# Logstash does not parse if 'if' condition change

**URL:** <https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700>\
**Category:** Logstash\
**Created:** [August 23, 2022, 11:59am UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700 "2022-08-23T11:59:13Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 23, 2022, 11:59am UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700/1 "2022-08-23T11:59:14Z")

</div>

Using single node ELK cluster version 7.16.3.  
Index won't appear in kibana if i used this configuration in logstash pipeline file

```auto
output {
if [tags] == "average_weight" {
elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "average_weight-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
 }
}
}

```

If i change the pattern in if condition than i can able to see my index

```auto
output {
if "average_weight" in [tags] {
elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "average_weight-%{+YYYY.MM.dd}"
    #user => "elastic"
    #password => "changeme"
 }
}
}

```

So is there any difference between these two ?  
I don't want to use in operator

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 23, 2022, 12:24pm UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700/2 "2022-08-23T12:24:14Z")

</div>

If you are creating the `tags` field in Logstash using `add_tag`, then it is an array, a collection type field, so you need to use the `in` or `not in` operator.

What you have in reality is `tags: ["average_weight", "other-tags"]`

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 23, 2022, 4:32pm UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700/3 "2022-08-23T16:32:50Z")

</div>

Hi @leandrojmp basically i introduced this tags in filebeat.yml

```auto
- type: filestream

  # Change to true to enable this input configuration.
  enabled: true
  tags: ["average_weight"]
  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /home/aniket/python/average_weight.log

```

according to me logstash will check that this field(when it receive events from beats) is exist and it has the value  
So i am creating tag but i am using this tags.. Please correct me

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [August 23, 2022, 5:01pm UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700/4 "2022-08-23T17:01:01Z")

</div>

Tag is a field which can contains multiple values as the array.

`if "average_weight" in [tags]` means check does the values "average\_weight" exist in tags  
`if [tags] == "average_weight"` means check is tags equal to "average\_weight", which never be possible since is the array, not a value.

What is possible to compare is a member of the array, for instance:  
` if [tags][0] == "average_weight"`

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 23, 2022, 5:54pm UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700/5 "2022-08-23T17:54:00Z")

</div>

It is the same thing, the `tags` fields both in Beats and Logstash is an array.

If you want to use this field in the conditional you will need to make a check using `in` or `not in`.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [August 24, 2022, 8:59am UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700/6 "2022-08-24T08:59:55Z")

</div>

Thank you @Rios @leandrojmp i thought tag field in beat is not array. Thank you both of you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2022, 9:00am UTC](https://discuss.elastic.co/t/logstash-does-not-parse-if-if-condition-change/312700/7 "2022-09-21T09:00:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
