# Documentation on in\_event and expect in Ruby filter test framework?

**URL:** <https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551>\
**Category:** Logstash\
**Created:** [October 6, 2023, 7:38pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551 "2023-10-06T19:38:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![paolovalladolid](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Post date:** [October 6, 2023, 7:38pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551/1 "2023-10-06T19:38:21Z")

</div>

I started working on a Ruby script to be called from my Logstash ruby filter.

The official documentation mentions a test framework [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html#_testing_the_ruby_script)

There is an example test provided

```auto
test "drop percentage 100%" do
  parameters do
    { "percentage" => 1 }
  end

  in_event { { "message" => "hello" } }

  expect("drops the event") do |events|
    events.size == 0
  end
end

```

Is there any documentation for `in_event`? Do I just paste in a full JSON document to test on?

Does `expect` work like the [expect in RSpec](https://rubydoc.info/gems/rspec-expectations/RSpec%2FMatchers:expect)? If not, is there any documentation on how to use it?

---

<div class="post-metadata">

**Author:** ![paolovalladolid](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Post date:** [October 6, 2023, 9:00pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551/2 "2023-10-06T21:00:55Z")

</div>

Sorry, too late for me to edit the OP with my additional questions about the example test provided in the official docs:

1. Where does the `parameters` variable come from?

2. Can we type anything we want into the `expect` argument? For example is the above test still going to run as expected if we had typed `expect("blow away event")`?

3. How do I get the output of the `filter` function in the test? The example test just looks at the number of events. The official docs say `filter` returns a list of events. It would have been nice to see the `expect` portion of the test take a look at - at the very least - one value inside one of the events in the list of events that filter is supposed to return.

---

<div class="post-metadata">

**Author:** ![paolovalladolid](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Post date:** [October 6, 2023, 10:56pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551/3 "2023-10-06T22:56:42Z")

</div>

Here is my test, based on guessing what might work since I cannot find the proper documentation:

```auto
test "get task array" do
  in_event {
    {
      "name":"job1",
      "error":[
         {
         "task":"75fc",
         "message":{
            "ietf-restconf:errors":{
               "error":[
                  {
                     "error-type":"application",
                     "error-tag":"malformed-message",
                     "error-path":"/pathto/problem",
                     "error-message":"missing element: name in thepath"
                  }
               ]
            }
         },
         "timestamp":1.695060733555E+12
        },
       {
         "task":"job",
         "message":"Job has no available transitions. 6649, cb04, f5dd could have led to the workflow end task, but did not. These tasks performed in a way that the end of the workflow could not be reached.",
         "timestamp":1.69506073357E+12
        }
      ]
    }
  }

  expect("extracts the task array") do |events|
    puts events
    events.size == 2
  end
end

```

I am getting a test failure. I tried to use the `puts` statement to see what is actually inside `events` in the `expect` block, but the puts is not producing any output. What do I need to do?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 6, 2023, 11:23pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551/4 "2023-10-06T23:23:39Z")

</div>

> [@paolovalladolid](#):
>
> ```auto
> expect("extracts the task array") do |events|
> puts events
> events.size == 2
> end
> 
> ```

I had never tried testing ruby scripts before this, but having poked around in the [source](https://github.com/logstash-plugins/logstash-filter-ruby/tree/main/lib/logstash/filters/ruby)...

I think in\_event should be a hash or an array of hashes, each of which is used to create an event (@timestamp and @version get added).

I think the `do |events|` is passed the array of events return by your filter function. So your test should be

```
events[0].get("tasks").size == 2

```

If I add -t to my logstash command line I then get

> [2023-10-06T19:21:55,283][INFO][logstash.filters.ruby.script] Test run complete {:script\_path=\>"/home/user/.../script.rb", :results=\>{:passed=\>1, :failed=\>0, :errored=\>0}}

Any puts calls in either the filter function or the expect bit write to stdout as expected.

However `puts events` just produces

```
[#<LogStash::Event:0x29eeb1bb>]

```

and `puts events[0]` produces

```
2023-10-06T23:32:54.237298312Z %{host} %{message}

```

because it calls the .to\_s or inspect of the event and that method is not useful. You can get the actual event using `puts events[0].to_hash`.

---

<div class="post-metadata">

**Author:** ![Andrew\_Mora](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_mora/32/125622_2.png) [@Andrew\_Mora](https://discuss.elastic.co/u/Andrew_Mora)\
**Post date:** [October 7, 2023, 6:06am UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551/5 "2023-10-07T06:06:55Z")

</div>

It seems like the official documentation mentions the use of a test framework with an example test case provided. However, it's unclear if there's documentation available for the "in\_event" function and how to use it effectively. Similarly, more information about how "expect" works, especially in comparison to RSpec, would be helpful for users trying to understand its usage. AC Football Cases

---

<div class="post-metadata">

**Author:** ![paolovalladolid](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Post date:** [October 9, 2023, 7:18pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551/6 "2023-10-09T19:18:36Z")

</div>

Thanks! I went back and forth on whether or not to put the ruby filter inline, or put it in a separate .rb file. I chose the latter to use the testing framework, because there are so many possible points of failure in the pipeline config file already. Testing the ruby filter by itself looks like a good idea.

The explanation of `in_event` makes sense

I modified the `expect` mehod as follows

```auto
expect("extracts the task array") do |events|
    puts "EVENTS ARRAY:"
    puts events[0].to_hash
    events[0].get(["error_task_array"]).count == 2
  end # expect

```

I can see in the output that `error_task_array` has 2 elements as expected

```auto
EVENTS ARRAY:
{"error_task_array"=>["75fc", "job"], "@timestamp"=>2023-10-09T19:06:52.475893048Z, "error"=>[{"timestamp"=>1695060733555.0, "task"=>"75fc", "message"=>{"ietf-restconf:errors"=>{"error"=>[{"error-message"=>"missing element: name in thepath", "error-type"=>"application", "error-path"=>"/pathto/problem", "error-tag"=>"malformed-message"}]}}}, {"timestamp"=>1695060733570.0, "task"=>"job", "message"=>"Job has no available transitions. 6649, cb04, f5dd could have led to the workflow end task, but did not. These tasks performed in a way that the end of the workflow could not be reached."}], "name"=>"job1", "@version"=>"1"}

```

However the test continues to fail

```auto
[ERROR] 2023-10-09 19:15:13.373 [LogStash::Runner] expectcontext - ***TEST RAISED ERROR: 'get task array extracts the task array'*** {"exception"=>"#<TypeError: no implicit conversion of Array into String>"

```

I cannot figure out the proper way to get the number of elements in `error_task_array`. Besides `count` I also tried `size` and `length`.

---

<div class="post-metadata">

**Author:** ![paolovalladolid](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Post date:** [October 9, 2023, 9:32pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551/7 "2023-10-09T21:32:07Z")

</div>

I got the test to pass by cheating in this manner:

```auto
expect("extracts the task array") do |events|
    events.size != 0
    #taskArray = events[0].get(["error_task_array"])
    #taskArray != null
end # expect

```

It's a shame that I cannot implement a proper test for now but I need to get a move on.

I opened an issue on Github against the ruby filter. I see there are a bunch of open issues already regarding the lack of documentation. However the issue I opened is specifically about not being able to check the size of an array.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2023, 9:33pm UTC](https://discuss.elastic.co/t/documentation-on-in-event-and-expect-in-ruby-filter-test-framework/344551/8 "2023-11-06T21:33:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
