# Logstash filter section problem

**URL:** <https://discuss.elastic.co/t/logstash-filter-section-problem/90826>\
**Category:** Logstash\
**Created:** [June 26, 2017, 2:11pm UTC](https://discuss.elastic.co/t/logstash-filter-section-problem/90826 "2017-06-26T14:11:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmbrown](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@jmbrown](https://discuss.elastic.co/u/jmbrown)\
**Post date:** [June 26, 2017, 2:11pm UTC](https://discuss.elastic.co/t/logstash-filter-section-problem/90826/1 "2017-06-26T14:11:09Z")

</div>

Hi, I'm trying to create a set of filters that will add a field based on a numeric value received by logstash.  
At the moment I'm just adding a TAG to see if the "IF" works.  
It appears that there is something wrong with my IF statement.  
I've tried '174' , "174", and 174 without any enclosing marks.

How do can I debug this further ?? According to the netflow codec docs ipfix.bgpDestinationAsNumber  
is a numeric field.

filter {

```
if [ipfix.bgpDestinationAsNumber] == '174' {
    mutate {
        add_tag => { "FUBAR" => "BARF" }
    } 
}

```

}

Thank you for the help

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [June 26, 2017, 2:27pm UTC](https://discuss.elastic.co/t/logstash-filter-section-problem/90826/2 "2017-06-26T14:27:37Z")

</div>

Just the numeric without the quotes should work.

Also, is the "ipfix.bgpDestinationAsNumber" a nested one? By default the netflow codec has a target field called "netflow" as per the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-netflow.html#plugins-codecs-netflow-target), so you might need to reference it as

```auto

```

Btw, the add\_tag needs just a value that will end up in the "tags" field, no need to supply a field name. Try this instead

```auto
filter {
	if [netflow][ipfix.bgpDestinationAsNumber] == 174 {
		mutate {
			add_tag => ["BARF"]
		}
	}
}
```

---

<div class="post-metadata">

**Author:** ![jmbrown](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@jmbrown](https://discuss.elastic.co/u/jmbrown)\
**Post date:** [June 26, 2017, 4:29pm UTC](https://discuss.elastic.co/t/logstash-filter-section-problem/90826/3 "2017-06-26T16:29:13Z")

</div>

Hi Paris,

Thank you for your help. I had to modify the field name, but your example helped solve the problem

For others: The corrected line is

filter {  
if [ipfix][bgpDestinationAsNumber] == 174 {  
mutate {  
add\_tag =\> ["BARF"]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2017, 4:29pm UTC](https://discuss.elastic.co/t/logstash-filter-section-problem/90826/4 "2017-07-24T16:29:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
