# Logstash conditional statement not working

**URL:** <https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657>\
**Category:** Logstash\
**Created:** [June 22, 2023, 9:04am UTC](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657 "2023-06-22T09:04:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 22, 2023, 9:04am UTC](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657/1 "2023-06-22T09:04:48Z")

</div>

I want to use a conditional statement in my logstash config, so that syslogs are sent to "syslogindex" and other logs are sent to "testindex". I have tried multiple things, but It just does not work. This is my config:

 ![contitionalstatement](https://us1.discourse-cdn.com/elastic/original/3X/a/1/a1b5b65e7c7546849fe183e66f728b3fe1bca8d0.png)

The Logstash log then always shows something like "\_index =\> Testindex, Reason: Could not index event to elasticsearch. Object mapping for [host] tried to parse field [host] as object, but found a concrete value". This tells me that the condition is not working and the logs are sent to the wrong index, which is not configured to take syslogs

How can I make the condition work?

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 22, 2023, 10:04am UTC](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657/2 "2023-06-22T10:04:23Z")

</div>

Hi,

I am not aware that Logstash automatically adds the input name as tag, you could try [adding the tag](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html#plugins-inputs-syslog-tags) manually:

```auto
input {
  syslog {
    port => 514
    tags => ["syslog"]
  }
}

```

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 22, 2023, 10:18am UTC](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657/3 "2023-06-22T10:18:05Z")

</div>

Adding the tag makes the logs go to the correct index now, but I still receive the mapping error. I tried creating a new, simple mapping. But here I receive the error "mapper [message] cannot be changed from type [match\_only\_text] to [text]". This is my mapping:

```plaintext
{
  "properties": {
    "@timestamp": {
      "type": "date"
    },
    "host": {
      "type": "keyword"
    },
    "facility": {
      "type": "keyword"
    },
    "severity": {
      "type": "keyword"
    },
    "message": {
      "type": "text"
    },
    "switch": {
      "type": "keyword"
    },
    "port": {
      "type": "keyword"
    },
    "vlan": {
      "type": "keyword"
    } 
  }
}

```

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 22, 2023, 10:26am UTC](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657/4 "2023-06-22T10:26:34Z")

</div>

You cannot change the mapping of a field when this field already exists. Normally, when using [Index Lifecycle Management](https://www.elastic.co/guide/en/elasticsearch/reference/current/index-lifecycle-management.html), you would update the mapping in the index template and then [rollover](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-rollover-index.html#rollover-index-api-example) the write alias. This creates a new index with the new mapping.  
If you do not use Lifecycle Management, you would need to create a new index manually and point Logstash to it.

---

<div class="post-metadata">

**Author:** ![Shabu](https://avatars.discourse-cdn.com/v4/letter/s/838e76/32.png) [@Shabu](https://discuss.elastic.co/u/Shabu)\
**Post date:** [June 22, 2023, 11:18am UTC](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657/5 "2023-06-22T11:18:14Z")

</div>

I tried changing the mapping again and just removed the fields that would result in a type change error. This way, the fields that were already working were left unchanged and the new ones were added. Thank you for your time

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2023, 11:19am UTC](https://discuss.elastic.co/t/logstash-conditional-statement-not-working/336657/6 "2023-07-20T11:19:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
