# Can I attach a messages byte-count as a metadata field?

**URL:** <https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531>\
**Category:** Logstash\
**Created:** [September 1, 2016, 10:21am UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531 "2016-09-01T10:21:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [September 1, 2016, 10:21am UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531/1 "2016-09-01T10:21:30Z")

</div>

Hi; I'm currently running a Logstash server in which I receive messages from various sources. I'd like to find out the the approximate byte-count of each incoming message and attach this as a @metadata field, so I can drop excessively large messages, and monitor the approximate size of incoming messages.

Is this possible to implement using the ruby filter? I tried

```
code => "event['message_size'] = event.message.length

```

but it didn't work, as message seems to be an object not a string.

Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 10:29am UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531/2 "2016-09-01T10:29:31Z")

</div>

> ```
> code => "event['message_size'] = event.message.length
> 
> ```

Change to:

```
code => "event['message_size'] = event['message'].length"

```

---

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [September 1, 2016, 12:43pm UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531/3 "2016-09-01T12:43:23Z")

</div>

Thanks for the reply; I tried that variant of the code in my filter block

```
ruby {
	code => "event['message_size'] = event['message'].length"
}

```

but each message was labelled with a \_rubyexception tag, and no message length field.

Just to note, I'm using the version of Logstash that is released on the Ubuntu PPA

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 1:28pm UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531/4 "2016-09-01T13:28:33Z")

</div>

Your logs should contain more information about the Ruby exception.

---

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [September 1, 2016, 2:50pm UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531/5 "2016-09-01T14:50:03Z")

</div>

Thanks, I didn't actually know Ruby exceptions were stored in logstash.log

```
{:timestamp=>"2016-09-01T15:48:49.535000+0100", :message=>"Ruby exception occurred: undefined method `length' for nil:NilClass", :level=>:error}

```

I get an error essentially saying that the event-message is null, which is strange (I hope this isn't turning into a bug report!)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 4:35pm UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531/6 "2016-09-01T16:35:45Z")

</div>

This indeed indicates that the `message` field is unset.

---

<div class="post-metadata">

**Author:** ![Ryan\_Grannell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ryan_grannell/32/41712_2.png) [@Ryan\_Grannell](https://discuss.elastic.co/u/Ryan_Grannell)\
**Post date:** [September 2, 2016, 3:08pm UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531/7 "2016-09-02T15:08:56Z")

</div>

I can't believe the cause of the error was this simple; I just added a check that the message is defined, and everything worked perfectly.

```
if event['message']
	event['message_size'] = event['message'].length
end

```

I appreciate the help fixing this problem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:40am UTC](https://discuss.elastic.co/t/can-i-attach-a-messages-byte-count-as-a-metadata-field/59531/8 "2017-07-06T04:40:12Z")

</div>


