# Logstash - if - indexOf

**URL:** <https://discuss.elastic.co/t/logstash-if-indexof/243314>\
**Category:** Logstash\
**Created:** [July 31, 2020, 6:42am UTC](https://discuss.elastic.co/t/logstash-if-indexof/243314 "2020-07-31T06:42:51Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![daemon](https://avatars.discourse-cdn.com/v4/letter/d/c6cbf5/32.png) [@daemon](https://discuss.elastic.co/u/daemon)\
**Post date:** [July 31, 2020, 6:42am UTC](https://discuss.elastic.co/t/logstash-if-indexof/243314/1 "2020-07-31T06:42:51Z")

</div>

Java  
if("str||aaa").indexOf("||")

logstash filter if?

ps. What should I do?

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [July 31, 2020, 7:14am UTC](https://discuss.elastic.co/t/logstash-if-indexof/243314/2 "2020-07-31T07:14:05Z")

</div>

I think this is what you are looking for:

> **[Accessing event data and fields | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals)**

> You can use the `in` operator to test whether a field contains a specific string, key, or list element. Note that the semantic meaning of `in` can vary, based on the target type. For example, when applied to a string. `in` means "is a substring of". When applied to a collection type, `in` means "collection contains the exact value".

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2020, 7:14am UTC](https://discuss.elastic.co/t/logstash-if-indexof/243314/3 "2020-08-28T07:14:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
