# Logstash condition match

**URL:** <https://discuss.elastic.co/t/logstash-condition-match/36207>\
**Category:** Logstash\
**Created:** [December 2, 2015, 5:02pm UTC](https://discuss.elastic.co/t/logstash-condition-match/36207 "2015-12-02T17:02:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [December 2, 2015, 5:02pm UTC](https://discuss.elastic.co/t/logstash-condition-match/36207/1 "2015-12-02T17:02:57Z")

</div>

I have to add one more field , if my condition is true. But its not working.

My condition is " Json message has a field called clientip, if its present then one more filed has to be added with message"

Log Message : **{"Protocol": "http", "Clientid": "2062230369", "clientip": "10.11.12.13"}**

Config :

> input {stdin { codec=\>json }}  
> filter {  
> if "\_jsonparsefailure" in [tags] {  
> drop {}  
> }  
> else {  
> if [clientip] == 'true' {  
> date {  
> match =\> ["timestamp", "YYYY-MM-dd HH:mm:ss"]  
> add\_field =\> { "primary" =\> "%{clientip}"}  
> }  
> }}}  
> output {  
> stdout { codec =\> "rubydebug" }  
> }

But,my condition is failed, this is the output i'm getting

> {  
> "Protocol" =\> "http",  
> "Clientid" =\> "2062230369",  
> "clientip" =\> "10.11.12.13",  
> "@version" =\> "1",  
> "@timestamp" =\> "2015-12-02T16:56:41.462Z",  
> "host" =\> "gugan"  
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 2, 2015, 8:55pm UTC](https://discuss.elastic.co/t/logstash-condition-match/36207/2 "2015-12-02T20:55:04Z")

</div>

But the `clientip` field isn't equal to the string "true" so the condition is false. To check for the presence of a field you can use this:

```auto
if [clientip] {
  ...
}

```

(This way of checking for field existence isn't perfect. If the field exists but contains a false boolean value the condition will evaluate to false.)

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [December 3, 2015, 10:10am UTC](https://discuss.elastic.co/t/logstash-condition-match/36207/3 "2015-12-03T10:10:32Z")

</div>

its not working.

Tested Log : {"Protocol": "http", "Clientid": "2062230369", "clientip": "10.11.12.13", "timesistamp": "2015-06-15 12:45:50"}

> Logstash startup completed  
> {  
> "Protocol" =\> "http",  
> "Clientid" =\> "2062230369",  
> "clientip" =\> "10.11.12.13",  
> "timesistamp" =\> "2015-06-15 12:45:50",  
> "@version" =\> "1",  
> "@timestamp" =\> "2015-12-03T10:07:34.798Z",  
> "host" =\> "gugan"  
> }  
> Logstash shutdown completed  
> root@gugan:~/ELK#

Pasting my config once again Here.:

> filter {

> if "\_jsonparsefailure" in [tags] {  
> drop {}  
> }  
> else {  
> if [clientip] {  
> date {  
> match =\> ["timestamp", "YYYY-MM-dd HH:mm:ss"]  
> target =\> "@timestamp"  
> add\_field =\> { "primary" =\> "%{clientip}"}  
> }  
> geoip {  
> source =\> "clientip"  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 3, 2015, 10:17am UTC](https://discuss.elastic.co/t/logstash-condition-match/36207/4 "2015-12-03T10:17:42Z")

</div>

The conditional probably works fine but

- the date filter doesn't work because the field is named `timesistamp` and not `timestamp` and
- the geoip filter doesn't work because the IP address in `clientip` is in a non-public IP address space that doesn't work with geoip.

---

<div class="post-metadata">

**Author:** ![gugansankar](https://avatars.discourse-cdn.com/v4/letter/g/e274bd/32.png) [@gugansankar](https://discuss.elastic.co/u/gugansankar)\
**Post date:** [December 3, 2015, 11:33am UTC](https://discuss.elastic.co/t/logstash-condition-match/36207/5 "2015-12-03T11:33:55Z")

</div>

OMG. Sorry @magnusbaeck . I troubled you for this silly things.

But, Thanks for your kind reply. Hereafter, I will try to double verify before posting. I thought, Something made mistake on the condition match. but I didn't expect the problem lies there.

About GeoIP, yes I know. geoip would work on Public IP and its not for private IP's.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:20am UTC](https://discuss.elastic.co/t/logstash-condition-match/36207/6 "2017-07-06T05:20:10Z")

</div>


