# Logstash filter condition not working some times

**URL:** <https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722>\
**Category:** Logstash\
**Created:** [July 27, 2022, 8:03am UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722 "2022-07-27T08:03:14Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![perezdev](https://avatars.discourse-cdn.com/v4/letter/p/8e8cbc/32.png) [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Post date:** [July 27, 2022, 8:03am UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722/1 "2022-07-27T08:03:14Z")

</div>

Hello,

I have following logstash configuration file for winlogbeat events:

```auto
input {
  #Winlgobeat
  beats {
    port => 5044
  }
}
filter {
  #Filter winlogbeat events
     mutate {
        rename => {
                "[event][code]" => "event_id"
                "[winlog][event_data][TargetUserName]" => "destination_user_name"
                "[winlog][event_data][MemberName]" => "tls_client_issuer"
        }
    }
    if [source_ip] == "-" {
        mutate {
                replace => ["source_ip", "0.0.0.0"]
        }
    }
    mutate {
        copy => { "[message]" => "event_original" }
    }
	if [event_id] == "4755" or [event_id] == "4731" or [event_id] == "4763" or [event_id] == "4730" or [event_id] == "4758" or [event_id] == "4754" or [event_id] == "4759" or [event_id] == "4760" or [event_id] == "4757" or [event_id] == "4735" or [event_id] == "4729" or [event_id] == "4732" or [event_id] == "4756" or [event_id] == "4737" or [event_id] == "4727" or [event_id] == "4728" or [event_id] == "4762" or [event_id] == "4761" {
        mutate {
            rename => {
                        "destination_user_name" => "group_name"
                        "tls_client_issuer" => "destination_user_name"
                }
        }
    }
}

```

What I want to achieve is that when event\_id match any of the OR condition defined, to rename the mentioned field names.

This configuration seems to work fine, but after a few hours it stopped working as some of the events were not renamed according to the condition defined. After a few minutes, it start working again, when no changes/restart of service are applied.

Could you help me with this issue?

Thank you.

---

<div class="post-metadata">

**Author:** ![zoug](https://avatars.discourse-cdn.com/v4/letter/z/90db22/32.png) [@zoug](https://discuss.elastic.co/u/zoug)\
**Post date:** [July 27, 2022, 12:11pm UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722/2 "2022-07-27T12:11:18Z")

</div>

Not sure if this is your problem, but I've had issues when the if statement contains more than one condition if parentheses are missing. So maybe try `if ([event_id] == "4755"...) {`.

---

<div class="post-metadata">

**Author:** ![perezdev](https://avatars.discourse-cdn.com/v4/letter/p/8e8cbc/32.png) [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Post date:** [July 27, 2022, 1:35pm UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722/3 "2022-07-27T13:35:52Z")

</div>

It seems that's not the reason of my issue. I tested adding parentheses, but as mentioned before this field renaming works intermittently. Thanks for the help.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [July 27, 2022, 2:39pm UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722/4 "2022-07-27T14:39:48Z")

</div>

Your condition looks fine my guess would be elswhere is there any parsing involvd earlier or after this statement ?

And how do you ship logs ? Can you describe the log flow and the solutions that are involved in shipping / parsing ?

---

<div class="post-metadata">

**Author:** ![perezdev](https://avatars.discourse-cdn.com/v4/letter/p/8e8cbc/32.png) [@perezdev](https://discuss.elastic.co/u/perezdev)\
**Post date:** [July 27, 2022, 3:32pm UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722/5 "2022-07-27T15:32:55Z")

</div>

I updated my first comment adding the complete filter section on my logstash conf file.

Conditionals and mutate actions before the conditional related to the issue are working fine.

Events are shipped from a Windows server where I have default winlogbeat running. I'm using logstash to parse/transform some fields/values related.

Collection is working fine so far, apart from this conditional that doesn't rename the expected fields sometimes.

Thanks for the help.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 27, 2022, 3:47pm UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722/6 "2022-07-27T15:47:19Z")

</div>

> [@perezdev](#):
>
> `	if [event_id] == "4755" or [event_id] == "4731" ...`

Can you check how is the "event\_id" field arrived, numeric or string?  
Your conf is OK if is string. If is a numeric, it will be:  
`	if [event_id] == 4755 or [event_id] == 4731 `

If you think that the process has been stopped, details will be in logstash.log  
Sometime recorders are not sent every second. Win logs are asynchronous events.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [August 4, 2022, 6:31am UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722/7 "2022-08-04T06:31:29Z")

</div>

Hi,  
I'm testing your configuration next week, for the sake of it do you have any documents (elastic entry) you can show us with the failed and correct parsing ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2022, 6:31am UTC](https://discuss.elastic.co/t/logstash-filter-condition-not-working-some-times/310722/8 "2022-09-01T06:31:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
