# Logstash if condition

**URL:** <https://discuss.elastic.co/t/logstash-if-condition/250689>\
**Category:** Logstash\
**Created:** [October 1, 2020, 1:58pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689 "2020-10-01T13:58:43Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 1, 2020, 3:05pm UTC](https://discuss.elastic.co/t/logstash-if-condition/250689/2 "2020-10-01T15:05:30Z")

</div>

As you have found, you cannot use a sprintf reference directly in a conditional, and I do not think you can use nested sprintf references such as

```
%{[processes]["%{[process][hash][md5]}"][paths]}

```

Something you could try is

```
ruby {
    code => '
        hash = event.get("[process][hash][md5]")
        paths = event.get("[processes][#{hash}][paths]")
        event.set("[@metadata][paths]", paths)
    '
}
if [process][executable] not in [@metadata][paths] {
```

---

_[View the full topic](https://discuss.elastic.co/t/logstash-if-condition/250689)._
