# Badly formatted index, after interpolation still contains placeholder: \[%{\[@metadat a\]\[target\_index\]}\]

**URL:** <https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder-metadat-a-target-index/338905>\
**Category:** Logstash\
**Created:** [July 20, 2023, 7:09pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder-metadat-a-target-index/338905 "2023-07-20T19:09:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dsv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsv/32/47173_2.png) [@dsv](https://discuss.elastic.co/u/dsv)\
**Post date:** [July 20, 2023, 7:09pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder-metadat-a-target-index/338905/1 "2023-07-20T19:09:00Z")

</div>

Hey guys, trying to aggregate audit events from a linux with  
` logstash-8.8.1-1.x86_64`  
and got the error:  
`Badly formatted index, after interpolation still contains placeholder: [%{[@metadat a][target_index]}]`

The `stdout { codec => rubydebug }` event output:  
{  
"@timestamp" =\> 2023-07-20T18:27:01.000Z,  
"@version" =\> "1",  
"tags" =\> [  
[0] "aggregated"  
],  
"process.title" =\> "tr -dc [:digit:]",  
"host.name" =\> "host09",  
"[@metadata][target\_index]" =\> "p-os-linux-sh",  
}

**The code:**

```auto
aggregate {
    task_id => "%{audit.event.id}"
    code => "
            curr_index = 'empty'

            map['tags'] || map['tags'] = event.get('tags')
            map['process.title'] || map['process.title'] = event.get('process.title')
            map['host.name'] || map['host.name'] = event.get('host.name')
            map['@timestamp'] || map['@timestamp'] = event.get('@timestamp')
            map['[@metadata][target_index]'] || map['[@metadata][target_index]'] = event.get('[@metadata][target_index]')

            curr_index = event.get('[@metadata][target_index]')

            if ! map['[@metadata][target_index]'].match(/3y$/)
                    if curr_index.match(/3y$/)
                            map['[@metadata][target_index]'] = curr_index
                    elsif curr_index.match(/1y$/) and not map['[@metadata][target_index]'].match(/1y$/)
                            map['[@metadata][target_index]'] = curr_index
                    end
            end
        "
        push_map_as_event_on_timeout => true
        timeout => 10
        inactivity_timeout => 5

        timeout_code => '
                    event.tag("aggregated")
                '
  }

```

The root of the problem is the different [@metadata][target\_index] values in events. The most priority index ends with 3y and so on.  
If i set [@metadata][target\_index]'] in "timeout\_code" block by "string" value it works.  
But don't know how to set it from a variable  
`event.set( '[@metadata][target_index]', map['[@metadata][target_index]' ] )`  
is not working.

I know it looks like invention of the wheel while auditbeat exists.  
But the auditbeat consumes too many CPU for usage in a high load prod.

Replacing the map['[@metadata][target\_index]'] by map['@metadata.target\_index'] does not help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 20, 2023, 9:30pm UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder-metadat-a-target-index/338905/2 "2023-07-20T21:30:37Z")

</div>

> [@dsv](#):
>
> "[@metadata][target\_index]" =\> "p-os-linux-sh"

You have a field called "[@metadata][target\_index]", not a [@metadata] object with a [target\_index] field inside it. Try

```
        code => '
            map["[@metadata]"] ||= {}
            map["[@metadata]"]["target_index"] = event.get("[@metadata][target_index]")
        '

```

---

<div class="post-metadata">

**Author:** ![dsv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsv/32/47173_2.png) [@dsv](https://discuss.elastic.co/u/dsv)\
**Post date:** [July 21, 2023, 11:00am UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder-metadat-a-target-index/338905/3 "2023-07-21T11:00:59Z")

</div>

Thanks to @Badger. His suggestion with a little change is working  
`map['@metadata']['target_index'] || map['@metadata']['target_index'] = event.get('[@metadata][target_index]')`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2023, 11:01am UTC](https://discuss.elastic.co/t/badly-formatted-index-after-interpolation-still-contains-placeholder-metadat-a-target-index/338905/4 "2023-08-18T11:01:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
