# Need help with a NOT in if statement, is it "not" or "!"?

**URL:** <https://discuss.elastic.co/t/need-help-with-a-not-in-if-statement-is-it-not-or/299486>\
**Category:** Logstash\
**Created:** [March 11, 2022, 6:14pm UTC](https://discuss.elastic.co/t/need-help-with-a-not-in-if-statement-is-it-not-or/299486 "2022-03-11T18:14:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![teebu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/teebu/32/10119_2.png) [@teebu](https://discuss.elastic.co/u/teebu)\
**Post date:** [March 11, 2022, 6:14pm UTC](https://discuss.elastic.co/t/need-help-with-a-not-in-if-statement-is-it-not-or/299486/1 "2022-03-11T18:14:37Z")

</div>

```auto
        # filter out local ips
        if !([http][request][headers][CF-Connecting-IP] =~ "^10.0.*" or [http][request][headers][CF-Connecting-IP] =~ "^127.0.*" or [http][request][headers][CF-Connecting-IP] == "0.0.0.0") {
            geoip {
                  source => "[http][request][headers][CF-Connecting-IP]"
                  target => "[client][geo]"
                  tag_on_failure => ["geoip-city-failed"]
              }
        }

```

`if not (...)` is throwing an error.

the `if !()` is not throwing an error, but allowing empty fields to go through the if statement, creating the `"geoip-city-failed"` tag.

I see this [Accessing event data and fields in the configuration | Logstash Reference [8.1] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html) mentioniong `Expressions can be long and complex. Expressions can contain other expressions, you can negate expressions with !, and you can group them with parentheses (...).`

But why is my not statement not working?

I need to add an additional check if that field exists.

```auto
if [http][request][headers][CF-Connecting-IP] and !([http][request][headers][CF-Connecting-IP] =~ "^10.0.*" or [http][request][headers][CF-Connecting-IP] =~ "^127.0.*" or [http][request][headers][CF-Connecting-IP] == "0.0.0.0") {

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2022, 6:58pm UTC](https://discuss.elastic.co/t/need-help-with-a-not-in-if-statement-is-it-not-or/299486/2 "2022-03-11T18:58:41Z")

</div>

In an if statement you use ! for NOT. The exception is the "not in" operator which is the opposite of an "in" operator.

> [@teebu](#):
>
> I need to add an additional check if that field exists.

Yes, if the field does not exist then the [Java code](https://github.com/logstash-plugins/logstash-filter-geoip/blob/feeb56b857c93688cd30685c0aa1ea38abd79ef7/src/main/java/org/logstash/filters/geoip/GeoIPFilter.java#L147) will return false, and the ruby code treats that as a [failure](https://github.com/logstash-plugins/logstash-filter-geoip/blob/feeb56b857c93688cd30685c0aa1ea38abd79ef7/lib/logstash/filters/geoip.rb#L117). Most filters are a no-op if the source field does not exist, but the geoip filter is different.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2022, 6:59pm UTC](https://discuss.elastic.co/t/need-help-with-a-not-in-if-statement-is-it-not-or/299486/3 "2022-04-08T18:59:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
