# Copy complete event to a field of a new event

**URL:** <https://discuss.elastic.co/t/copy-complete-event-to-a-field-of-a-new-event/295583>\
**Category:** Logstash\
**Created:** [January 27, 2022, 1:08pm UTC](https://discuss.elastic.co/t/copy-complete-event-to-a-field-of-a-new-event/295583 "2022-01-27T13:08:08Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![HansPeterSloot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hanspetersloot/32/51132_2.png) [@HansPeterSloot](https://discuss.elastic.co/u/HansPeterSloot)\
**Post date:** [January 28, 2022, 4:04pm UTC](https://discuss.elastic.co/t/copy-complete-event-to-a-field-of-a-new-event/295583/6 "2022-01-28T16:04:19Z")

</div>

I have no idea.  
But I found this:

> [@Ruby Filter - Event.Remove Inconsistent Results](https://discuss.elastic.co/t/ruby-filter-event-remove-inconsistent-results/138268):
>
> Problem Statement I believe there is a bug in the ruby filter plugin when using event.remove Expected Output: ... event\_data.sql\_text =\> "some sql text" event\_data.logType =\> "Oracle" ... With no root fields (e.g., sql\_text or logType). All data should reside under event\_data nested object. Background: I am using docker instances to run an ES stack (3 Elasticsearches, 1 Logstash). I have tested this with docker versions 6.0.0 and 6.3.0 for Logstash. I'm pulling in data from variety of source…

Looks very much the same.

If have created a script and pointed have the path variable point to it.

In this script I created a new event with

```auto
def filter(event)

docs = []
new_event = LogStash::Event.new

*<code>*

docs.push(new_event)

return docs

```

and fill this event with correct format

To no avail

I cannot remove the fields in a hardcoded way because the formats of the events differ.

Regards Hans

---

_[View the full topic](https://discuss.elastic.co/t/copy-complete-event-to-a-field-of-a-new-event/295583)._
