# From scripted field to logstash

**URL:** <https://discuss.elastic.co/t/from-scripted-field-to-logstash/220062>\
**Category:** Logstash\
**Created:** [February 20, 2020, 12:01am UTC](https://discuss.elastic.co/t/from-scripted-field-to-logstash/220062 "2020-02-20T00:01:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [February 20, 2020, 12:01am UTC](https://discuss.elastic.co/t/from-scripted-field-to-logstash/220062/1 "2020-02-20T00:01:13Z")

</div>

I dunno if this is the place, but since the destination is Logstash's ruby filter, I think it is.  
I have this massive scripted field... and I'm considering reindexing and adding it to the pipeline config, but I'm not really sure how to change painless into ruby. Maybe you guys have some pointers?

It's a scripted field to ease up my team's life when digging into RRAS logs, so it takes a couple fields and gives back a single "ConnectionInfo", containing stuff like parse from Packet Type, Account Status Type, Reason Code and Account Session Time.

I'm not looking for someone to just "translate" it to me, of course, but a couple tips I think would be faster than me trying to learn Ruby all over just for this field.

It starts like this... scripted field is called "ConnectionInfo".

```auto
def code = doc['ReasonCode.keyword'].value;
def packet = doc['PacketType.keyword'].value;
def type = doc['AcctStatusType.keyword'].value;
def tempo = doc['AcctSessionTime.keyword'].value;
def sessionTime = "";

if (tempo != null) { 
	def time = Integer.parseInt(tempo);
	if (time == 0) { sessionTime = "Nao disponivel" }
	else if (time > 3600) { sessionTime = (time / 60 / 60) + " horas, " + (time / 60 % 60) + " minutos e " + (time % 60) + " segundos" }
	else if (time > 60) { sessionTime = (time / 60 % 60) + " minutos e " + (time % 60) + " segundos" }
	else { sessionTime = time + " segundos" }
} else { sessionTime = ""}

if (code == "0") { 
	if ( packet == "1") { return "CONNECTION_REQUEST"; }
	else { 
		if (type == "1") {return "START_CONNECTION"}
		else if (type == "2") {return "END_CONNECTION : " + sessionTime}
		else { return "SUCCESS"; }
		}
	} else if (code == "1") { return "REFUSED: INTERNAL_ERROR";
} else { return code; }

```

I understand it may end up too big for using inline ruby code, so I'd have to move over to [using a Ruby script file](https://www.elastic.co/guide/en/logstash/6.8/plugins-filters-ruby.html#_using_a_ruby_script_file).

---

<div class="post-metadata">

**Author:** ![joaociocca](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joaociocca/32/15827_2.png) [@joaociocca](https://discuss.elastic.co/u/joaociocca)\
**Post date:** [February 20, 2020, 1:40am UTC](https://discuss.elastic.co/t/from-scripted-field-to-logstash/220062/2 "2020-02-20T01:40:51Z")

</div>

Scratch all that, got it.

```auto
code = event.get("ReasonCode").to_i;
packet = event.get("PacketType").to_i;
type = event.get("AcctStatusType").to_i;
tempo = event.get("AcctSessionTime").to_i;

if ! tempo.nil?
  time = tempo;
  if time == 0
    sessionTime = "Nao disponivel";
  elsif time > 3600
    sessionTime = (time / 60 / 60).to_s + " horas, " + (time / 60 % 60).to_s + " minutos e " + (time % 60).to_s + " segundos";
  elsif time > 60
    sessionTime = (time / 60 % 60).to_s + " minutos e " + (time % 60).to_s + " segundos";
  else
    sessionTime = time.to_s + " segundos";
  end
end

if code == 0
  if packet == 1
    connectionInfo = "CONNECTION_REQUEST";
  else
    if type == 1
      connectionInfo = "START_CONNECTION";
    elsif type == 2
      connectionInfo = "END_CONNECTION : " + sessionTime;
    else
      connectionInfo = "SUCCESS";
    end
  end
elsif code == 1
  connectionInfo = "REFUSED: INTERNAL_ERROR";
else
  connectionInfo = code;
end

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2020, 1:40am UTC](https://discuss.elastic.co/t/from-scripted-field-to-logstash/220062/3 "2020-03-19T01:40:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
