# Logstash if condition

**URL:** <https://discuss.elastic.co/t/logstash-if-condition/32075>\
**Category:** Logstash\
**Created:** [October 13, 2015, 9:52am UTC](https://discuss.elastic.co/t/logstash-if-condition/32075 "2015-10-13T09:52:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![schilwan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schilwan/32/14206_2.png) [@schilwan](https://discuss.elastic.co/u/schilwan)\
**Post date:** [October 13, 2015, 9:52am UTC](https://discuss.elastic.co/t/logstash-if-condition/32075/1 "2015-10-13T09:52:16Z")

</div>

I have some data that comes in and using the ipaddress to get hold of geo details using geoip.

What I found is my add\_field adds the field below if it finds a region for example

> "region\_name": "CA",  
> although if one does not exist in the dat file the data comes in Elastic as:  
> "regionName": "%{[geometry][region\_name]}"

I rather it be null then have the parameter value.

My logstash config has the below:

> mutate {  
> add\_field =\> ["[regionName]", "%{[geometry][region\_name]}"]

> ```
> }
> 
> ```

I tried the following as a test, which I assumed checked if a region existed as a property then add a field, but apparently this is not the case, appears when I do the following it just adds blob2 as a field when it finds geometry

> if "{[geometry][region\_name]}" { mutate { add\_field =\> { "blob2" =\> "Testing" }}}

Thanks

---

<div class="post-metadata">

**Author:** ![schilwan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schilwan/32/14206_2.png) [@schilwan](https://discuss.elastic.co/u/schilwan)\
**Post date:** [October 13, 2015, 9:55am UTC](https://discuss.elastic.co/t/logstash-if-condition/32075/2 "2015-10-13T09:55:19Z")

</div>

Not sure why undefined\> is coming up in the above syntax, ignore that.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 13, 2015, 10:08am UTC](https://discuss.elastic.co/t/logstash-if-condition/32075/3 "2015-10-13T10:08:38Z")

</div>

If you move the `add_field` to the geoip filter itself things should work since it'll only be processed if the filter is successful, which in the geoip case should mean that it found a match for the IP address.

```
filter {
  geoip {
    ...
    add_field => ["regionName", "%{[geometry][region_name]}" }
  }
}
```

---

<div class="post-metadata">

**Author:** ![schilwan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schilwan/32/14206_2.png) [@schilwan](https://discuss.elastic.co/u/schilwan)\
**Post date:** [October 13, 2015, 10:44am UTC](https://discuss.elastic.co/t/logstash-if-condition/32075/4 "2015-10-13T10:44:13Z")

</div>

Thanks Magnus for responding I tried that, but data came back as below, the regionName comes back with the parameter:

> "geometry": {  
> "country\_code2": "US",  
> "country\_code3": "USA",  
> "country\_name": "United States",  
> "continent\_code": "NA",  
> "latitude": 38,  
> "longitude": -97,  
> "dma\_code": 0,  
> "area\_code": 0,  
> "location": [  
> -97,  
> 38  
> ],  
> "coordinates": [  
> -97,  
> 38  
> ],  
> "type": "Point"  
> },  
> "regionName": "%{[geometry][region\_name]}",

The below was the very first draft of the add\_field which is why I assumed I had to do a mutate, if condition on the data, as oppose to adding it in the geoip.

> geoip {  
> source =\> "ipAddress"  
> target =\> "geometry"  
> database =\> "/etc/logstash/GeoLiteCity.dat"  
> add\_field =\> ["regionName", "%{[geometry][region\_name]}" ]  
> add\_field =\> ["countryName", "%{[geometry][country\_name]}"]  
> add\_field =\> ["countryCode", "%{[geometry][country\_code3]}"]  
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 13, 2015, 12:19pm UTC](https://discuss.elastic.co/t/logstash-if-condition/32075/5 "2015-10-13T12:19:12Z")

</div>

Oh, okay. It seems the various fields (like `region_name`) aren't always set. In that case your original attempt with a conditional was a good option, just with the wrong syntax. Try this:

```
if [geometry][region_name] {
  mutate {
    add_field => { "blob2" => "Testing" }
  }
}

```

(Won't work as expected if the field whose existence if being checked exists and contains a false boolean value.)

---

<div class="post-metadata">

**Author:** ![schilwan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/schilwan/32/14206_2.png) [@schilwan](https://discuss.elastic.co/u/schilwan)\
**Post date:** [October 13, 2015, 1:39pm UTC](https://discuss.elastic.co/t/logstash-if-condition/32075/6 "2015-10-13T13:39:16Z")

</div>

Thanks, you were right it was my syntax, now fixed to:

> if [geometry][region\_name] {  
> mutate {  
> add\_field =\> ["regionName", "%{[geometry][region\_name]}" ]  
> }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:26am UTC](https://discuss.elastic.co/t/logstash-if-condition/32075/7 "2017-07-06T05:26:42Z")

</div>


