# Getting sum of a field in xml

**URL:** <https://discuss.elastic.co/t/getting-sum-of-a-field-in-xml/251657>\
**Category:** Logstash\
**Created:** [October 10, 2020, 8:45pm UTC](https://discuss.elastic.co/t/getting-sum-of-a-field-in-xml/251657 "2020-10-10T20:45:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ameeruddin\_Mohammed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameeruddin_mohammed/32/41289_2.png) [@Ameeruddin\_Mohammed](https://discuss.elastic.co/u/Ameeruddin_Mohammed)\
**Post date:** [October 10, 2020, 8:45pm UTC](https://discuss.elastic.co/t/getting-sum-of-a-field-in-xml/251657/1 "2020-10-10T20:45:42Z")

</div>

hi, i am new to elk. with a lot of googling and checking responses of @Badger i was able to come up with a working config to load data as i wanted.

sample loaded data

{  
"@timestamp" =\> xxx,  
"host" =\> "xxx",  
"data" =\> {  
"pmAverageSirError" =\> "3354,860,908,1053,1414,1868,1263,1603,1607,2122,1538,2226,1701,1911,1735,2866,2196,2572,3087,4539,8700,40007,9578,1393,708,382,304,217,172,119,90,79,65,57,62,42,38,35,25,22,22,171",  
"measObjLdn" =\> "ManagedElement=xxx,NodeBFunction=1,NodeBLocalCellGroup=1,NodeBLocalCell=xxx,RadioLinks=1"  
},  
"tags" =\> [  
[0] "multiline",  
[1] "\_rubyexception"  
],  
"@version" =\> "1",  
"path" =\> "xxx"  
}

now i want to sum a field so i tried

ruby {  
code =\> '  
a = event.get("[data][pmAverageSirError]")  
if a  
sum = 0  
a.each\_index { |x|  
sum += a.to\_i

```
		        }
		        event.set("sum_pmAverageSirError", sum)
				event.set("test", a)
		    end
		'
	}

```

please support.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 10, 2020, 9:20pm UTC](https://discuss.elastic.co/t/getting-sum-of-a-field-in-xml/251657/2 "2020-10-10T21:20:36Z")

</div>

Ruby arrays are Enumerable, and the Enumerable module has a sum function.

```
    ruby {
        code => '
            a = event.get("[data][pmAverageSirError]")
            if a
                a = a.split(",")
                a.each_index { |x| a[x] = a[x].to_i }
                event.set("sum_pmAverageSirError", a.sum)
            end
        '
    }
```

---

<div class="post-metadata">

**Author:** ![Ameeruddin\_Mohammed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ameeruddin_mohammed/32/41289_2.png) [@Ameeruddin\_Mohammed](https://discuss.elastic.co/u/Ameeruddin_Mohammed)\
**Post date:** [October 10, 2020, 9:34pm UTC](https://discuss.elastic.co/t/getting-sum-of-a-field-in-xml/251657/3 "2020-10-10T21:34:04Z")

</div>

> [@Badger](#):
>
> ```auto
> ruby {
> code => '
> a = event.get("[data][pmAverageSirError]")
> if a
> a = a.split(",")
> a.each_index { |x| a[x] = a[x].to_i }
> event.set("sum_pmAverageSirError", a.sum)
> end
> '
> }
> 
> ```

thanks for the reply. it works. is it possible from my previous config that i can move everything our of data array and have only the actual fields and values?

i am using a code provided by you in some thread.

```auto
        xml { source => "message" target => "[@metadata][theXML]" force_array => true }
    ruby {
        code => '
            xml = event.get("[@metadata][theXML]")
            types = xml["measType"]
            values = xml["measValue"]
            a = []
            values.each { |x|
                h = {}
                h["measObjLdn"] = x["measObjLdn"]
                x["r"].each_index { |i|
                    h[types[i]["content"]] = x["r"][i]["content"]
                }
                a << h
            }
            event.set("data", a)
        '
    }
	
			if ([data]) {
				split { field => "[data]" }
				}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 11, 2020, 9:19pm UTC](https://discuss.elastic.co/t/getting-sum-of-a-field-in-xml/251657/4 "2020-10-11T21:19:58Z")

</div>

To move sub-fields to the top level you can use code like [this](https://discuss.elastic.co/t/how-to-dynamically-move-nested-key-value-to-root-level/180006/2).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2020, 9:20pm UTC](https://discuss.elastic.co/t/getting-sum-of-a-field-in-xml/251657/5 "2020-11-08T21:20:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
