# Converting strings to integers then manipulating

**URL:** <https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353>\
**Category:** Logstash\
**Created:** [April 24, 2018, 4:26pm UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353 "2018-04-24T16:26:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![sdberts](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@sdberts](https://discuss.elastic.co/u/sdberts)\
**Post date:** [April 24, 2018, 4:26pm UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353/1 "2018-04-24T16:26:32Z")

</div>

I have a string coming through in the following format:

"Memory Used": "500 MB"  
"Memory Used": "768 KB"

Basically, what I need to do is convert everything into MBs in integer/float format. For the fields containing "MB," it's simple enough. I just do a gsub and replace "MB" with "". I'm having a bit of trouble with the fields containing "KB" though. What I need to do is strip off KB if it exists, then divide the new integer by 1000 to get MBs. Any advice?

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 24, 2018, 4:50pm UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353/2 "2018-04-24T16:50:52Z")

</div>

I'm on my phone. So I won't even try to write working code. But what I'd do is write a ruby filter:

Initialize a variable divisor = 1  
If the field value matches .\*kb$ divisor = 1000  
Replace everything that is not a number [^\d] with nothing (gsub)  
Convert the string: Integer()  
Divide this by the divisor.

I hope, that helps.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 5:04pm UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353/3 "2018-04-24T17:04:36Z")

</div>

Have you looked at the (third-party) units filter?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 24, 2018, 5:38pm UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353/4 "2018-04-24T17:38:17Z")

</div>

If you don't care about the difference between 1000 and 1024 then the following might work for you. I use it when parsing GC logs

```auto
  mutate {
    gsub => ["message", "\b(?<size>[0-9]+)\.[0-9](?<unit>[BKMG])\b", "\k<size>\k<unit>" ]
    gsub => [
      "message", "\b(?<size>[0-9]+)G\b", "\k<size>000000000",
      "message", "\b(?<size>[0-9]+)M\b", "\k<size>000000",
      "message", "\b(?<size>[0-9]+)K\b", "\k<size>000",
      "message", "\b(?<size>[0-9]+)B\b", "\k<size>"
      ]
   }
ruby { code => 'event.set("someFieldInMB", event.get("someField").to_f/1000000)' }
```

---

<div class="post-metadata">

**Author:** ![sdberts](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@sdberts](https://discuss.elastic.co/u/sdberts)\
**Post date:** [April 24, 2018, 7:33pm UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353/5 "2018-04-24T19:33:35Z")

</div>

I have not, but I'll check that out!

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [April 25, 2018, 6:48am UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353/6 "2018-04-25T06:48:28Z")

</div>

The filter plugin will probably solve this, but for the sake of completeness, this is what I had in mind:

```
ruby {
    code => '
      divisor = 1
      divisor = 1000 if event.get("Memory Used") =~ /KB$/
      event.set("Memory Used", Integer(event.get("Memory Used").gsub(/[^\d]/,"")).to_f/divisor)
    '
  }
```

---

<div class="post-metadata">

**Author:** ![sdberts](https://avatars.discourse-cdn.com/v4/letter/s/e99b99/32.png) [@sdberts](https://discuss.elastic.co/u/sdberts)\
**Post date:** [April 25, 2018, 11:52am UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353/7 "2018-04-25T11:52:30Z")

</div>

This is almost exactly what I ended up with based on your previous comment. Thank you very much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2018, 12:01pm UTC](https://discuss.elastic.co/t/converting-strings-to-integers-then-manipulating/129353/8 "2018-05-23T12:01:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
