# Logstash output conditional not working

**URL:** <https://discuss.elastic.co/t/logstash-output-conditional-not-working/187617>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [June 26, 2019, 3:51pm UTC](https://discuss.elastic.co/t/logstash-output-conditional-not-working/187617 "2019-06-26T15:51:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pcantea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pcantea/32/53396_2.png) [@pcantea](https://discuss.elastic.co/u/pcantea)\
**Post date:** [June 26, 2019, 3:51pm UTC](https://discuss.elastic.co/t/logstash-output-conditional-not-working/187617/1 "2019-06-26T15:51:41Z")

</div>

Sample logstash message  
{  
"@version": "1",  
"agent": {  
"type": "filebeat",  
"hostname": "83b529353ae1",  
"ephemeral\_id": "1df074c7-acb2-4c57-897d-143403cd5af9",  
"version": "7.1.1",  
"id": "61831d51-b5a3-47bf-96e8-99e151078ce0"  
},  
"host": {  
"name": "83b529353ae1"  
},  
"input": {  
"type": "docker"  
},  
"ecs": {  
"version": "1.0.0"  
},  
"log": {  
"offset": 76271,  
"file": {  
"path": "/usr/share/dockerlogs/data/a842ff11e4afe04e80b8863d34ee9a8b57007e5f9121ffded96272ddbe86dec3/a842ff11e4afe04e80b8863d34ee9a8b57007e5f9121ffded96272ddbe86dec3-json.log"  
}  
},  
"container": {  
"image": {  
"name": "[783811678347.dkr.ecr.us-west-2.amazonaws.com/impact-net-v3:52@sha256:16822f5b02f0b797aafc3ff74c19b73350b0da5d049ec91737c5c9e4c58268a6](http://783811678347.dkr.ecr.us-west-2.amazonaws.com/impact-net-v3:52@sha256:16822f5b02f0b797aafc3ff74c19b73350b0da5d049ec91737c5c9e4c58268a6)"  
},  
"name": "impact-net-v3\_impact-net.1.m3muxrphxkah4br4sybe16rhx",  
"id": "a842ff11e4afe04e80b8863d34ee9a8b57007e5f9121ffded96272ddbe86dec3",  
"labels": {  
"com\_docker\_swarm\_task\_name": "impact-net-v3\_impact-net.1.m3muxrphxkah4br4sybe16rhx",  
"com\_docker\_swarm\_task": "",  
"SERVICE\_NAME": "impact-net",  
"com\_docker\_swarm\_service\_name": "impact-net-v3\_impact-net",  
"com\_docker\_swarm\_node\_id": "w1sn9esxmvn3yvxxm7th9zwo8",  
"SERVICE\_TAGS": "production,sso,java",  
"com\_docker\_swarm\_task\_id": "m3muxrphxkah4br4sybe16rhx",  
"com\_docker\_swarm\_service\_id": "xekejqmc3kfmfdialapvn37y0",  
"com\_docker\_stack\_namespace": "impact-net-v3"  
}  
},  
"message": "Jun 26, 2019 8:22:12 AM com.impactorder.impactnetv3.plugins.PartnerLogin ",  
"@timestamp": "2019-06-26T15:22:12.073Z",  
"stream": "stderr",  
"tags": [  
"beats\_input\_codec\_plain\_applied"  
]  
}

So far I've tried  
if [docker][container][labels][SERVICE\_TAGS] =~ "production"  
if [SERVICE\_TAGS] in [docker][container][labels]  
if "production" in [docker][container][labels][SERVICE\_TAGS]  
if [docker][container][labels][com\_docker\_stack\_namespace] == "impact-net-v3"

Nothing seems to work. As soon as I enable any of the output conditionals all output stops

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 26, 2019, 4:24pm UTC](https://discuss.elastic.co/t/logstash-output-conditional-not-working/187617/2 "2019-06-26T16:24:35Z")

</div>

> [@pcantea](#):
>
> if "production" in [docker][container][labels][SERVICE\_TAGS]

I would expect

```
if "production" in [container][labels][SERVICE_TAGS]

```

to work. Note that that is a substring test. So

```
if "tion,sso,j" in [container][labels][SERVICE_TAGS]

```

would also work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 4:24pm UTC](https://discuss.elastic.co/t/logstash-output-conditional-not-working/187617/3 "2019-07-24T16:24:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
