# Logstash if condition

**URL:** <https://discuss.elastic.co/t/logstash-if-condition/250689>\
**Category:** Logstash\
**Created:** [October 1, 2020, 1:58pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689 "2020-10-01T13:58:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yotam\_Mazurik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yotam_mazurik/32/51497_2.png) [@Yotam\_Mazurik](https://discuss.elastic.co/u/Yotam_Mazurik)\
**Post date:** [October 1, 2020, 1:58pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689/1 "2020-10-01T13:58:44Z")

</div>

Hey, i'm new to logstash and got stuck while trying to create an if condition...

The structure of my if condition:

```auto
    if ([process][executable] not in [processes]["%{[process][hash][md5]}"][paths]) {
     ....
    }

```

when I try to use this configuration logstash will not start and response with an error about the structure of the condition.

to test it, I wrote a possible value and it worked:

```auto
    if ([process][executable] not in [processes][5746bd7e255dd6a8afa06f7c42c1ba41][paths]) {
     ....
    }

```

to be more specific, I did use this phrase at the rest of my code:  
`[processes]["%{[process][hash][md5]}"][paths]`

any ideas?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 1, 2020, 3:05pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689/2 "2020-10-01T15:05:30Z")

</div>

As you have found, you cannot use a sprintf reference directly in a conditional, and I do not think you can use nested sprintf references such as

```
%{[processes]["%{[process][hash][md5]}"][paths]}

```

Something you could try is

```
ruby {
    code => '
        hash = event.get("[process][hash][md5]")
        paths = event.get("[processes][#{hash}][paths]")
        event.set("[@metadata][paths]", paths)
    '
}
if [process][executable] not in [@metadata][paths] {
```

---

<div class="post-metadata">

**Author:** ![Yotam\_Mazurik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yotam_mazurik/32/51497_2.png) [@Yotam\_Mazurik](https://discuss.elastic.co/u/Yotam_Mazurik)\
**Post date:** [October 1, 2020, 5:36pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689/3 "2020-10-01T17:36:39Z")

</div>

thank you for the quick response!

I am not sure if "event.set" copies the data or just points to the given field.  
the field i am referring to ("paths") may include a large set of data, so copying it may not be the best solution.

isn't there any option to use temporary varriables \ pointers?

edit:  
maybe there is a way to "check" the condition via ruby code and update a boolean as a field in the metadata section?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 1, 2020, 5:49pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689/4 "2020-10-01T17:49:43Z")

</div>

> [@Yotam\_Mazurik](#):
>
> maybe there is a way to "check" the condition via ruby code and update a boolean as a field in the metadata section?

Assuming you are using 'not in' as an array membership test and not a sub-string match, you could try

```
code => '
    hash = event.get("[process][hash][md5]")
    paths = event.get("[processes][#{hash}][paths]")
    exe = event.get("[process][executable]")
    event.set("[@metadata][exeFound]", paths.include?(exe))
'

```

---

<div class="post-metadata">

**Author:** ![Yotam\_Mazurik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yotam_mazurik/32/51497_2.png) [@Yotam\_Mazurik](https://discuss.elastic.co/u/Yotam_Mazurik)\
**Post date:** [October 1, 2020, 10:04pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689/5 "2020-10-01T22:04:45Z")

</div>

Thank you so much.  
it was the exact solution I was looking for.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2020, 10:04pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689/6 "2020-10-29T22:04:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
