# After upgrade Logstash 2.3 tries to evaluate $1 enviroment-var in embedded ruby code

**URL:** <https://discuss.elastic.co/t/after-upgrade-logstash-2-3-tries-to-evaluate-1-enviroment-var-in-embedded-ruby-code/46064>\
**Category:** Logstash\
**Created:** [April 1, 2016, 12:52pm UTC](https://discuss.elastic.co/t/after-upgrade-logstash-2-3-tries-to-evaluate-1-enviroment-var-in-embedded-ruby-code/46064 "2016-04-01T12:52:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kaem2111](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaem2111/32/24961_2.png) [@kaem2111](https://discuss.elastic.co/u/kaem2111)\
**Post date:** [April 1, 2016, 12:52pm UTC](https://discuss.elastic.co/t/after-upgrade-logstash-2-3-tries-to-evaluate-1-enviroment-var-in-embedded-ruby-code/46064/1 "2016-04-01T12:52:57Z")

</div>

Hallo,

I am using ruby code in Logstash in the kind:

```
ruby { code => "
      b = { 'K' => 1024.0, 'M' => 1048576.0, 'G' => 1073741824.0 }
      event['z0'].each do | k0, v0 |
          if (v0 =~ /^[\-\+0-9]/)
              factor = 1
              factor = b[$1] if (v0 =~ /[0-9]([KMG])B$/)
              event[k0] = v0.to_f * factor
          else
              event[k0] = v0
          end
     end
"}

```

After upgrading to Logstash 2.3 it stops with the message:

....:reason=\>"Cannot evaluate `$1`. Environment variable `1` is not set and there is no default value given.", :level=\>:error}.

Is there a way to prevent Logstash from investigating environment vars in ruby code - e.g. by escaping $1, but so that it still works in ruby?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 2, 2016, 11:16pm UTC](https://discuss.elastic.co/t/after-upgrade-logstash-2-3-tries-to-evaluate-1-enviroment-var-in-embedded-ruby-code/46064/2 "2016-04-02T23:16:10Z")

</div>

This is a known issue, we're working on having a fix for it ASAP.  
You may need to downgrade to get around this unfortunately ☹

---

<div class="post-metadata">

**Author:** ![AlexClineBB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexclinebb/32/8914_2.png) [@AlexClineBB](https://discuss.elastic.co/u/AlexClineBB)\
**Post date:** [April 5, 2016, 8:26pm UTC](https://discuss.elastic.co/t/after-upgrade-logstash-2-3-tries-to-evaluate-1-enviroment-var-in-embedded-ruby-code/46064/3 "2016-04-05T20:26:41Z")

</div>

I ran into this issue as well. Had to downgrade from 2.3.0-1 in the apt repo using the 2.3.3-1 .deb file manually.

Would love to see a quick fix for this and older versions maintained in the apt repo for quick version downgrading and pinning when needed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/after-upgrade-logstash-2-3-tries-to-evaluate-1-enviroment-var-in-embedded-ruby-code/46064/4 "2017-07-06T05:03:43Z")

</div>


