# Update field value if it matches a certain word

**URL:** <https://discuss.elastic.co/t/update-field-value-if-it-matches-a-certain-word/201305>\
**Category:** Logstash\
**Created:** [September 26, 2019, 7:19pm UTC](https://discuss.elastic.co/t/update-field-value-if-it-matches-a-certain-word/201305 "2019-09-26T19:19:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [September 26, 2019, 7:19pm UTC](https://discuss.elastic.co/t/update-field-value-if-it-matches-a-certain-word/201305/1 "2019-09-26T19:19:58Z")

</div>

Hello,

I am trying to replace the value of a field if the field value matches with a certain regex. I am looking at the update function in mutate filter.

```
output:
  "repo" => "test-xyz;buildNumber=2.1",

```

how do i set a mutate filter on this such that

`if "repo" value starts with "test-xyz;" , set value for repo as "test-internal"`

```
if [repo] = "test-xyz; .*"{

update => 'test-internal'

}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 26, 2019, 7:31pm UTC](https://discuss.elastic.co/t/update-field-value-if-it-matches-a-certain-word/201305/2 "2019-09-26T19:31:32Z")

</div>

You should use =~ rather than =, and remove the space from the regexp. You can use [mutate+replace](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-replace) to replace the value of a field.

---

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [September 26, 2019, 8:04pm UTC](https://discuss.elastic.co/t/update-field-value-if-it-matches-a-certain-word/201305/3 "2019-09-26T20:04:07Z")

</div>

```
if [repo] =~ "test-xyz;.*"{
      filter {
            mutate {
              replace => { "repo" => "test-internal" }
            }
          }
      }

```

Is this the right syntax ?

I get a syntax error when i tried the above

`[2019-09-26T15:46:19,838][ERROR][logstash.agent] Failed to execute action {:id=>:main, :action_type=>LogStash::ConvergeResult::FailedAction, :message=>"Expected one of #, => at line 45, column 20`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 26, 2019, 8:32pm UTC](https://discuss.elastic.co/t/update-field-value-if-it-matches-a-certain-word/201305/4 "2019-09-26T20:32:13Z")

</div>

No, the conditional has to be inside the filter

```
filter {
    if [repo] =~ "test-xyz;.*" {
        mutate {
          replace => { "repo" => "test-internal" }
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2019, 1:40pm UTC](https://discuss.elastic.co/t/update-field-value-if-it-matches-a-certain-word/201305/6 "2019-10-25T13:40:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
