# Logstash config output regex condition on integer

**URL:** <https://discuss.elastic.co/t/logstash-config-output-regex-condition-on-integer/58909>\
**Category:** Logstash\
**Created:** [August 25, 2016, 9:40am UTC](https://discuss.elastic.co/t/logstash-config-output-regex-condition-on-integer/58909 "2016-08-25T09:40:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![metalcapone](https://avatars.discourse-cdn.com/v4/letter/m/46a35a/32.png) [@metalcapone](https://discuss.elastic.co/u/metalcapone)\
**Post date:** [August 25, 2016, 9:40am UTC](https://discuss.elastic.co/t/logstash-config-output-regex-condition-on-integer/58909/1 "2016-08-25T09:40:46Z")

</div>

Hello all!

I'm working on indexing IIS logs in ES using Logstash.  
Here is my config output section, where I try to seperate the http code response (status field) in two indices:

```
output {
   	if [type] == "mywebsite" and [status] =~ "^[2]" {
		elasticsearch {
			hosts => ["192.168.1.3:9200"]
			index => "logstash-httpCode2XX-%{+YYYY.MM}"
			document_type => "log"
		}
	}
	if [type] == "mywebsite" and [status] =~ "^[5]" {
		elasticsearch {
			hosts => ["192.168.1.3:9200"]
			index => "logstash-httpCode5XX-%{+YYYY.MM}"
			document_type => "log"
		}
	}
}

```

Given [status] field is "grokked" and mutated as an integer:

```
mutate {
	convert => {
		status => "integer"
        }
}

```

I do not understand why the second part of my conditions with the regex does not work... It is not verified, nothing is sent to my ES indices.

I add that without this condition, everything's ok until ES, so no Grok or mutate issue...

Thanks a lot if you have any idea!  
Have a good day.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2016, 11:00am UTC](https://discuss.elastic.co/t/logstash-config-output-regex-condition-on-integer/58909/2 "2016-08-25T11:00:06Z")

</div>

I'm not sure regexp matches work for integer fields. Note that the correct syntax for regexp matching is `[status] =~ /^[2]/` (which is equivalent to `[status] =~ /^2/`). Either way, why use regexp matching in the first place when you can do `[status] >= 200 and [status] < 300`?

---

<div class="post-metadata">

**Author:** ![metalcapone](https://avatars.discourse-cdn.com/v4/letter/m/46a35a/32.png) [@metalcapone](https://discuss.elastic.co/u/metalcapone)\
**Post date:** [August 25, 2016, 12:22pm UTC](https://discuss.elastic.co/t/logstash-config-output-regex-condition-on-integer/58909/3 "2016-08-25T12:22:22Z")

</div>

Thanks for your reply!

It works fine using the simple mathematical comparison. When I tried the first time, I used quotes...  
Morality, regex seem to not work on intergers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:41am UTC](https://discuss.elastic.co/t/logstash-config-output-regex-condition-on-integer/58909/4 "2017-07-06T04:41:38Z")

</div>


