# Logstash: Comparison of two variables

**URL:** <https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464>\
**Category:** Logstash\
**Created:** [February 29, 2024, 4:15pm UTC](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464 "2024-02-29T16:15:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![moep](https://avatars.discourse-cdn.com/v4/letter/m/ad7895/32.png) [@moep](https://discuss.elastic.co/u/moep)\
**Post date:** [February 29, 2024, 4:15pm UTC](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464/1 "2024-02-29T16:15:27Z")

</div>

I wrote a logstash config like that, with a lot of `if [message]`. In this example code below, Im filtering logs and have the problem, that a grok named `(%{EMAILADDRESS:sender})` (the opposide of `(%{EMAILADDRESS:recipient})` ) is written in my output, which I don't use in this `if` block . I don't get any grokparse errors and I'm 100% in this `if` block. For debugging reasons I named to something else and the result was how I assumed.  
So my (nasty) idea for a workaround is like `(%{EMAILADDRESS:recipient}) == (%{EMAILADDRESS:sender})` then `remove_field => "sender"`.

What's the syntax for comparing these both pattern?

```auto
input { 
        file {
                id => "main"
                path => "/usr/share/logstash/mainlog.log"
                sincedb_path => "/dev/null"
                start_position => "beginning"
        }
        stdin { } 
}
filter { 

[…]
            if [flags] == "**" {
			if [message] =~ "SMTP error from remote mail server after RCPT TO" {
				grok {
					"match" => { "message" => " (%{EMAILADDRESS:recipient})" }
				}
				mutate {
					update => { "exim_msg_state" => "error from remote" }
					lowercase => ["recipient"]
				}
			}
                }

[…]

}

output {
        elasticsearch { 
                hosts => ["elasticsearch:9200"]
        }
        stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 29, 2024, 5:35pm UTC](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464/2 "2024-02-29T17:35:17Z")

</div>

Hello,

It is not really clear what you are trying to do and what is your issue.

> [@moep](#):
>
> (%{EMAILADDRESS:recipient}) == (%{EMAILADDRESS:sender})

You can't have conditionals inside a grok pattern, you can just compare fields by using `if [recipient] == [sender]`

Can you provide more context and some sample documents of what you are trying to achieve and what is the result?

---

<div class="post-metadata">

**Author:** ![moep](https://avatars.discourse-cdn.com/v4/letter/m/ad7895/32.png) [@moep](https://discuss.elastic.co/u/moep)\
**Post date:** [February 29, 2024, 5:42pm UTC](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464/3 "2024-02-29T17:42:11Z")

</div>

sure I can.

this example below was just for example in in "pseudocode". I tested it in this way.  
My idea was to compare, if in the ` (%{EMAILADDRESS:recipient})` is equal to ` (%{EMAILADDRESS:sender})`. If yes, then remove field `sender`.  
So I have to check if the contenct is equal and put `remove_field` in the `mutate` block.

Edit: thank you for this solution it works now,

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 1, 2024, 2:45am UTC](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464/4 "2024-03-01T02:45:48Z")

</div>

Can you show that part of .conf, how have you implemented?

---

<div class="post-metadata">

**Author:** ![moep](https://avatars.discourse-cdn.com/v4/letter/m/ad7895/32.png) [@moep](https://discuss.elastic.co/u/moep)\
**Post date:** [March 1, 2024, 10:36pm UTC](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464/5 "2024-03-01T22:36:14Z")

</div>

> [@Rios](#):
>
> Can you show that part of .conf, how have you implemented?

yes.

```auto
input { 
        file {
                id => "main"
                path => "/usr/share/logstash/mainlog.log"
                sincedb_path => "/dev/null"
                start_position => "beginning"
        }
        stdin { } 
}
filter { 

[…]
            if [flags] == "**" {
			if [message] =~ "SMTP error from remote mail server after RCPT TO" {
				grok {
					"match" => { "message" => " (%{EMAILADDRESS:recipient})" }
				}
				mutate {
					update => { "exim_msg_state" => "error from remote" }
					lowercase => ["recipient"]
				}
                                if [recipient] == [sender] {
                                   # dirty workaround
                                    mutate {
                                      remove_field => "sender"
                                    }
                          }
			}
                }

[…]

}

output {
        elasticsearch { 
                hosts => ["elasticsearch:9200"]
        }
        stdout { codec => rubydebug }
}

```

edit: I know the yml syntax doesnt looks nice. I hope you can read and understand it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2024, 10:36pm UTC](https://discuss.elastic.co/t/logstash-comparison-of-two-variables/354464/6 "2024-03-29T22:36:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
