# Logstash conditions not working as expected

**URL:** <https://discuss.elastic.co/t/logstash-conditions-not-working-as-expected/166625>\
**Category:** Logstash\
**Created:** [January 31, 2019, 6:07pm UTC](https://discuss.elastic.co/t/logstash-conditions-not-working-as-expected/166625 "2019-01-31T18:07:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![JeremyinNC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremyinnc/32/44868_2.png) [@JeremyinNC](https://discuss.elastic.co/u/JeremyinNC)\
**Post date:** [January 31, 2019, 6:07pm UTC](https://discuss.elastic.co/t/logstash-conditions-not-working-as-expected/166625/1 "2019-01-31T18:07:58Z")

</div>

I am trying to determine why the last part of my outputs is failing (when not remarked out). Here is my configuration. Would someone help me figure out why it's failing? It's saying I am missing

```
 output {
  if [type] == "dlq" {
    kafka {
     message_key => "%{userId}"
    topic_id => "core.device.events.dlq"
    compression_type => "snappy"
    codec => "json"
    }
} 
# Handle Device Responses  
   else if [type] == "device-response" {
   kafka {
    message_key => "%{userId}"
    topic_id => "core.device.commands.%{operation}.response"
    compression_type => "snappy"
    codec => "json"
   }
 } 
# ALL Messages go to events.all
else {
  kafka {
    message_key => "%{userId}"
    topic_id => "core.device.events.all"
    compression_type => "snappy"
    codec => "json"
  }

  # Create per-deviceType topics - Need to create the topics in Kafka when adding a new deviceType!
  kafka {
    message_key => "%{userId}"
    topic_id => "core.device.events.%{deviceType}"
    compression_type => "snappy"
    codec => "json"
` }

# Create per-operation topics - Need to create the topics in Kafka when adding a new operation!       
# if [operation] == "alarm" or [operation] == "remove-staged-software" or [operation] == "file-upload" {
# {
# message_key => "%{userId}"
# topic_id => "core.device.event.%{operation}"
# compression_type => "snappy"
# codec => "json"
# }
# }
 }

```

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2019, 6:31pm UTC](https://discuss.elastic.co/t/logstash-conditions-not-working-as-expected/166625/2 "2019-01-31T18:31:32Z")

</div>

> [@JeremyinNC](#):
>
> ```
> # if [operation] == "alarm" or [operation] == "remove-staged-software" or [operation] == "file-upload" { 
> # {
> 
> ```

Appears to be missing the word kafka.

---

<div class="post-metadata">

**Author:** ![JeremyinNC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremyinnc/32/44868_2.png) [@JeremyinNC](https://discuss.elastic.co/u/JeremyinNC)\
**Post date:** [January 31, 2019, 7:04pm UTC](https://discuss.elastic.co/t/logstash-conditions-not-working-as-expected/166625/3 "2019-01-31T19:04:48Z")

</div>

Wow, thank you. Stupid mistake but at least it's easy to fix.

Thank you so much.

---

<div class="post-metadata">

**Author:** ![JeremyinNC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremyinnc/32/44868_2.png) [@JeremyinNC](https://discuss.elastic.co/u/JeremyinNC)\
**Post date:** [January 31, 2019, 7:34pm UTC](https://discuss.elastic.co/t/logstash-conditions-not-working-as-expected/166625/4 "2019-01-31T19:34:46Z")

</div>

Well that was a typo from cutting and pasting into this wonderful UI when I was trying to get it to blockquote. The error is

```
 "[FATAL] 2019-01-31 19:31:02.427 [LogStash::Runner] runner - The given configuration is invalid. Reason: Expected one of #, and, or, xor, nand, { at line 96, column 40 (byte 2522) after output {" 

```

Here is the failing config:

```
input {
  stomp {
    destination => "consumer.kafka-core.virtual.topic.out.events.all"
    codec => "json"
    host => "mq"
    type => "device-events"
    }
  stomp {
    destination => "consumer.kafka-core.virtual.topic.out.commands.all"
    codec => "json"
    host => "mq"
    type => "commands"
    }
  stomp {
    destination => "consumer.kafka-core.virtual.topic.out.DLQ.all"
    codec => "json"
    host => "mq"
    type => "dlq"
    }
  stomp {
    destination => "consumer.kafka-core.virtual.topic.out.response.all"
    codec => "json"
    host => "mq"
    type => "device-response"
  }
 }

# Filters
filter {
# For incoming events from devices
  if [type] == "device-events" {  
    mutate {
      replace => { "type" => "event-%{deviceType}-%{operation}" }
      }
    }

# Rules for outgoing commands sent to devices
  if [type] == "commands" {
     mutate {
       remove_field => ["[payload][cert]" ]
       remove_field => ["[payload][pwd]" ]
       }
     mutate {
       replace => { "type" => "command-%{deviceType}-%{operation}" }
       }
     }

# Rules for ALL messages
  mutate {
       lowercase => ["type"]
       }
  date {
       locale => en
       match => ["sentTimestamp" , "dd/MMM/yyyy:HH:mm:ss Z" , "yyyy-MM-dd HH:mm:ss,SSS" , "yyy-MM-dd HH:mm:ss,SSSZ" , "ISO8601"]
       }
  }

# Outputs
output {
# Handle Dead Letter Messages  
  if [type] == "dlq" {
    kafka {
      message_key => "%{siteId}"
      topic_id => "core.device.events.dlq"
      compression_type => "snappy"
      codec => "json"
      }
  } 
# Handle Device Responses  
    else if [type] == "device-response" {
    kafka {
      message_key => "%{siteId}"
      topic_id => "core.device.commands.%{operation}.response"
      compression_type => "snappy"
      codec => "json"
      }
  } 

# ALL Messages go to events.all
    kafka {
      message_key => "%{siteId}"
      topic_id => "core.device.events.all"
      compression_type => "snappy"
      codec => "json"
    }

  # Create per-deviceType topics - Need to create the topics in Kafka when adding a new deviceType!
      kafka {
        message_key => "%{siteId}"
        topic_id => "core.device.events.%{deviceType}"
        compression_type => "snappy"
        codec => "json"
       }
  
  # Create per-operation topics - Need to create the topics in Kafka when adding a new operation!       
       if [operation] == "alarm-event" OR [operation] == "remove-staged-software-event" OR [operation] == "file-upload-event" {
           kafka {
             message_key => "%{siteId}"
             topic_id => "core.device.event.%{operation}"
             compression_type => "snappy"
             codec => "json"
           }
       }
     }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2019, 7:47pm UTC](https://discuss.elastic.co/t/logstash-conditions-not-working-as-expected/166625/5 "2019-01-31T19:47:09Z")

</div>

Two ways forward. Go to line 96 and then 40 columns in you find your self on the O of OR on this line

```
 if [operation] == "alarm-event" OR [operation]

```

Or read the error message

```
 after output {\n# Handle Dead Letter Messages [...] if [operation] == \"alarm-event\" 

```

Either way, what comes next is "OR". Which should be "or".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2019, 7:47pm UTC](https://discuss.elastic.co/t/logstash-conditions-not-working-as-expected/166625/6 "2019-02-28T19:47:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
