# Output IF ELSE configuration error

**URL:** <https://discuss.elastic.co/t/output-if-else-configuration-error/39869>\
**Category:** Logstash\
**Created:** [January 22, 2016, 11:32am UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869 "2016-01-22T11:32:43Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![logstaszek](https://avatars.discourse-cdn.com/v4/letter/l/b9e5f3/32.png) [@logstaszek](https://discuss.elastic.co/u/logstaszek)\
**Post date:** [January 22, 2016, 11:32am UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/1 "2016-01-22T11:32:43Z")

</div>

So, this is my output configuration:

> output  
> {
> 
> if [field] == "ABC" and [OK] == "Yes"  
> {  
> elasticsearch  
> {  
> hosts =\> "localhost:9200"  
> user =\> "xxx"  
> password =\> "xxx"  
> index =\> "abc"   
> }  
> }
> 
> else if [field] == "DEF" and [OK] == "Yes"  
> {  
> elasticsearch  
> {  
> hosts =\> "localhost:9200"  
> user =\> "xxx"  
> password =\> "xxx"  
> index =\> "def"  
> }  
> }
> 
> else  
> {  
> elasticsearch  
> {  
> hosts =\> "localhost:9200"  
> user =\> "xxx"  
> password =\> "xxx"  
> index =\> "other"  
> }  
> }
> 
> ```
> stdout 
> { 
> codec => rubydebug 
> }
> 
> ```
> 
> }

Everything work good, if field exist it's throwing my logs to properly indices.  
But the error show up, when the field has another value than "abc" or "def".  
Output config say us that, for example: log with field with value "xyz" should go to index "other",  
but log didn't appear there, and in logstash stdout i can find error:

> "error"=\>{"type"=\>"mapper\_parsing\_exception",  
> "reason"=\>"failed to parse [field]", "caused\_by"=\>{"type"=\>"number\_format\_exception",  
> "reason"=\>"For input string: "xyz""}}}}, :level=\>:warn}

I'm pretty sure that, this error is related to output config.  
If statement didn't work properly?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 22, 2016, 11:53am UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/2 "2016-01-22T11:53:38Z")

</div>

It looks like ES is complaining because the field named `field` is mapped as an integer or float but you're trying to add a document containing the string "xyz".

---

<div class="post-metadata">

**Author:** ![logstaszek](https://avatars.discourse-cdn.com/v4/letter/l/b9e5f3/32.png) [@logstaszek](https://discuss.elastic.co/u/logstaszek)\
**Post date:** [January 22, 2016, 12:16pm UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/3 "2016-01-22T12:16:47Z")

</div>

if [field] != "DEF" and [field] != "ABC"  
{  
.  
.  
.  
index =\> "other"  
}

also didn't work.

When i put an integer to [field], it's asking for another field which is not integer. This is weird...  
Any ideas how to solve that?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 23, 2016, 4:30pm UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/4 "2016-01-23T16:30:33Z")

</div>

> also didn't work.

Please show the error message.

> When i put an integer to [field], it's asking for another field which is not integer. This is weird...

Why? It checks the fields in order, and when you've fixed the first non-integer field it'll look at the next one and complain about that.

---

<div class="post-metadata">

**Author:** ![logstaszek](https://avatars.discourse-cdn.com/v4/letter/l/b9e5f3/32.png) [@logstaszek](https://discuss.elastic.co/u/logstaszek)\
**Post date:** [January 25, 2016, 8:31am UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/5 "2016-01-25T08:31:54Z")

</div>

> [@magnusbaeck](#):
>
> Why? It checks the fields in order, and when you've fixed the first non-integer field it'll look at the next one and complain about th

Yes, it's normal, I know, but why it asks for Integer? If I put a proper name to [field] - it's adding whole log to correct index, if i put any other name there, it's showing me an error, but it should add that log to index with not properly written names (index =\> "other")... This is how IF ELSE should work, no?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 25, 2016, 9:09am UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/6 "2016-01-25T09:09:58Z")

</div>

What exactly is the problem here? That Logstash is attempting to send events to the wrong index or that it's not able to send events to the right index because ES returns mapper\_parsing\_exception?

---

<div class="post-metadata">

**Author:** ![logstaszek](https://avatars.discourse-cdn.com/v4/letter/l/b9e5f3/32.png) [@logstaszek](https://discuss.elastic.co/u/logstaszek)\
**Post date:** [January 25, 2016, 9:17am UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/7 "2016-01-25T09:17:30Z")

</div>

Logstash is not able to send events to the right index because it returns mapper\_parsing\_exception.

Just check what i write in 1st post.  
First IF statement is working good, if there is good value of field, the event go to right index.  
Second ELSE IF statement also working well, events go to right index.  
But last, ELSE is not working well... I thought, if field value is "blebleble" or anything, the event should go to the index named "other" but it returns mapper\_parsing\_exception...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 25, 2016, 9:37am UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/8 "2016-01-25T09:37:55Z")

</div>

> Logstash is not able to send events to the right index because it returns mapper\_parsing\_exception.

Okay, so let's not derail the discussion by talking about if statements when those appear to be working just fine. Either stop trying to store strings in the integer field or map that field as a string. That requires the index to be reindexed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:14am UTC](https://discuss.elastic.co/t/output-if-else-configuration-error/39869/9 "2017-07-06T05:14:32Z")

</div>


