# Why '\[field\] in \[ "value" \]' is not working as expected?

**URL:** <https://discuss.elastic.co/t/why-field-in-value-is-not-working-as-expected/111411>\
**Category:** Logstash\
**Created:** [December 12, 2017, 6:44pm UTC](https://discuss.elastic.co/t/why-field-in-value-is-not-working-as-expected/111411 "2017-12-12T18:44:52Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![vb4t](https://avatars.discourse-cdn.com/v4/letter/v/a698b9/32.png) [@vb4t](https://discuss.elastic.co/u/vb4t)\
**Post date:** [December 12, 2017, 6:44pm UTC](https://discuss.elastic.co/t/why-field-in-value-is-not-working-as-expected/111411/1 "2017-12-12T18:44:53Z")

</div>

Hello. I have a field and I want to compare its value agains the list of another values, but this comparison does not work:  
if [field] in ["value"]  
But this works:  
if [field] in ["randomxyz", "value"]  
Why there have to be at least 2 elements? I understand the following behaviour:  
if [field] in "somestringvalue"  
which finds content of [field] in string "somestringvalue", but in case of array I do not get it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 9, 2018, 6:44pm UTC](https://discuss.elastic.co/t/why-field-in-value-is-not-working-as-expected/111411/2 "2018-01-09T18:44:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
