# Using if else in logstash filter

**URL:** <https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853>\
**Category:** Logstash\
**Created:** [October 18, 2022, 7:56am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853 "2022-10-18T07:56:32Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 18, 2022, 7:56am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/1 "2022-10-18T07:56:32Z")

</div>

Hi everyone,

i'd like to ask, is it possible to use OR operator in if else statement in logstash filter?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/f/4fab03549b00a4832ee3d4ca0fd70dc8100710c8.png)

so, i want to delete the event that has value "VoIP-Null0", "Null0", and "Loopback0" in data.ifDescr field. i already apply configuration like this to delete them

> filter{  
> csv {  
> separator =\> ","  
> skip\_header =\> true  
> columns =\> ["timestamp","host","data.ifDescr","data.ifInOctets","data.ifOutOctets"]  
> }
> 
> if [data][ifDescr] == "VoIP-Null0" or [data][ifDescr] == "Null0" or [data][ifDescr] == "Loopback0"{  
> drop { }  
> }  
> }

but there's no change. the event are still exist. even in the logstash log, there is no error  
can you show me how to solve this? thank you

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 18, 2022, 8:12am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/2 "2022-10-18T08:12:21Z")

</div>

Yes it is supported AND OR... Check [docs](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals)

Check in LS ruby debugger real the field name "data.ifInOctets" or [data][ifDescr].  
I haven't tried, but should be different names in CSV. Also is useful,not mandatory, to have () in log. operations  
...

```auto
columns => ["timestamp","host","[data][ifDescr]","[data][ifInOctets]","[data][ifOutOctets]"]
}

if ( ([data][ifDescr] == "VoIP-Null0") or ([data][ifDescr] == "Null0") or ([data][ifDescr] == "Loopback0") ) {
drop { }
}

```

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 18, 2022, 11:37am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/3 "2022-10-18T11:37:06Z")

</div>

Thank you for the response. i'll try your suggestion later. because I tried my luck before and it worked. hahaha. i change it from

> if [data][ifDescr] == "VoIP-Null0" or [data][ifDescr] == "Null0" or [data][ifDescr] == "Loopback0"{  
> drop { }  
> }

into

> if [data.ifDescr] == "VoIP-Null0" or [data.ifDescr] == "Null0" or [data.ifDescr] == "Loopback0"{  
> drop { }  
> }

I didn't think it would work. Once again, thank you

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 18, 2022, 3:14pm UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/4 "2022-10-18T15:14:39Z")

</div>

data.ifDescr - single field name  
[data][ifDescr] - nested field

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 18, 2022, 3:22pm UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/5 "2022-10-18T15:22:31Z")

</div>

> [@yuswanul](#):
>
> "timestamp","host","data.ifDescr","data.ifInOctets","data.ifOutOctets"

You should avoid using dots in fields name as this can lead to confusion because they work in different ways in Logstash and Elasticsearch.

In Logstash, using `data.ifDescr` means a field with a literal dot in its name, you have this:

```auto
{ "data.ifDescr": "value" }

```

In elasticsearch in scripts or ingest pipelines, using `data.ifDescr` would mean a json object named `data` with a nested field named `ifDescr`.

Something like this:

```auto
{ "data": { "ifDescr": "value" } }

```

In your case, if you named your field as `data.ifDescr`, then you should use `[data.ifDescr]` in your conditional.

But the recommendation is to change your csv filter and condtional to the ones that @Rios shared.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 19, 2022, 1:52am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/6 "2022-10-19T01:52:43Z")

</div>

Thanks for the explanation @leandrojmp . i also want to ask something about if else. is it good to use conditional statement this many?

 ![WhatsApp Image 2022-10-19 at 08.37.42](https://us1.discourse-cdn.com/elastic/original/3X/2/9/29e4e63ec24e6f9a93b83f44e6ee5372fc3587e5.jpeg)

or is it better if i make it like this?

> if "Crypto" in [data][ifDescr] or "Bluetooth" in [data][ifDescr] or "unrouted" in [data][ifDescr]{  
> drop { }  
> }  
> else if "VoIP" in [data][ifDescr] or "Null" in [data][ifDescr] or "Loopback" in [data][ifDescr]{  
> drop { }  
> }

I'm afraid if I use conditional statements like above picture, it will affect logstash performance. Thank you

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 19, 2022, 2:38am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/7 "2022-10-19T02:38:44Z")

</div>

It makes no difference and will have zero impact in the performance.

But if the value of the field `[data][ifDescr]` is a single keyword you can improve your conditional and make it more readable.

```auto
if [data][ifDescr] in ["Crypto", "Bluetooth", "unrouted", "VoIP", "Null", "Loopback"] {
    drop {}
}

```

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 19, 2022, 3:36am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/8 "2022-10-19T03:36:37Z")

</div>

Thanks a lot for the solution @leandrojmp and Thank you for the help @Rios

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [October 19, 2022, 5:13am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/9 "2022-10-19T05:13:50Z")

</div>

actually that is some keyword of the value. because the value of the field is unrouted Vlan 56 (for example) if the value is not a single keyword, how do i improve my conditional?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 16, 2022, 5:14am UTC](https://discuss.elastic.co/t/using-if-else-in-logstash-filter/316853/10 "2022-11-16T05:14:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
