# Seraching value of variable

**URL:** <https://discuss.elastic.co/t/seraching-value-of-variable/193768>\
**Category:** Logstash\
**Created:** [August 5, 2019, 10:35am UTC](https://discuss.elastic.co/t/seraching-value-of-variable/193768 "2019-08-05T10:35:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![RickT](https://avatars.discourse-cdn.com/v4/letter/r/3bc359/32.png) [@RickT](https://discuss.elastic.co/u/RickT)\
**Post date:** [August 5, 2019, 10:35am UTC](https://discuss.elastic.co/t/seraching-value-of-variable/193768/1 "2019-08-05T10:35:33Z")

</div>

hi,  
i'm searching to compare the value of a variable in a field (from "message" or from a specific field).

I'm trying this, but without result :  
...  
filter {  
mutate {  
add\_field =\> { "mails" =\> "joe, mary, pierre" }  
add\_field =\> { "user" =\> "mary" }  
}  
if [mails] =~ "%{user}" {..................}  
.....

Is my conditional line is correct ?

In my final configuration, the field "user" is issued from logs and json plugin.  
Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 5, 2019, 11:57am UTC](https://discuss.elastic.co/t/seraching-value-of-variable/193768/2 "2019-08-05T11:57:47Z")

</div>

I would not expect a sprintf reference to work in that context. You can do it in ruby.

```
    ruby {
        code => '
            if event.get("mails").include? event.get("user")
                event.set("FoundIt", true)
            end
        '
    }

```

will work. However, that will also work searching for "pie". If you want to test for the complete word then try

```
    mutate { gsub => ["mails", " ", ""] }
    mutate { split => { "mails" => "," } }
    ruby {
        code => '
            if event.get("mails").include? event.get("user")
                event.set("FoundIt", true)
            end
        '
    }
```

---

<div class="post-metadata">

**Author:** ![RickT](https://avatars.discourse-cdn.com/v4/letter/r/3bc359/32.png) [@RickT](https://discuss.elastic.co/u/RickT)\
**Post date:** [August 5, 2019, 12:59pm UTC](https://discuss.elastic.co/t/seraching-value-of-variable/193768/3 "2019-08-05T12:59:18Z")

</div>

Thanks very munch Badger !  
It's working very well.

In complement, as i'm a quiet curious, could you give me a good link to read documentation about "code" of ruby. I would to discover the other options of syntax.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2019, 12:59pm UTC](https://discuss.elastic.co/t/seraching-value-of-variable/193768/4 "2019-09-02T12:59:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
