# Event.sprintf question for use in logstash-filter-elasticsearch

**URL:** <https://discuss.elastic.co/t/event-sprintf-question-for-use-in-logstash-filter-elasticsearch/81758>\
**Category:** Logstash\
**Created:** [April 10, 2017, 7:34am UTC](https://discuss.elastic.co/t/event-sprintf-question-for-use-in-logstash-filter-elasticsearch/81758 "2017-04-10T07:34:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nick-george](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nick-george/32/23318_2.png) [@nick-george](https://discuss.elastic.co/u/nick-george)\
**Post date:** [April 10, 2017, 7:34am UTC](https://discuss.elastic.co/t/event-sprintf-question-for-use-in-logstash-filter-elasticsearch/81758/1 "2017-04-10T07:34:08Z")

</div>

Hi,

Is there any way to get event.sprintf to print the entire event, not just individual fields? I'm trying to build a percolator query that contains the entire logstash event.

What I'd like my percolator query to look like:

```
{
  "query" : {
    "percolate" : {
       "field" : "query",
       "document_type" : "doctype",
       "document": { <THE ENTIRE LOGSTASH EVENT HERE>}
    }
  }
}

```

My logstash conf looks like

```
  elasticsearch {
      index => 'percolator'
      query_template => 'query_template.json' # The template above
  }

```

And the sprintf code in the filter I'm referring to is below. The query\_dsl variable contains the content of the query\_template.json file.

```
if @query_dsl
        query = LogStash::Json.load(event.sprintf(@query_dsl))
        params[:body] = query
...

```

Many thanks,  
Nick George

---

<div class="post-metadata">

**Author:** ![nick-george](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nick-george/32/23318_2.png) [@nick-george](https://discuss.elastic.co/u/nick-george)\
**Post date:** [April 10, 2017, 10:51am UTC](https://discuss.elastic.co/t/event-sprintf-question-for-use-in-logstash-filter-elasticsearch/81758/2 "2017-04-10T10:51:41Z")

</div>

Just in case anyone else ever has this problem, I appear to have worked around it with the following logstash config.  
It would work in any case where you need to jam the entire event into a single field (for whatever reason).

```
ruby { #Create a new field that contains the entire JSON dump of the event (as it currently stands)
  code => "event.set('event_json', event.to_json())"
}

elasticsearch {
  index => 'percolator'
  query_template => '/etc/logstash/query_template.json'
}

mutate {
  remove_field => 'event_json'
}

```

where the query\_template.json file contains:

```
{
  "query" : {
    "percolate" : {
       "field" : "query",
       "document_type" : "doctype",
       "document": %{[event_json]}
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2017, 10:52am UTC](https://discuss.elastic.co/t/event-sprintf-question-for-use-in-logstash-filter-elasticsearch/81758/3 "2017-05-08T10:52:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
