# Output When Data in Field is a Specific Value

**URL:** <https://discuss.elastic.co/t/output-when-data-in-field-is-a-specific-value/287733>\
**Category:** Logstash\
**Created:** [October 26, 2021, 9:17pm UTC](https://discuss.elastic.co/t/output-when-data-in-field-is-a-specific-value/287733 "2021-10-26T21:17:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [October 26, 2021, 9:17pm UTC](https://discuss.elastic.co/t/output-when-data-in-field-is-a-specific-value/287733/1 "2021-10-26T21:17:29Z")

</div>

Hi,  
I want to know only output a field called network.application when it contains the value ALPHA but I am getting an error that

Expected one of [\t\r\n], "#", "{" at line 152, column 7 (byte 3941) after output {  
if [network][application] == "ALPHA" {  
codec  
[FATAL] 2021-10-26 17:07:00.423 [LogStash::Runner] Logstash - Logstash stopped processing because of an error: (SystemExit) exit

```auto
output {
if [network][application] == "ALPHA" {
codec => cef {
    reverse_mapping => true
    delimiter => "\r\n"
      fields => [
      "start",
      "end",
      "cs1",
      "cs2",
      "cs3",
      "cs4",
      "src",
      "act",
      "deviceProduct",
      "deviceVendor"
            ]
      
      vendor => "TEST"
      product => "ALPHa"
        }
}
}

```

its obviously the way the syntax ist but I can't figure it out. I just want to convert any log to CEF that has the network.application = ALPHA

thx

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 26, 2021, 9:43pm UTC](https://discuss.elastic.co/t/output-when-data-in-field-is-a-specific-value/287733/2 "2021-10-26T21:43:49Z")

</div>

You have not told it what output plugin to use. The compiler is interpreting codec as a plugin name (it would fail to load it later if it didn't fail here) and a plugin name cannot be followed by =\>

Maybe

```
output {
    if [network][application] == "ALPHA" {
        file {
            codec => cef {
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2021, 9:44pm UTC](https://discuss.elastic.co/t/output-when-data-in-field-is-a-specific-value/287733/3 "2021-11-23T21:44:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
