# Change a Number Field Value

**URL:** <https://discuss.elastic.co/t/change-a-number-field-value/184008>\
**Category:** Logstash\
**Created:** [June 3, 2019, 3:20pm UTC](https://discuss.elastic.co/t/change-a-number-field-value/184008 "2019-06-03T15:20:53Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [June 4, 2019, 1:59pm UTC](https://discuss.elastic.co/t/change-a-number-field-value/184008/11 "2019-06-04T13:59:59Z")

</div>

Work with the ruby output plugin and you will see what is going on.  
Most of your questions were already answered on this forum, you just have to google a bit.

Eg:

> [@Help With Multiple If {} else if {} COnfiguration](https://discuss.elastic.co/t/help-with-multiple-if-else-if-configuration/40417):
>
> I am seeking help with a Logstash configuration issue. Some of my syslog messages coming into my indexer are in JSON format and some are not. I am solving this using multiple if {} else if {} else {} statements after groking the syslog\_message out of the event. (Is there a better way?) My problem is that this works for some of my events (e.g. player events) but not others (e.g. sysstatf events). What am I doing wrong? Here are two example input lines: \<190\>Jan 28 19:00:32 host2 player-player[…

> [@Count length of field / number of characters in a field and add the result into a new field](https://discuss.elastic.co/t/count-length-of-field-number-of-characters-in-a-field-and-add-the-result-into-a-new-field/157705/8):
>
> Can you try this: filter { if [log\_name] == "Microsoft-Windows-Sysmon/Operational" { ruby { code =\> "event['processcreate'] = event['process\_command\_line'].length" } } }

---

_[View the full topic](https://discuss.elastic.co/t/change-a-number-field-value/184008)._
