# Event.get(message).bytesize

**URL:** <https://discuss.elastic.co/t/event-get-message-bytesize/267004>\
**Category:** Logstash\
**Created:** [March 11, 2021, 10:19pm UTC](https://discuss.elastic.co/t/event-get-message-bytesize/267004 "2021-03-11T22:19:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jchaves506](https://avatars.discourse-cdn.com/v4/letter/j/4bbf92/32.png) [@jchaves506](https://discuss.elastic.co/u/jchaves506)\
**Post date:** [March 11, 2021, 10:19pm UTC](https://discuss.elastic.co/t/event-get-message-bytesize/267004/1 "2021-03-11T22:19:17Z")

</div>

Continuing the discussion from [How to get entire enriched "event" size (not message size)](https://discuss.elastic.co/t/how-to-get-entire-enriched-event-size-not-message-size/255184):

I'm using metricbeat, and I'm looking to know what's the size of the message, I tried using that but I'm getting:

[ERROR][logstash.filters.ruby] Ruby exception occurred: undefined method `bytesize' for nil:NilClass

I've been looking for a reference page about what other options do I have to get this but I couldn't find it. I also found someone saying about mentioning the LENGTH attribute could be used but that didn't work either.

could someone please help me on this?

thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 11, 2021, 10:47pm UTC](https://discuss.elastic.co/t/event-get-message-bytesize/267004/2 "2021-03-11T22:47:36Z")

</div>

It is really not a simple question to answer, because it is unclear what you are asking for. If you want the length of the JSON string that will get written to elasticsearch then serialize the event and check the length of the string.

If you want an approximation of the size of the entire event then you could re-purpose some [code](https://github.com/kaspernj/knjrbfw/blob/master/lib/knj/memory_analyzer.rb#L334).

If you want to know how much memory is allocated for an object that will vary between JVMs, and depend on what other objects exist (think string pools).

Note that

```
ruby { code => 'event.set("size", event.to_s.bytesize)' }

```

does not do what you want because event.to\_s does not do what you expect.

---

<div class="post-metadata">

**Author:** ![jchaves506](https://avatars.discourse-cdn.com/v4/letter/j/4bbf92/32.png) [@jchaves506](https://discuss.elastic.co/u/jchaves506)\
**Post date:** [March 12, 2021, 2:50pm UTC](https://discuss.elastic.co/t/event-get-message-bytesize/267004/3 "2021-03-12T14:50:35Z")

</div>

Thanks... well, what I'm looking is a way to know the size of the message logstash is analizing, the code below works for events from winlogbeats, but not for metricbeats, I guess the attribute 'message' is not part of the event for metricbeat, and wondering what would it be then, I haven't found any documentation about that.  
Probably packetbeat could tell me easier what's the size of the package sent by the device but is not my intention to use that.

```auto
    filter {
        ruby {
            code => "event.set('message_size', event.get('message').bytesize)"
        }
    }

```

---

<div class="post-metadata">

**Author:** ![jchaves506](https://avatars.discourse-cdn.com/v4/letter/j/4bbf92/32.png) [@jchaves506](https://discuss.elastic.co/u/jchaves506)\
**Post date:** [March 12, 2021, 6:07pm UTC](https://discuss.elastic.co/t/event-get-message-bytesize/267004/4 "2021-03-12T18:07:31Z")

</div>

Ok... since the only module I have active in metricbeat is SYSTEM.YML what I did was:

```auto
ruby { 
         code => "event.set('systemSize', event.get('system').to_s.bytesize)"
}

```

that is returning what I suppose is the size of that message from beats, at list the part related to the module at least.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2021, 6:08pm UTC](https://discuss.elastic.co/t/event-get-message-bytesize/267004/5 "2021-04-09T18:08:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
