# Logstash compare one field with multiple value (string)

**URL:** <https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315>\
**Category:** Logstash\
**Created:** [February 20, 2016, 5:56pm UTC](https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315 "2016-02-20T17:56:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![gnoale](https://avatars.discourse-cdn.com/v4/letter/g/b9bd4f/32.png) [@gnoale](https://discuss.elastic.co/u/gnoale)\
**Post date:** [February 20, 2016, 5:56pm UTC](https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315/1 "2016-02-20T17:56:11Z")

</div>

Hi there,

This is the configuration I am using for debugging purpose.  
The goal is basically to filter sources hosts to apply appropriate filter to the messages, and add a tag to distinguish them in elasticsearch.

```
input {
     syslog {
         port => 5114
     }
}

filter {
    # vtiger
    if [host] == "192.168.40.140" or [host] == "192.168.40.141" {
        grok {
            match => { "message" => "%{COMBINEDAPACHELOG}"}
        }
        mutate {
            add_tag => ["vtiger"]
        }
    }
    # NetScaler
    else if [host] == "192.168.41.111" {
        grok {
            # AppFirewall - CEF mode ON
            match => { "message" => "%{NOTSPACE} %{NOTSPACE}(?<security_check>(APPFW_[^\s|]+))%{DATA}%{IP:clientip} %{NOTSPACE} %{WORD}=%{WORD:verb} %{WORD}=%{NOTSPACE:request} %{WORD}=%{GREEDYDATA:explanation} cn1=%{WORD} cn2=%{WORD} cs1=%{WORD:profile} %{GREEDYDATA} act=%{GREEDYDATA:action}"}
        }
        mutate {
            add_tag => ["NetScaler AppFw"]
            remove_tag => ["_grokparsefailure_sysloginput"]
            remove_field => ["facility","priority","severity"]
        }
    }
}

output {
     stdout { codec => rubydebug }
}

```

This configuration is working, but I find odd that I cannot simply write this :  
`if [host] == ("192.168.40.140" or "192.168.40.141")`

If I do, an exception is triggered

The question is in the subject 🙂  
Maybe I am missing a point ?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 21, 2016, 8:10pm UTC](https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315/2 "2016-02-21T20:10:13Z")

</div>

> [@gnoale](#):
>
> if [host] == ("192.168.40.140" or "192.168.40.141")

Try `if [host] == "192.168.40.140" or [host] == "192.168.40.141"`.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2016, 6:19pm UTC](https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315/3 "2016-02-22T18:19:41Z")

</div>

> This configuration is working, but I find odd that I cannot simply write this :  
> `if [host] == ("192.168.40.140" or "192.168.40.141")`

I don't know of a single programming language where this works the way you want it to. Another way of accomplishing what you want is this:

```
if [host] in ["192.168.40.140", "192.168.40.141"] {

```

---

<div class="post-metadata">

**Author:** ![gnoale](https://avatars.discourse-cdn.com/v4/letter/g/b9bd4f/32.png) [@gnoale](https://discuss.elastic.co/u/gnoale)\
**Post date:** [February 22, 2016, 9:06pm UTC](https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315/4 "2016-02-22T21:06:48Z")

</div>

Thanks @magnusbaeck I will do that.

> I don't know of a single programming language where this works the way you want it to

Proof of concept in Python :

```
>>> toto = 4
>>> 
>>> if toto == (4 or 3):
... print "It works"
... 
It works
>>> if toto == (2 or 3):
... print "It works"
... 
>>>

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2016, 9:13pm UTC](https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315/5 "2016-02-22T21:13:19Z")

</div>

Yes, that happened to work since `4 or 3` evaluates to `4`. Try reversing the order:

```auto
$ python
Python 2.7.11 (default, Jan 11 2016, 21:04:40)
[GCC 5.3.1 20160101] on linux2
Type "help", "copyright", "credits" or "license" for more information.
>>> toto = 4
>>> if toto == (3 or 4):
... print "It works"
...
>>>

```

---

<div class="post-metadata">

**Author:** ![gnoale](https://avatars.discourse-cdn.com/v4/letter/g/b9bd4f/32.png) [@gnoale](https://discuss.elastic.co/u/gnoale)\
**Post date:** [February 22, 2016, 9:25pm UTC](https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315/6 "2016-02-22T21:25:46Z")

</div>

Ah okay, Thanks for pointing that out !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:10am UTC](https://discuss.elastic.co/t/logstash-compare-one-field-with-multiple-value-string/42315/7 "2017-07-06T05:10:14Z")

</div>


