# Global variable?

**URL:** <https://discuss.elastic.co/t/global-variable/96794>\
**Category:** Logstash\
**Created:** [August 11, 2017, 3:24pm UTC](https://discuss.elastic.co/t/global-variable/96794 "2017-08-11T15:24:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chemse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chemse/32/17956_2.png) [@Chemse](https://discuss.elastic.co/u/Chemse)\
**Post date:** [August 11, 2017, 3:24pm UTC](https://discuss.elastic.co/t/global-variable/96794/1 "2017-08-11T15:24:57Z")

</div>

Hello,

Since logstash deals with a log file line by line, I have a field just in the begining of the file, I want to use it value as a condition for the rest of the file. Is there a method to do it ? Make this variable available in all the process ??

**Help !!!!**

---

<div class="post-metadata">

**Author:** ![Chemse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chemse/32/17956_2.png) [@Chemse](https://discuss.elastic.co/u/Chemse)\
**Post date:** [August 14, 2017, 9:53am UTC](https://discuss.elastic.co/t/global-variable/96794/2 "2017-08-14T09:53:06Z")

</div>

I’ve tried this code but it doesn’t work

```
date {
        match => ["period1","dd/MM/YYYY"]
        target=> "period1"
    }
    date {
        match => ["period2","dd/MM/YYYY"]
        target=> "period2"
   }
   ruby {
        code => "event.set('period', (event.get('period2') - event.get('period1'))/3600/24)"

   }
   ruby{
               code => "$my_var " = "%{peroid}" 
       }

```

I want to use the value of $my\_var as a condition for an other event (next line)

---

<div class="post-metadata">

**Author:** ![Chemse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chemse/32/17956_2.png) [@Chemse](https://discuss.elastic.co/u/Chemse)\
**Post date:** [August 14, 2017, 1:16pm UTC](https://discuss.elastic.co/t/global-variable/96794/3 "2017-08-14T13:16:25Z")

</div>

**Help please !!!** 😥😥😥😥

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [August 14, 2017, 2:37pm UTC](https://discuss.elastic.co/t/global-variable/96794/4 "2017-08-14T14:37:41Z")

</div>

Logstash is a streaming processor. There is no way for it to keep state on a line from the beginning of a file using only the `ruby` filter.

You may wonder why this is so. The answer is particularly that Logstash isn't programmed to know if it's going to only ever ready one file. It's designed to keep reading from new files in a location, even if you specify a single-named file. What if that file keeps the same name, but is rotated by some other process? Logstash can't know that. As a result, there's simply no way using the `file` input plugin to read headers from the first line of a file and keep them for use later on in the stream.

There have been some efforts made by some users to write a csv input plugin to accomplish this, as csv files frequently have a header line for this same purpose. I'm not sure where those efforts are hosted, or if you can find them. My point is that what you're seeking requires a dedicated _input_ plugin, and cannot be otherwise accomplished using the `ruby` filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2017, 2:38pm UTC](https://discuss.elastic.co/t/global-variable/96794/5 "2017-09-11T14:38:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
