# Logstash - comparison 2 fields

**URL:** <https://discuss.elastic.co/t/logstash-comparison-2-fields/291692>\
**Category:** Logstash\
**Created:** [December 13, 2021, 4:38pm UTC](https://discuss.elastic.co/t/logstash-comparison-2-fields/291692 "2021-12-13T16:38:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Christophe\_Journel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christophe_journel/32/12534_2.png) [@Christophe\_Journel](https://discuss.elastic.co/u/Christophe_Journel)\
**Post date:** [December 13, 2021, 4:38pm UTC](https://discuss.elastic.co/t/logstash-comparison-2-fields/291692/1 "2021-12-13T16:38:59Z")

</div>

Hello.  
I would like to compare 2 fields using logstash.  
To be more precise, i would like to know id the content of one field is included into the other one, using ( regex)

i tried this configuration

```auto
   if ( [test][field1] and [test][field2]){
     if ([test][field2] =~ /.*%{[test][field1]}/) {
       mutate {
         add_field => { "DiffRegexp" => "true" }
       }
     } 
   }

```

However, That 's not working.

Any help would be appreciated

Thanks !

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 13, 2021, 6:06pm UTC](https://discuss.elastic.co/t/logstash-comparison-2-fields/291692/2 "2021-12-13T18:06:25Z")

</div>

No sprintf substitution is done on conditionals

```
    mutate { add_field => { "[a]" => "foo%{b}" } }
    mutate { add_field => { "[b]" => "bar" } }

    if "%{b}" in [a] { mutate { add_field => { "[c]" => "baz" } } }

```

will add the field [c]. You can use a ruby filter

```
    ruby {
        code => '
            a = event.get("a"); b = event.get("b")
            if a and b and a.include? b
                event.set("c", "baz")
            end
        '
    }
```

---

<div class="post-metadata">

**Author:** ![Christophe\_Journel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christophe_journel/32/12534_2.png) [@Christophe\_Journel](https://discuss.elastic.co/u/Christophe_Journel)\
**Post date:** [December 14, 2021, 11:47am UTC](https://discuss.elastic.co/t/logstash-comparison-2-fields/291692/3 "2021-12-14T11:47:48Z")

</div>

Thank you @Badger , this is indeed the solution 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 11, 2022, 11:48am UTC](https://discuss.elastic.co/t/logstash-comparison-2-fields/291692/4 "2022-01-11T11:48:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
