# External Ruby script

**URL:** <https://discuss.elastic.co/t/external-ruby-script/218049>\
**Category:** Logstash\
**Created:** [February 5, 2020, 6:54pm UTC](https://discuss.elastic.co/t/external-ruby-script/218049 "2020-02-05T18:54:01Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Incauto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incauto/32/60149_2.png) [@Incauto](https://discuss.elastic.co/u/Incauto)\
**Post date:** [February 5, 2020, 6:54pm UTC](https://discuss.elastic.co/t/external-ruby-script/218049/1 "2020-02-05T18:54:01Z")

</div>

Hi im trying to use a ruby script outside the logstash conf, the ruby secction in the conf is outside the filter, hostgroup on grok is the field of interest, it can be variable, somethimes has one hostgroup, sometimes 3, sometimes X.

the log is this one:

```auto
02/04/20 17:03:13 ['V.Errazuriz', 'V.Errazuriz-Network', 'Auto Discovery'] 

```

this is the filter

```auto
filter {
        if [application] == "2uptime" {
                grok {
                        match => {"message" => "%{DATA:fecha} %{TIME:hora} \[%{DATA:hostgroup}\]" }
    }
}

```

this is the path to the external script

```auto
ruby {
        path => "/etc/logstash/conf.d/rubyparse.rb"
        script_params => {
        "source_field" => "hostgroup"
        }
}

```

And this is my external script,

```auto

def register(params)
        @source_field = params["source_field"]
end

def filter(event)

#add separated string in to an array
h = event.get("@source_field").split(",")
#delete the single quotes surrounding the strings
hgn = h.map{ |n| n.delete_prefix("'").delete_suffix("'") }

if hgn then
        hgn.each_index { |i|
  event.set("hgname_#{i+1}", hgn[i])
}
 return [event]
end

```

but this rows me an error.

is map method usable in logstahs? inside his library  
how the processed data comes back to the conf from the ruby script

I understand the how to pass the value to the external script,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 5, 2020, 8:47pm UTC](https://discuss.elastic.co/t/external-ruby-script/218049/2 "2020-02-05T20:47:25Z")

</div>

> [@Incauto](#):
>
> ```
> if hgn then
> hgn.each_index { |i| event.set("hgname_#{i+1}", hgn[i]) }
> return [event]
> end
> 
> ```

You are missing an end for the if.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 4, 2020, 8:47pm UTC](https://discuss.elastic.co/t/external-ruby-script/218049/3 "2020-03-04T20:47:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
