# Issues with if statement, grok, and mutate

**URL:** <https://discuss.elastic.co/t/issues-with-if-statement-grok-and-mutate/24754>\
**Category:** Logstash\
**Created:** [July 1, 2015, 7:33pm UTC](https://discuss.elastic.co/t/issues-with-if-statement-grok-and-mutate/24754 "2015-07-01T19:33:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![naisanza](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/naisanza/32/44808_2.png) [@naisanza](https://discuss.elastic.co/u/naisanza)\
**Post date:** [July 1, 2015, 7:33pm UTC](https://discuss.elastic.co/t/issues-with-if-statement-grok-and-mutate/24754/1 "2015-07-01T19:33:09Z")

</div>

I'm having issues with a conditional statement. I have a grok filter used to parse through a dataset, of which a field named `domain` will be created. Then, I want a regex conditional to check if that field matches `%{HOST}` and if it does, use `mutate` to `add_field` a new field `"hostname" => "%{domain}"`

However, when parsed the new field is not created.

When explicitly added to the `grok` filter as an `add_field` line, it works. However, I won't be able to run a verification check on it.

Working version:

```auto
filter {
    if [dataType] == "domainIQ" {
    grok {
        # Main regex
        match => ["message", "\A%{HOST:domain},%{IPV4:domainIP},%{IPV4:ip.subnet},([-]||(%{HOST:mx})),([-]||(%{IPV4:mxIP})),([-]||(?<dns>[a-zA-Z0-9.]+)),\"?([Uu]nknown|(?<isp>[a-zA-Z0-9ÁÉÍÓÚ-áéíóu-ñÑ .,+'*&\\#~\-_(){}?=:/]+))\"?,\"?([Uu]nknown|(?<ispCity>[a-zA-Z .]+))\"?,([Uu]nknown|(?<ispRegion>([a-zA-Z]+)|([a-zA-Z]{2}))),\"?([Uu]nknown|(?<ispCountry>[a-zA-Z #]+|[a-zA-Z]{2}))\"?,\"?([Uu]nknown|(?<domainIPorg>[a-zA-Z0-9ÁÉÍÓÚ-áéíóu-ñÑ .,+'*&\\#~\-_(){}?=:/]+))\"?,\"?([Uu]nkown|(?<domainOrgCity>[a-zA-Z .]+))\"?,([Uu]nknown|(?<domainOrgRegion>[a-zA-Z0-9]+)),\"?([Uu]nknown|(?<domainOrgCountry>[a-zA-Z #]+|[a-zA-Z]{2}))\"?" ]

        add_field => { "hostname" => "%{domain}" }
            add_field => { "dataSource" => "http://www.domainiq.com/bulk_whois_ip" }
            tag_on_failure => ["_grokparsefailure", "1003_filter-domainiq.conf"]
    }
    }
}

```

Non-working Version 1:

```auto
filter {
    if [dataType] == "domainIQ" {
    grok {
        # Main regex
        match => ["message", "\A%{HOST:domain},%{IPV4:domainIP},%{IPV4:ip.subnet},([-]||(%{HOST:mx})),([-]||(%{IPV4:mxIP})),([-]||(?<dns>[a-zA-Z0-9.]+)),\"?([Uu]nknown|(?<isp>[a-zA-Z0-9ÁÉÍÓÚ-áéíóu-ñÑ .,+'*&\\#~\-_(){}?=:/]+))\"?,\"?([Uu]nknown|(?<ispCity>[a-zA-Z .]+))\"?,([Uu]nknown|(?<ispRegion>([a-zA-Z]+)|([a-zA-Z]{2}))),\"?([Uu]nknown|(?<ispCountry>[a-zA-Z #]+|[a-zA-Z]{2}))\"?,\"?([Uu]nknown|(?<domainIPorg>[a-zA-Z0-9ÁÉÍÓÚ-áéíóu-ñÑ .,+'*&\\#~\-_(){}?=:/]+))\"?,\"?([Uu]nkown|(?<domainOrgCity>[a-zA-Z .]+))\"?,([Uu]nknown|(?<domainOrgRegion>[a-zA-Z0-9]+)),\"?([Uu]nknown|(?<domainOrgCountry>[a-zA-Z #]+|[a-zA-Z]{2}))\"?" ]

        #add_field => { "hostname" => "%{domain}" }
        add_field => { "dataSource" => "http://www.domainiq.com/bulk_whois_ip" }
        tag_on_failure => ["_grokparsefailure", "1003_filter-domainiq.conf"]
    }
        if [domain] =~ "%{HOST}" { mutate { add_field => { "hostname" => "%{domain}" }}}
        if [domainIP] =~ "%{IPV4}" { mutate { add_field => { "ip" => "%{domainIP}" }}}
    
        if [mx] =~ "%{HOST}" { mutate { add_field => { "hostname" => "%{mx}" }}}    
        if [mxIP] =~ "%{IPV4}" { mutate { add_field => { "ip" => "%{mxIP}" }}}
    }
}

```

Non-working Version 2:

```auto
filter {
    if [dataType] == "domainIQ" {
    grok {
        # Main regex
        match => ["message", "\A%{HOST:domain},%{IPV4:domainIP},%{IPV4:ip.subnet},([-]||(%{HOST:mx})),([-]||(%{IPV4:mxIP})),([-]||(?<dns>[a-zA-Z0-9.]+)),\"?([Uu]nknown|(?<isp>[a-zA-Z0-9ÁÉÍÓÚ-áéíóu-ñÑ .,+'*&\\#~\-_(){}?=:/]+))\"?,\"?([Uu]nknown|(?<ispCity>[a-zA-Z .]+))\"?,([Uu]nknown|(?<ispRegion>([a-zA-Z]+)|([a-zA-Z]{2}))),\"?([Uu]nknown|(?<ispCountry>[a-zA-Z #]+|[a-zA-Z]{2}))\"?,\"?([Uu]nknown|(?<domainIPorg>[a-zA-Z0-9ÁÉÍÓÚ-áéíóu-ñÑ .,+'*&\\#~\-_(){}?=:/]+))\"?,\"?([Uu]nkown|(?<domainOrgCity>[a-zA-Z .]+))\"?,([Uu]nknown|(?<domainOrgRegion>[a-zA-Z0-9]+)),\"?([Uu]nknown|(?<domainOrgCountry>[a-zA-Z #]+|[a-zA-Z]{2}))\"?" ]

        #add_field => { "hostname" => "%{domain}" }
        add_field => { "dataSource" => "http://www.domainiq.com/bulk_whois_ip" }
        tag_on_failure => ["_grokparsefailure", "1003_filter-domainiq.conf"]
    }
    }
}

filter {
    if [dataType] == "domainIQ" {
        if [domain] =~ "%{HOST}" { mutate { add_field => { "hostname" => "%{domain}" }}}
        if [domainIP] =~ "%{IPV4}" { mutate { add_field => { "ip" => "%{domainIP}" }}}
    
        if [mx] =~ "%{HOST}" { mutate { add_field => { "hostname" => "%{mx}" }}}    
        if [mxIP] =~ "%{IPV4}" { mutate { add_field => { "ip" => "%{mxIP}" }}}
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/issues-with-if-statement-grok-and-mutate/24754/2 "2017-07-06T05:35:47Z")

</div>


