# Logstash "if" condition not working as expected

**URL:** <https://discuss.elastic.co/t/logstash-if-condition-not-working-as-expected/274483>\
**Category:** Logstash\
**Created:** [May 31, 2021, 10:21am UTC](https://discuss.elastic.co/t/logstash-if-condition-not-working-as-expected/274483 "2021-05-31T10:21:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![suryarao67](https://avatars.discourse-cdn.com/v4/letter/s/c77e96/32.png) [@suryarao67](https://discuss.elastic.co/u/suryarao67)\
**Post date:** [May 31, 2021, 10:21am UTC](https://discuss.elastic.co/t/logstash-if-condition-not-working-as-expected/274483/1 "2021-05-31T10:21:40Z")

</div>

Below is my input message to logstash

```auto
{
	"object2": "",
	"headers": {
		"request_path": "/",
		"request_method": "POST",
		"http_accept": "*/*",
		"content_type": "application/json; charset=utf-8",
		"http_version": "HTTP/1.1",
		"http_user_agent": null,
		"content_length": "859",
		"http_host": "XXXXXXXXXXXXX"
	},
	"host": "xxxxxxx",
	"logger_name": "awx.analytics.activity_stream",
	"summary_fields": {
		"actor": {
			"username": "xxx.xxx@xxx.com",
			"first_name": "xxx",
			"id": 999,
			"last_name": "xxx"
		},
		"credential": [{
			"kind": "ssh",
			"cloud": false,
			"credential_type_id": 1,
			"description": "test sr_xxx for activity streams 44671112213",
			"kubernetes": false,
			"name": "xx_xxx_test",
			"id": 999
		}]
	},
	"@version": "1",
	"@timestamp": "2021-05-31T10:02:20.745Z",
	"level": "INFO",
	"cluster_host_id": "xxxxxxxxxx",
	"message": "Activity Stream update entry for xxxxxxxx",
	"stack_info": null,
	"operation": "update",
	"actor": "xxx@xxx.com",
	"changes": {
		"description": ["test sr_xxx for activity streams 4144671112213", "test sr_xxx for activity streams 44671112213"]
	},
	"object1": "credential",
	"relationship": "",
	"tower_uuid": null

```

and below is my logstash config

```auto
    input {
      http {
        port => 5000
        codec => json
        ssl => true
        ssl_certificate_authorities => "/etc/ssl/elastic/elastic.crt"
        ssl_certificate => "/etc/ssl/elastic/elastic.crt"
        ssl_key => "/etc/ssl/elastic/elastic.key"
        ssl_verify_mode => "peer"
      }
    }
    output {
      elasticsearch {
        hosts => ["xxx.xxx.xxx.xxx:9200"]
      }
      stdout { codec => rubydebug }
      #stdout { codec => json }
      if [changes][description] =~ /test sr_xxx for activity streams/ {
          file { path => "/tmp/sr_output.txt" }
      }
    }

```

I expect the input message to be written to the file /tmp/sr\_output.txt but it's not being written.

Any idea as to why?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 31, 2021, 10:51am UTC](https://discuss.elastic.co/t/logstash-if-condition-not-working-as-expected/274483/2 "2021-05-31T10:51:35Z")

</div>

It looks like that your field `changes.description` is an array.

```auto
"changes": {
		"description": ["test sr_xxx for activity streams 4144671112213", "test sr_xxx for activity streams 44671112213"]
	}

```

So, to access its values you would need to use `[changes][description][0]`, but this will only work for the first item in the array, but it seems that this array has only one item.

You could also use the [split](https://www.elastic.co/guide/en/logstash/current/plugins-filters-split.html) filter in the field `changes.description`, it would create an event for every item in this array, with only one item in the array it would just flatten this field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2021, 10:52am UTC](https://discuss.elastic.co/t/logstash-if-condition-not-working-as-expected/274483/3 "2021-06-28T10:52:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
