# LogStash Conditional IN (Check values from a List)

**URL:** <https://discuss.elastic.co/t/logstash-conditional-in-check-values-from-a-list/61865>\
**Category:** Logstash\
**Created:** [September 29, 2016, 8:36pm UTC](https://discuss.elastic.co/t/logstash-conditional-in-check-values-from-a-list/61865 "2016-09-29T20:36:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ELK\_User](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@ELK\_User](https://discuss.elastic.co/u/ELK_User)\
**Post date:** [September 29, 2016, 8:36pm UTC](https://discuss.elastic.co/t/logstash-conditional-in-check-values-from-a-list/61865/1 "2016-09-29T20:36:40Z")

</div>

Hi,  
I am trying to find out if there's a way for me to generate a **Conditional IN based** output  
from incoming Apache Log response codes.  
I want to compare the Codes from a **Declared List/Array** of Codes

My config is;  
input {  
beats { port =\> "5044" }  
}  
filter {  
grok { match =\> { "message" =\> "%{COMBINEDAPACHELOG}" } }  
}  
output {  
if [response] in ["200","202"] {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}  
}  
}

The above works fine, but I want to do something like,  
output {  
if [response] in [VALID\_RESPONSE\_CODES\_] {  
elasticsearch { hosts =\> ["localhost:9200"] }  
}  
if [response] in [INVALID\_RESPONSE\_CODES\_] {  
....  
}  
}

How do I declare the above two (VALID\_RESPONSE\_CODES) as Arrays (List) in the Config file.  
Ideally, I would like these to be separate **conf files** with just these two arrays declared ?

Any help is greatly appreciated.  
thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 30, 2016, 5:49am UTC](https://discuss.elastic.co/t/logstash-conditional-in-check-values-from-a-list/61865/2 "2016-09-30T05:49:54Z")

</div>

The configuration language doesn't support constants. Using the translate filter to look up error codes and add a separate field is one option. You could also generate the configuration files using a template language.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:36am UTC](https://discuss.elastic.co/t/logstash-conditional-in-check-values-from-a-list/61865/3 "2017-07-06T04:36:20Z")

</div>


