# Logstash conditional test for value in a field

**URL:** <https://discuss.elastic.co/t/logstash-conditional-test-for-value-in-a-field/251968>\
**Category:** Logstash\
**Created:** [October 13, 2020, 8:43pm UTC](https://discuss.elastic.co/t/logstash-conditional-test-for-value-in-a-field/251968 "2020-10-13T20:43:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zorkmid](https://avatars.discourse-cdn.com/v4/letter/z/e68b1a/32.png) [@Zorkmid](https://discuss.elastic.co/u/Zorkmid)\
**Post date:** [October 13, 2020, 8:43pm UTC](https://discuss.elastic.co/t/logstash-conditional-test-for-value-in-a-field/251968/1 "2020-10-13T20:43:05Z")

</div>

Hello all,

Is the follow correct for testing for the presence of a value and then applying the appropriate grok filter? The event types, urlfLog, accessLog all arrive in the same syslog input stream and I'd like to test and apply grok formatting to them before passing the events to the output stage.

```auto
    filter {
            	if [logname] == "urlfLog" {
            	 grok {
            		 patterns_dir => ["/etc/logstash/patterns"]
            		 match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{WORD:logname}, applianceName=%{textDef:applianceName}, tenantName=%{textDef:tenantName}, flowId=%{NONNEGINT:flowId}, flowCookie=%{NONNEGINT:flowCookie} " }
            			 }
            	} else if [logname] == "accessLog" {
            	 grok {
            		 patterns_dir => ["/etc/logstash/patterns"]
            		 match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{WORD:logname}, applianceName=%{textDef:applianceName}, tenantName=%{textDef:tenantName}, flowId=%{NONNEGINT:flowId}, flowCookie=%{NONNEGINT:flowCookie}, flowStartMilliseconds=%{NONNEGINT:flowStartMilliseconds}"}
            		 } 
            	} 
         }

```

Regards  
TimW

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 13, 2020, 8:45pm UTC](https://discuss.elastic.co/t/logstash-conditional-test-for-value-in-a-field/251968/2 "2020-10-13T20:45:52Z")

</div>

> [@Zorkmid](#):
>
> Is the follow correct for testing for the presence of a value and then applying the appropriate grok filter?

Looks OK to me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 10, 2020, 8:45pm UTC](https://discuss.elastic.co/t/logstash-conditional-test-for-value-in-a-field/251968/3 "2020-11-10T20:45:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
