# Journalbeat processor logical operators fail with expanded notation

**URL:** <https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813>\
**Category:** Beats\
**Tags:** journalbeat\
**Created:** [May 21, 2020, 9:00pm UTC](https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813 "2020-05-21T21:00:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Disconn3ct](https://avatars.discourse-cdn.com/v4/letter/d/59ef9b/32.png) [@Disconn3ct](https://discuss.elastic.co/u/Disconn3ct)\
**Post date:** [May 21, 2020, 9:00pm UTC](https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813/1 "2020-05-21T21:00:22Z")

</div>

- Version: 7.6.1
- Operating System: Ubuntu 16.04

Creating a journalbeat configuration using logical operators according to the documentation causes failures:

```auto
processors:
  - drop_event:
      when:
        or:
          - equals:
              systemd.unit: "another-random.service"
          - equals:
              systemd.unit: "journalbeat.service"

```

On start: `Exiting: error initializing processors: failed to initialize condition: missing or invalid condition`

Collapsing the `equals` into dot-notated entries works:

```auto
processors:
  - drop_event:
      when:
        or:
          - equals.systemd.unit: "another-random.service"
          - equals.systemd.unit: "journalbeat.service"

```

Huge thanks to mark54g and csaide for help with the workaround!

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 1, 2020, 9:41pm UTC](https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813/2 "2020-06-01T21:41:01Z")

</div>

Hi welcome to the board,

this doesn't sound much like something to solve here, but more to shout out kudos for the 2 folks.

Am I correct or do I miss here something?

---

<div class="post-metadata">

**Author:** ![Disconn3ct](https://avatars.discourse-cdn.com/v4/letter/d/59ef9b/32.png) [@Disconn3ct](https://discuss.elastic.co/u/Disconn3ct)\
**Post date:** [June 2, 2020, 2:17pm UTC](https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813/3 "2020-06-02T14:17:28Z")

</div>

From the bug report page:

> Please post all questions and issues on [Beats - Discuss the Elastic Stack](https://discuss.elastic.co/c/beats)  
> before opening a Github Issue. Your questions will reach a wider audience there,  
> and if we confirm that there is a bug, then you can open a new issue.

So here is my bug report, please feel free to manage it however your process requires. Everything needed to reproduce is above, but if it does become an issue please tag me (vir-dis) so that I can monitor.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 3, 2020, 11:54pm UTC](https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813/4 "2020-06-03T23:54:48Z")

</div>

Ah, ok. I got it.

But in this case this doesn't seem to be really a bug, but more an indentation issue:  
Can you try please something like that?

```auto
processors:
- drop_event:
    when:
      or:
      - equals:
          systemd:
            unit: another-random.service
      - equals:
          systemd:
            unit: journalbeat.service

```

[https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#condition-equals](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#condition-equals)  
[https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#condition-or](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html#condition-or)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 7:59am UTC](https://discuss.elastic.co/t/journalbeat-processor-logical-operators-fail-with-expanded-notation/233813/5 "2022-11-04T07:59:17Z")

</div>


