# How Can I See the Inside of my Logstash Event Object in a Ruby Script?

**URL:** <https://discuss.elastic.co/t/how-can-i-see-the-inside-of-my-logstash-event-object-in-a-ruby-script/197415>\
**Category:** Logstash\
**Created:** [August 29, 2019, 8:15pm UTC](https://discuss.elastic.co/t/how-can-i-see-the-inside-of-my-logstash-event-object-in-a-ruby-script/197415 "2019-08-29T20:15:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![redapplesonly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redapplesonly/32/57700_2.png) [@redapplesonly](https://discuss.elastic.co/u/redapplesonly)\
**Post date:** [August 29, 2019, 8:15pm UTC](https://discuss.elastic.co/t/how-can-i-see-the-inside-of-my-logstash-event-object-in-a-ruby-script/197415/1 "2019-08-29T20:15:00Z")

</div>

Hi Logstash Jedi Masters,

I’m building my first Logstash service. I want my filter to be able to do a little processing based on the data flowing through LS.

My LS setup is pretty basic. Here’s my LS config file, simplified for this post:

```
input {
  kafka {
    ...stuff here...
  }
}

filter {
  ruby {
    # Send all events to an external Ruby script:
    path => "/home/me/ruby_scripts/myScript.rb"
  }
}

output {
  elasticsearch{
    ...stuff here...
  }
}

```

Pretty simple. The problem is, when “myScript.rb” is called, I need it to actually look inside the event object and do some basic processing on the data inside. Here’s the script:

```
#!/usr/bin/env ruby

def filter(event)
        puts "myScript.rb :: I got an event! Data is: "+event.getData()
        return [event]
end

```

Obviously this doesn’t work, because I don’t understand much about that Logstash event object. I’ve looked it up ([here](https://github.com/elastic/logstash/blob/master/logstash-core/src/main/java/org/logstash/Event.java)) and it looks like the object is just a wrapper for another embedded data object called a ConvertedMap:

```
public Event()
    {
        this.metadata = new ConvertedMap(10);
        this.data = new ConvertedMap(10);
        this.data.putInterned(VERSION, VERSION_ONE);
        this.cancelled = false;
        setTimestamp(Timestamp.now());
    }

```

I’m assuming the ConvertedMap is defined [here](https://github.com/elastic/logstash/blob/master/logstash-core/src/main/java/org/logstash/ConvertedMap.java)…? And this, in turn, is a child class of IdentityHashMap, [defined here](https://docs.oracle.com/javase/8/docs/api/java/util/IdentityHashMap.html)?

And here you can see my problem. I know that when data is pulled into Logstash, that data is passed to my Ruby script as an event object. But I never defined the interior of the event object. Is there some way of determining what it is? And how I can access the actual data LS is passing along to ElasticSearch? Are there any tutorials anyone could recommend?

Thanks!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 29, 2019, 9:25pm UTC](https://discuss.elastic.co/t/how-can-i-see-the-inside-of-my-logstash-event-object-in-a-ruby-script/197415/2 "2019-08-29T21:25:03Z")

</div>

You can get a hash containing the contents of the event using event.to\_hash

---

<div class="post-metadata">

**Author:** ![redapplesonly](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/redapplesonly/32/57700_2.png) [@redapplesonly](https://discuss.elastic.co/u/redapplesonly)\
**Post date:** [August 30, 2019, 8:15pm UTC](https://discuss.elastic.co/t/how-can-i-see-the-inside-of-my-logstash-event-object-in-a-ruby-script/197415/3 "2019-08-30T20:15:50Z")

</div>

> [@Badger](#):
>
> .to\_hash

Yes! Absolutely right! Thank you Badger, you saved my bacon.

I'm going to add a few notes to anyone who might be following in my footsteps. I found that given Badger's trick, I could convert my event into a hash, and then convert that hash into a string. Here's how it works...

Again, I have this as my filter in my LS config file:

```
filter {
  ruby {
    # Pass event to external Ruby script
    path => "/home/me/ruby_scripts/myScript.rb"
  }
}

```

Here's that external script:

```
#!/usr/bin/env ruby

def filter(event)
        puts "Your event as a string is :: "+(event.to_hash).to_s
        return [event]
end

```

That syntax took a little while to figure out, but it was worth it.

For other beginners like me, here are the resources I used. Two handy sites on Ruby for beginners are [here](http://sandbox.mc.edu/~bennet/ruby/code/index.html) and [here](https://www.ruby-lang.org/en/documentation/quickstart/). And for commands related to hashes in Ruby, look [here](https://ruby-doc.org/core-2.4.2/Hash.html).

Thank again Badger!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 8:16pm UTC](https://discuss.elastic.co/t/how-can-i-see-the-inside-of-my-logstash-event-object-in-a-ruby-script/197415/4 "2019-09-27T20:16:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
