# Convert values from string to int

**URL:** <https://discuss.elastic.co/t/convert-values-from-string-to-int/325164>\
**Category:** Logstash\
**Created:** [February 9, 2023, 3:36pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164 "2023-02-09T15:36:33Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Law\_Rence](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/law_rence/32/117057_2.png) [@Law\_Rence](https://discuss.elastic.co/u/Law_Rence)\
**Post date:** [February 9, 2023, 3:36pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164/1 "2023-02-09T15:36:33Z")

</div>

How can I convert all the keys that have numbers from strings to int using ruby?

example:  
"x": "hello",  
"a": "1",  
"b": "2",  
"c": "3",  
"d": "bye"

to:

"x": "hello",  
"a": 1,  
"b": 2,  
"c": 3,  
e.t.c

here's my ruby:

```auto
filter {
    ruby {
        code => "
            event.get("message").each {|key, value|
               if value =~ /\A\d+\Z/
                event.set("value", value.to_i)
               end
           }
           "
      }
}

```

thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 9, 2023, 4:31pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164/2 "2023-02-09T16:31:31Z")

</div>

> [@Law\_Rence](#):
>
> `event.set("value", value.to_i)`

Surely that should be `event.set(key, value.to_i)`.

---

<div class="post-metadata">

**Author:** ![Law\_Rence](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/law_rence/32/117057_2.png) [@Law\_Rence](https://discuss.elastic.co/u/Law_Rence)\
**Post date:** [February 15, 2023, 4:12pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164/3 "2023-02-15T16:12:49Z")

</div>

> [@Law\_Rence](#):
>
> ```auto
> filter {
> ruby {
> code => "
> event.get("message").each {|key, value|
> if value =~ /\A\d+\Z/
> event.set("value", value.to_i)
> end
> }
> "
> }
> }
> 
> ```

thanks @Badger

However i get a

```auto
  "tags": [
    "_rubyexception"
  ],

```

my message looks like this

```auto
{
  "MSG": "File successfully transmitted to drive",
  "payloadTransferSpeedMBps": "146.388052",
  "transferTime": "0.032947",
  "readWriteTime": "0.027923",
  "reconciliationTime": "0",
  "driveTransferSpeedMBps": "146.402652",
  "capacityInBytes": "500000000000",
  "fileId": "757082",
  "@version": "1",
  "tapeVid": "V01006",
  "checksumingTime": "0.004905",
  "totalTime": "0.032877",
  "vendor": "IBM",
  "thread": "TapeWrite",
  "path": "/var/log/cta/cta-taped.log",
  "fSeq": "12835",
  "fileSize": "4812800",
  "headerVolume": "480",
  "LBPMode": "LBP_Off",
  "tapeDrive": "VDSTK11",
  "mediaType": "LTO8",
  "waitDataTime": "0.000011",
  "waitReportingTime": "0.000108",
  "dataVolume": "4812800",
  "vo": "desy",
  "mountId": "5643",
  "mountType": "ArchiveForUser",
  "TID": "15081",
  "LVL": "INFO",
  "PID": "14663",
  "@timestamp": "2023-02-15T15:38:45.874Z",
  "tags": [
    "_rubyexception"
  ],
  "logicalLibrary": "VLSTK10",
  "type": "cta-taped"
}

```

so i want all the values to be integers...these are not the only fields..  
my filter looks like this

```auto
filter {
    ruby {
        code => "
            event.get('message').each {|key, value|
               if value =~ /\A\d+\Z/
                event.set(key, value.to_i)
               end
           }
           "
      }
}

filter {
  mutate {
    gsub => ["message", " msg='", " _nested='"]
  }
  kv {
    source => "_nested"
    remove_field => "_nested"
  }

  kv {remove_field => "message" }

}

```

what am i missing/doing wrong?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 15, 2023, 5:36pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164/4 "2023-02-15T17:36:54Z")

</div>

If the kv filter is creating the fields that you want to be integers then it has to be before the ruby filter that converts them.

If you are getting a \_rubyexception tag then logstash will be logging an error message. What is that message?

---

<div class="post-metadata">

**Author:** ![Law\_Rence](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/law_rence/32/117057_2.png) [@Law\_Rence](https://discuss.elastic.co/u/Law_Rence)\
**Post date:** [February 15, 2023, 6:38pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164/5 "2023-02-15T18:38:57Z")

</div>

hi @Badger

this is the error message

```auto
Ruby exception occurred: undefined method `each' for #<String:0x49b0e43> {:class=>"NoMethodError", :backtrace=>["(ruby filter code):3:in `block in filter_method'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash
-filter-ruby-3.1.8/lib/logstash/filters/ruby.rb:96:in `inline_script'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.8/lib/logstash/filters/ruby.r
b:89:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:159:in `do_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:178:in `bl
ock in multi_filter'", "org/jruby/RubyArray.java:1821:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:175:in `multi_filter'", "org/logstash/config/ir/
compiler/AbstractFilterDelegatorExt.java:134:in `multi_filter'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:300:in `block in start_workers'"]}

```

previously, the ruby code was after the kv filters but still got the same.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 15, 2023, 7:51pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164/6 "2023-02-15T19:51:10Z")

</div>

That is telling you that [message] is a string, not a hash, so you cannot use .each on it.

---

<div class="post-metadata">

**Author:** ![Law\_Rence](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/law_rence/32/117057_2.png) [@Law\_Rence](https://discuss.elastic.co/u/Law_Rence)\
**Post date:** [February 16, 2023, 2:31pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164/7 "2023-02-16T14:31:23Z")

</div>

Thanks mate! Fixed it

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 16, 2023, 2:32pm UTC](https://discuss.elastic.co/t/convert-values-from-string-to-int/325164/8 "2023-03-16T14:32:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
