# Logstash filter fields in if conditions

**URL:** <https://discuss.elastic.co/t/logstash-filter-fields-in-if-conditions/242717>\
**Category:** Logstash\
**Created:** [July 27, 2020, 9:03am UTC](https://discuss.elastic.co/t/logstash-filter-fields-in-if-conditions/242717 "2020-07-27T09:03:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![vape](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vape/32/53918_2.png) [@vape](https://discuss.elastic.co/u/vape)\
**Post date:** [July 27, 2020, 9:03am UTC](https://discuss.elastic.co/t/logstash-filter-fields-in-if-conditions/242717/1 "2020-07-27T09:03:37Z")

</div>

Hello,

I am learning about logstash, esspecially about logstash filter with if condition. Something not clear to me is what are those fields used in if condition? How can I get the list of those fields?  
For example, I want to apply different grok filter format for logs coming from different hosts. How can i put the condition to match hostname.

Your clarification here is highly appreciated!  
Thanks!

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [July 27, 2020, 12:40pm UTC](https://discuss.elastic.co/t/logstash-filter-fields-in-if-conditions/242717/2 "2020-07-27T12:40:52Z")

</div>

There are many ways you could do. You can either do a if/else condition in output or within filter.  
I tend to do mostly within filter as it will be cleaner and modular

So an example would be

```auto
input {
    pipeline {
        address => os_nix_syslog_pipeline
    }
}

filter {
  grok {
    match => {
        message => "%{SYSLOG5424LINE}"
      }
  }

  if "syslog5424_host" == '127.0.0.1' {
    mutate {
      add_field => { "myhost" => "localhost" }
    }  
  } else {
    mutate {
      add_field => { "myhost" => "unknown" }
    }  
  }
}

output {
  elasticsearch {
    hosts => "http://localhost:9200"
    user => "elastic"
    password => "changeme"
    index => "os_%{myhost}-%{+YYYY.MM}"
  }
}

```

The idea here is

- Get the input from a pipeline or log. In this example, it is a linux\_syslog
- Grok to get the [linux\_syslog](https://github.com/elastic/elasticsearch/blob/7.8/libs/grok/src/main/resources/patterns/linux-syslog) paramters
- if the syslog\_host is `127.0.0.1`, its localhost and add a field called "myhost". If anything else, it is "unknown"
- Just pump the output based on that field

---

<div class="post-metadata">

**Author:** ![vape](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vape/32/53918_2.png) [@vape](https://discuss.elastic.co/u/vape)\
**Post date:** [July 27, 2020, 1:11pm UTC](https://discuss.elastic.co/t/logstash-filter-fields-in-if-conditions/242717/3 "2020-07-27T13:11:33Z")

</div>

So, you grok the event first to get the filed and then put the condition based on one of those fields, what if I want to grok based on the hostname from where the event comes, which field that I should use in my condition?  
Something like this ?  
if "database-server" in [hostname] {

}

---

<div class="post-metadata">

**Author:** ![kelk](https://avatars.discourse-cdn.com/v4/letter/k/13edae/32.png) [@kelk](https://discuss.elastic.co/u/kelk)\
**Post date:** [July 27, 2020, 2:23pm UTC](https://discuss.elastic.co/t/logstash-filter-fields-in-if-conditions/242717/4 "2020-07-27T14:23:37Z")

</div>

really can't comment on that until I see the payload and fields you have already extracted.  
Best thing to do is to see your raw data in Elastic, and then find the field (key-value) which has the "database-server". if it is beats, then it might be `host.name` or `agent.hostname` or `beat.hostname` depending on the version or type of input

So something like

```auto
if [host][name] == 'database-server' {

}

```

---

<div class="post-metadata">

**Author:** ![vape](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vape/32/53918_2.png) [@vape](https://discuss.elastic.co/u/vape)\
**Post date:** [July 28, 2020, 5:38am UTC](https://discuss.elastic.co/t/logstash-filter-fields-in-if-conditions/242717/5 "2020-07-28T05:38:26Z")

</div>

Thanks a lot for your suggestion. Yes, I am using filebeat to ship postgres log to logstash.  
After changing the condition, it works

```auto
if [host][hostname] == 'database-server' {

}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2020, 5:38am UTC](https://discuss.elastic.co/t/logstash-filter-fields-in-if-conditions/242717/6 "2020-08-25T05:38:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
