# Operators in Ingest Pipeline

**URL:** <https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743>\
**Category:** Elasticsearch\
**Tags:** painless, ingest-pipeline, runtime-fields\
**Created:** [February 16, 2023, 1:15pm UTC](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743 "2023-02-16T13:15:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![errupeshmca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/errupeshmca/32/78285_2.png) [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Post date:** [February 16, 2023, 1:15pm UTC](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743/1 "2023-02-16T13:15:34Z")

</div>

Hello, I am trying to parse and compare values through ingest pipeline, but couldn't do it,  
I was running below code, grok is running fine, but couldn't be able to compare value in set condition.

```auto
POST _ingest/pipeline/_simulate
{
  "pipeline": {
    "processors": [
      {
        "grok": {
          "field": "message",
          "patterns": ["%{HOSTNAME:host.name},%{WORD:host.driveletter},%{INT:host.driveusage}"]
        },
        "set": {
          "field": "summary.down",
          "value": 1,
          "if": "ctx.host.name == 'CALCWZ88C3'"
        }
      }
    ]
  },
  "docs": [
    {
      "_source": {
        "message": "CALCWZ88C3,C,13"
      }
      
    }
    
  ]
}

```

getting below issues

```auto
{
  "docs": [
    {
      "error": {
        "root_cause": [
          {
            "type": "script_exception",
            "reason": "runtime error",
            "script_stack": [
              "ctx.host.name == 'CALCWZ88C3'",
              " ^---- HERE"
            ],
            "script": "ctx.host.name == 'CALCWZ88C3'",
            "lang": "painless",
            "position": {
              "offset": 8,
              "start": 0,
              "end": 29
            }
          }
        ],
        "type": "script_exception",
        "reason": "runtime error",
        "script_stack": [
          "ctx.host.name == 'CALCWZ88C3'",
          " ^---- HERE"
        ],
        "script": "ctx.host.name == 'CALCWZ88C3'",
        "lang": "painless",
        "position": {
          "offset": 8,
          "start": 0,
          "end": 29
        },
        "caused_by": {
          "type": "null_pointer_exception",
          "reason": "cannot access method/field [name] from a null def reference"
        }
      }
    }
  ]
}

```

Could you please help ?

I have one more question , is there \< and \> than operators in ingest pipeline you can use, if yes please what's the syntax, I have to compare value which comes from grok ouput

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 16, 2023, 5:41pm UTC](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743/2 "2023-02-16T17:41:41Z")

</div>

Hi @errupeshmca,  
When I tried running your simulated command I was getting the same errors you saw, but actually creating the pipeline worked fine. Please try these steps:

1. Create the pipeline

```auto
PUT _ingest/pipeline/experiment
{
  "processors" : [
    {
      "grok": {
          "field": "message",
          "patterns": ["%{HOSTNAME:host.name},%{WORD:host.driveletter},%{INT:host.driveusage}"]
        },
        "set": {
          "field": "summary.down",
          "value": 1,
          "if": "ctx.host.name == 'CALCWZ88C3'"
        }
    }
  ]
}

```

1. Post test message

```auto
POST /your_index_name_here/_doc?pipeline=experiment
{
 "message": "CALCWZ88C3,C,112"
}

```

1. Verify it looks good

```auto
GET /your_index_name_here/_search

```

If all goes well you should see something like this:

```auto
{
  "took" : 1,
  "timed_out" : false,
  "_shards" : {
    "total" : 1,
    "successful" : 1,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 1,
      "relation" : "eq"
    },
    "max_score" : 1.0,
    "hits" : [
      {
        "_index" : "your_index_name_here",
        "_type" : "_doc",
        "_id" : "84gkd24YBQ_bO945337D",
        "_score" : 1.0,
        "_source" : {
          "summary" : {
            "down" : 1
          },
          "host" : {
            "driveusage" : "112",
            "name" : "CALCWZ88C3",
            "driveletter" : "C"
          },
          "message" : "CALCWZ88C3,C,112"
        }
      }
    ]
  }
}

```

In regards to your question on comparison operators see this [documentation](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-operators-boolean.html#greater-than-operator).

---

<div class="post-metadata">

**Author:** ![errupeshmca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/errupeshmca/32/78285_2.png) [@errupeshmca](https://discuss.elastic.co/u/errupeshmca)\
**Post date:** [February 17, 2023, 3:23pm UTC](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743/3 "2023-02-17T15:23:59Z")

</div>

Thanks Andrew that works, and thanks for the documentation links.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 17, 2023, 3:24pm UTC](https://discuss.elastic.co/t/operators-in-ingest-pipeline/325743/4 "2023-03-17T15:24:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
