# Event.set does not work

**URL:** <https://discuss.elastic.co/t/event-set-does-not-work/298317>\
**Category:** Logstash\
**Created:** [February 25, 2022, 10:54pm UTC](https://discuss.elastic.co/t/event-set-does-not-work/298317 "2022-02-25T22:54:20Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![stemons](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stemons/32/84571_2.png) [@stemons](https://discuss.elastic.co/u/stemons)\
**Post date:** [February 25, 2022, 10:54pm UTC](https://discuss.elastic.co/t/event-set-does-not-work/298317/1 "2022-02-25T22:54:20Z")

</div>

Hello, I'm trying to create new field in my filter, but seems that event.set does not work properly. I can't see neither errors nor the new fields in elastic.

I had to add the if condition since the field is not contained in all the document. How can I add the new derived field?

```auto
ruby {
        init => "require 'time'"
        code => "
                 duration = (event.get('@timestamp').to_i - event.get('start_date').to_i)/60/60;
                 event.set('system.process.cpu.duration', duration);
                 if event.get('system.filesystem.free') != nil
                        fs_gb = event.get('system.filesystem.free') / (1024*1024*1024);
                        event.set('system.filesystem.free_gb', fs_gb);
                 end
                 if event.get('system.cpu.total.pct') != nil
                        cpu_pct = event.get('system.cpu.total.pct') * 100;
                        event.set('system.cpu.total.pct_100', cpu_pct);
                 end
                 if !event.get('system.cpu.total.pct').nil?; event.set('cpu_pct',event.get('system.cpu.total.pct') * 100);end
                "
    }

```

Consider that only system.process.cpu.duration is set properly

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 25, 2022, 11:35pm UTC](https://discuss.elastic.co/t/event-set-does-not-work/298317/2 "2022-02-25T23:35:27Z")

</div>

> [@stemons](#):
>
> `if event.get('system.filesystem.free')`

If that is coming from metricbeat you would have to use

```
 if event.get('[system][filesystem][free]')

```

and so on. logstash does not use the naming convention for fields inside objects that beats and elasticsearch use.

---

<div class="post-metadata">

**Author:** ![stemons](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stemons/32/84571_2.png) [@stemons](https://discuss.elastic.co/u/stemons)\
**Post date:** [February 28, 2022, 10:20am UTC](https://discuss.elastic.co/t/event-set-does-not-work/298317/3 "2022-02-28T10:20:35Z")

</div>

I'm making the same exercise for an aws rds metric, but it is not work. Here is the configuration. Are this module has a different syntax?

```auto
 if event.get('[aws][rds][free_storage][bytes]') != nil
                                rds_free_gb = event.get('[aws][rds][free_storage][bytes]') / (1024*1024*1024);
                                event.set('[aws][rds][free_storage][gb]', rds_free_gb);
                          end

```

---

<div class="post-metadata">

**Author:** ![stemons](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stemons/32/84571_2.png) [@stemons](https://discuss.elastic.co/u/stemons)\
**Post date:** [March 2, 2022, 8:33am UTC](https://discuss.elastic.co/t/event-set-does-not-work/298317/4 "2022-03-02T08:33:45Z")

</div>

Enyone faced the same issue with this metricbeat module? How could I read the incoming events to check the syntax?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2022, 8:34am UTC](https://discuss.elastic.co/t/event-set-does-not-work/298317/5 "2022-03-30T08:34:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
