</div>

You cannot have a comma in an index name.

You can see what is not allowed by looking at the [tests](https://github.com/elastic/elasticsearch/blob/608a61ab85e82f8f6e88002ba7d8458411e7da62/core/src/test/java/org/elasticsearch/cluster/metadata/MetaDataCreateIndexServiceTests.java#L188-L202) (also [here](https://github.com/elastic/elasticsearch/blob/68ed72b92395fdbc777cad9046a6be4d695b9cd4/server/src/main/java/org/elasticsearch/common/Strings.java#L376)).

---

<div class="post-metadata">

**Author:** ![wanexa](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@wanexa](https://discuss.elastic.co/u/wanexa)\
**Post date:** [January 31, 2019, 4:55pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/3 "2019-01-31T16:55:05Z")

</div>

I know that s not the point I talk about conditional , works with if "\_grokparsefailure" not in [tags] {  
trying with two conditions!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2019, 5:04pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/4 "2019-01-31T17:04:09Z")

</div>

> [@wanexa](#):
>
> if ("\_grokparsefailure" not in [tags] or "\_geoip\_lookup\_failure" not in [tags])

OK, so that evaluates to false on events that have both tags, otherwise true. Is that what you want? If not, what do you want?

---

<div class="post-metadata">

**Author:** ![wanexa](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@wanexa](https://discuss.elastic.co/u/wanexa)\
**Post date:** [January 31, 2019, 5:07pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/5 "2019-01-31T17:07:30Z")

</div>

so that evaluates to false on events that have both tags --\> not both tags at least one of them

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2019, 5:10pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/6 "2019-01-31T17:10:15Z")

</div>

> [@Badger](#):
>
> if ("\_grokparsefailure" not in [tags] or "\_geoip\_lookup\_failure" not in [tags])

If a document has \_grokparsefailure but not \_geoip\_lookup\_failure then that evaluates to (false or true), which evaluates to true.

Perhaps you want

```
if ("_grokparsefailure" in [tags] or "_geoip_lookup_failure" in [tags]) {
    # One or both
} else {
    # Neither
}

```

---

<div class="post-metadata">

**Author:** ![wanexa](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@wanexa](https://discuss.elastic.co/u/wanexa)\
**Post date:** [January 31, 2019, 5:13pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/7 "2019-01-31T17:13:27Z")

</div>

I want if ("\_grokparsefailure" not in [tags] or "\_geoip\_lookup\_failure" not in [tags]) --\> don t work !! stiil get "Invalid index name [xxx,\_geoip\_lookup\_failure-2019.01.31]  
"or" in the condition seems not working with "(" or not

---

<div class="post-metadata">

**Author:** ![wanexa](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@wanexa](https://discuss.elastic.co/u/wanexa)\
**Post date:** [January 31, 2019, 6:05pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/8 "2019-01-31T18:05:08Z")

</div>

Ok the problem is logstash can't have two "not in" conditions  
`if ("_grokparsefailure" not in [tags] or "_geoip_lookup_failure" not in [tags])`--\> don t work

`if "_grokparsefailure" not in [tags] { ... } if "_geoip_lookup_failure" not in [tags] [ .. }`--\> dont work

how to get rid of it ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2019, 6:24pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/9 "2019-01-31T18:24:47Z")

</div>

> [@wanexa](#):
>
> Ok the problem is logstash can't have two "not in" conditions

This is not true. It may not work the way you want it to, but it works.

---

<div class="post-metadata">

**Author:** ![wanexa](https://avatars.discourse-cdn.com/v4/letter/w/858c86/32.png) [@wanexa](https://discuss.elastic.co/u/wanexa)\
**Post date:** [January 31, 2019, 6:37pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/10 "2019-01-31T18:37:29Z")

</div>

it s true it s not working  
`if ("_grokparsefailure" not in [tags] or "_geoip_lookup_failure" not in [tags])`  
try it and you ll see in logstash's output

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2019, 6:37pm UTC](https://discuss.elastic.co/t/issue-with-conditional-in-output-definition/166612/11 "2019-02-28T18:37:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
