# Pipeline rule: contains on list

**URL:** <https://community.graylog.org/t/pipeline-rule-contains-on-list/10275>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, route-to-streampl\
**Created:** [May 6, 2019, 12:37pm UTC](https://community.graylog.org/t/pipeline-rule-contains-on-list/10275 "2019-05-06T12:37:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [May 6, 2019, 12:37pm UTC](https://community.graylog.org/t/pipeline-rule-contains-on-list/10275/1 "2019-05-06T12:37:30Z")

</div>

Hi,  
I have to implement a rule where check the tags field.  
In this field we know that can be store more then one elements (like a `List<String>`). I need to check if contains a specific value (_like Stream rule_)

Is this possible on Pipeline rule? Can you give me an example?

Thanks  
Gianluca

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [May 6, 2019, 9:12pm UTC](https://community.graylog.org/t/pipeline-rule-contains-on-list/10275/2 "2019-05-06T21:12:49Z")

</div>

I can’t give you any example because I did not understand the request.

---

<div class="post-metadata">

**Author:** ![gianluca-valentini](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gianluca-valentini/32/1592_2.png) [@gianluca-valentini](https://community.graylog.org/u/gianluca-valentini)\
**Post date:** [May 7, 2019, 9:28am UTC](https://community.graylog.org/t/pipeline-rule-contains-on-list/10275/3 "2019-05-07T09:28:16Z")

</div>

Sorry.  
I need to create a rule to use it in a Pipeline.  
In this rule I have a field _myfield_ where I’d like to have a multivalue (it is similar to tags field that can contains more than one value when you use Collector Sidecar Configurations)

Like Collector Sidecar Configurations _tags_, I need to inspect the field values using **contains**.  
Looking Stream I can create a similar rule ’ Field _tags_ must contain _myfield_’ that we use to route event to a specific Stream.

Is this scenario feasible in pipeline rule?  
Can I check _tags_ value in _where_ condition building a pipeline rule?  
Fo example

```
where 
  $message.tags.contains("mick mouse")
then
  set_field(...)
```

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [May 8, 2019, 5:56am UTC](https://community.graylog.org/t/pipeline-rule-contains-on-list/10275/4 "2019-05-08T05:56:50Z")

</div>

Yes - that is total possible:

[http://docs.graylog.org/en/3.0/pages/pipelines/functions.html#contains](http://docs.graylog.org/en/3.0/pages/pipelines/functions.html#contains)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 22, 2019, 5:58am UTC](https://community.graylog.org/t/pipeline-rule-contains-on-list/10275/5 "2019-05-22T05:58:59Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
