# The use of if ... in \[array\]

**URL:** <https://discuss.elastic.co/t/the-use-of-if-in-array/369112>\
**Category:** Logstash\
**Created:** [October 21, 2024, 5:01am UTC](https://discuss.elastic.co/t/the-use-of-if-in-array/369112 "2024-10-21T05:01:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![NgDinhNamEtiis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ngdinhnametiis/32/135683_2.png) [@NgDinhNamEtiis](https://discuss.elastic.co/u/NgDinhNamEtiis)\
**Post date:** [October 21, 2024, 5:01am UTC](https://discuss.elastic.co/t/the-use-of-if-in-array/369112/1 "2024-10-21T05:01:47Z")

</div>

Hi  
When using if ... in [array] for Logstash with version 8.15.0:

```auto
input { generator { count => 1 } }

filter {
  if "a" in ["a","b"] {
    mutate {
      add_field => { "test_field" => "1" }
    }
  }
}

output { 
  stdout {} 
}

```

my questions are:

1. When I use this way:

```auto
if "a" in ["a","b"]

```

"test\_field" does not appear in my test, hope someone could explain why.

1. Puzzle with:  
[`if .. in []` doesn't match for single-element arrays · Issue #9932 · elastic/logstash (github.com)](https://github.com/elastic/logstash/issues/9932)  
I test a different implement but same idea with my Logstash mention above, it appear that this is not true, array with one value still return as expected, like:

```auto
if "element_in_array" in [one_element_array] => true

```

I hope some verify or information so that myself or someone could suggest this ticket to be **closed** , because It make me so confuse about the use of if ... in [array].

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 21, 2024, 10:59am UTC](https://discuss.elastic.co/t/the-use-of-if-in-array/369112/2 "2024-10-21T10:59:23Z")

</div>

> [@NgDinhNamEtiis](#):
>
> `if "element_in_array" in [one_element_array] => true`

The issue is that when it is ambiguous whether [] in a conditional is an array or a field reference, it is always resolved as a field reference. If you intend `[one_element_array]` to be a field reference then that would work as expected.

I am completely baffled as to why

```
if "a" in ["a", "b"] { mutate { add_tag => ["3"] } }

```

does not add the tag. Perhaps is it just too early in the morning for me to be thinking straight.

---

<div class="post-metadata">

**Author:** ![NgDinhNamEtiis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ngdinhnametiis/32/135683_2.png) [@NgDinhNamEtiis](https://discuss.elastic.co/u/NgDinhNamEtiis)\
**Post date:** [October 22, 2024, 6:13am UTC](https://discuss.elastic.co/t/the-use-of-if-in-array/369112/3 "2024-10-22T06:13:48Z")

</div>

Understand what you explained here, thank.  
Any update for:

```auto
if "a" in ["a", "b"] { mutate { add_tag => ["3"] } }

```

Find anything about this strange behavior?
