# Logstash conditional "in" with single element list not working

**URL:** <https://discuss.elastic.co/t/logstash-conditional-in-with-single-element-list-not-working/58807>\
**Category:** Logstash\
**Created:** [August 24, 2016, 11:10am UTC](https://discuss.elastic.co/t/logstash-conditional-in-with-single-element-list-not-working/58807 "2016-08-24T11:10:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thomas\_Larsson\_Kron](https://avatars.discourse-cdn.com/v4/letter/t/9d8465/32.png) [@Thomas\_Larsson\_Kron](https://discuss.elastic.co/u/Thomas_Larsson_Kron)\
**Post date:** [August 24, 2016, 11:10am UTC](https://discuss.elastic.co/t/logstash-conditional-in-with-single-element-list-not-working/58807/1 "2016-08-24T11:10:50Z")

</div>

Hello.

I'm using logstash 2.1.1 and I'm encountering a problem with using the "in" conditional expression to filter out log events that are not of a certain level.

If I have more than one element in the list, everything works, but with only one element in the list all elements get filtered away.

An example log file:

```
$ cat /tmp/thomas/logstash/test.log
2016-01-27 00:44:20,762 INFO some info level message
2016-01-27 00:44:20,763 WARN some warning level message

```

The working config (with two elements in the list):

```
$ cat test.conf
input {
  file {
    path => "/tmp/thomas/logstash/test.log"
    start_position => "beginning"
  }
}

filter {
  grok {
    match => { "message" => "%{TIMESTAMP_ISO8601:time}[\s\-]{1,}%{LOGLEVEL:level} %{GREEDYDATA:msg_rest}" }
  }
  if [level] not in ['WARN', 'INFO'] {
    drop {}
  }
}

output {
  stdout {}
}

```

The output when starting agent:

```
$ /opt/logstash/bin/logstash agent -f /etc/logstash/conf.d
Settings: Default filter workers: 4
Logstash startup completed
2016-08-24T11:03:32.872Z my-hostname 2016-01-27 00:44:20,762 INFO some info level message
2016-08-24T11:03:32.874Z my-hostname 2016-01-27 00:44:20,763 WARN some warning level message

```

If I change the above filter conditional to use a single item list instead like this:

```
filter {
  grok {
    match => { "message" => "%{TIMESTAMP_ISO8601:time}[\s\-]{1,}%{LOGLEVEL:level} %{GREEDYDATA:msg_rest}" }
  }
  if [level] not in ['INFO'] {
    drop {}
  }
}

```

Then I get nothing when running the agent:

```
$ /opt/logstash/bin/logstash agent -f /etc/logstash/conf.d
Settings: Default filter workers: 4
Logstash startup completed

```

Am I blind and have some syntax error in my conf or is it a bug?

Please help, best regards  
/Thomas

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [August 26, 2016, 9:47am UTC](https://discuss.elastic.co/t/logstash-conditional-in-with-single-element-list-not-working/58807/2 "2016-08-26T09:47:02Z")

</div>

If you want a single value, just do - `if [level] not in "INFO"`.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 27, 2016, 2:45pm UTC](https://discuss.elastic.co/t/logstash-conditional-in-with-single-element-list-not-working/58807/3 "2016-08-27T14:45:06Z")

</div>

Yeah, this is a bug.

```nohighlight
$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  if [host] in ['bertie', 'some-other-host'] {
    mutate {
      add_tag => ['match']
    }
  }
}
$ echo 'hello' | logstash -f test.config
Settings: Default pipeline workers: 8
Pipeline main started
{
       "message" => "hello",
      "@version" => "1",
    "@timestamp" => "2016-08-27T14:43:39.554Z",
          "host" => "bertie",
          "tags" => [
        [0] "match"
    ]
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}
$ cat test.config
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  if [host] in ['bertie'] {
    mutate {
      add_tag => ['match']
    }
  }
}
$ echo 'hello' | logstash -f test.config
Settings: Default pipeline workers: 8
Pipeline main started
{
       "message" => "hello",
      "@version" => "1",
    "@timestamp" => "2016-08-27T14:44:19.453Z",
          "host" => "bertie"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:41am UTC](https://discuss.elastic.co/t/logstash-conditional-in-with-single-element-list-not-working/58807/4 "2017-07-06T04:41:20Z")

</div>


