# Getting error SyntaxError: (ruby filter code):3: syntax error, unexpected kIN logstash

**URL:** https://discuss.elastic.co/t/getting-error-syntaxerror-ruby-filter-code-3-syntax-error-unexpected-kin-logstash/26567
**Category:** Logstash
**Created:** [July 30, 2015, 12:12pm UTC](https://discuss.elastic.co/t/getting-error-syntaxerror-ruby-filter-code-3-syntax-error-unexpected-kin-logstash/26567 "2015-07-30T12:12:34Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)
#### Post date: [July 30, 2015, 12:12pm UTC](https://discuss.elastic.co/t/getting-error-syntaxerror-ruby-filter-code-3-syntax-error-unexpected-kin-logstash/26567/1 "2015-07-30T12:12:34Z")

</div>

I want to split string field "label" which contains hyphen e.g. "Label =SCR1-xyz\_abc-Page "  
I am trying to split

Scenario= SCR1  
Transaction =xyz\_abc  
Request=Page

But with below config getting syntax error. Any idea why?

filter{

csv {  
separator =\> ","  
columns =\> ["timeStamp", "elapsed", "label"]  
}

ruby {  
code =\> "  
tmp = event['label']  
in = tmp.split('-')  
puts tmp  
event['Scenario'] = in[0]  
event['Transaction'] = in[1]  
event['Request'] = in[3]   
"  
}  
}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 30, 2015, 1:22pm UTC](https://discuss.elastic.co/t/getting-error-syntaxerror-ruby-filter-code-3-syntax-error-unexpected-kin-logstash/26567/2 "2015-07-30T13:22:02Z")

</div>

I can't spot any errors in that piece of Ruby, but why not just use the [mutate filter's split option](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-split)?

---

<div class="post-metadata">

### Author: ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)
#### Post date: [July 30, 2015, 1:40pm UTC](https://discuss.elastic.co/t/getting-error-syntaxerror-ruby-filter-code-3-syntax-error-unexpected-kin-logstash/26567/3 "2015-07-30T13:40:31Z")

</div>

As per my understanding if I use below option it will split the strings in same field 'Label'.  
mutate {  
split =\> { "label" =\> "-" }  
}

Currently I have three columns:  
Header: Label|ResponseCode|URL  
Value: Thread-group1-transaction\_1|200|Null  
Value: Thread-group1-transaction\_1-Request1|200|http://google.co.in  
Value: Thread-group1-transaction\_1-Request2|200|http://google.co.in/image  
Value: Thread-group1-transaction\_1-Request3|300|http://google.co.in  
and so...  
However my requirement is to store "Thread-group1-transaction\_1-Request" in such a way that when I search for Request; get corresponding column value of URL, when search for transaction get their corresponding value i.e.Null.

I believe storing each segment in separate field will help in searching. Is it posssible to split and store in separate fields.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 30, 2015, 2:35pm UTC](https://discuss.elastic.co/t/getting-error-syntaxerror-ruby-filter-code-3-syntax-error-unexpected-kin-logstash/26567/4 "2015-07-30T14:35:22Z")

</div>

The mutate filter's split option can only split into the same field, but there are other options for the mutate filter that can help you create new fields based on each array item in an array field.

---

<div class="post-metadata">

### Author: ![Saket\_Kumar](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Saket\_Kumar](https://discuss.elastic.co/u/Saket_Kumar)
#### Post date: [July 30, 2015, 2:56pm UTC](https://discuss.elastic.co/t/getting-error-syntaxerror-ruby-filter-code-3-syntax-error-unexpected-kin-logstash/26567/5 "2015-07-30T14:56:06Z")

</div>

I got success using below config and achieved what I wanted too...

mutate {  
split =\> { "label" =\> "-" }  
add\_field =\> { "Scenario" =\> "%{[label][0]}" }  
add\_field =\> { "Transaction" =\> "%{[label][1]}" }  
add\_field =\> { "Request" =\> "%{[label][2]}" }  
}

thanks!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:33am UTC](https://discuss.elastic.co/t/getting-error-syntaxerror-ruby-filter-code-3-syntax-error-unexpected-kin-logstash/26567/6 "2017-07-06T05:33:20Z")

</div>


