# How do I stringify entire event object in logstash and put it in one field

**URL:** <https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496>\
**Category:** Logstash\
**Created:** [October 21, 2023, 8:42am UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496 "2023-10-21T08:42:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ghanshyam\_baviskar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghanshyam_baviskar/32/126739_2.png) [@ghanshyam\_baviskar](https://discuss.elastic.co/u/ghanshyam_baviskar)\
**Post date:** [October 21, 2023, 8:42am UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496/1 "2023-10-21T08:42:28Z")

</div>

I am trying to implement a dead letter queue pipeline, I want to take entire event , stringify it and put it into a field "strigified\_event". so that it can be monitored for elasticsearch mapper errors

```auto
input {
  dead_letter_queue {
    path => "/home/light/development/repo/logstash/logstash-7.11.0/data/dead_letter_queue"
    commit_offsets => true 
    pipeline_id => "p-logs"
  }

  dead_letter_queue {
    path => "/home/light/development/repo/logstash/logstash-7.11.0/data/dead_letter_queue"
    commit_offsets => true 
    pipeline_id => "p-transactions"
  }
}

output {
  elasticsearch {
    hosts => ["localhost:9200"]
    index => "deadletterqueue-%{+YYYY.MM.dd}"
    action => "create"
  }

  stdout {
    codec => "rubydebug"
  }
  
}

```

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [October 21, 2023, 9:01am UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496/2 "2023-10-21T09:01:45Z")

</div>

I think something like this could work;

```json

filter {
  ruby {
    code => "event.set(\"stringified_event\", event)" 
  }
  mutate {
    convert => {"stringified_event" => " string" }    
  }
}

```

In this "pseudo" code i am using ruby to create a new event with the entire event in it. Then I use mutate to convert it to a string.

Keep in mind this will keep everything around it too.

---

<div class="post-metadata">

**Author:** ![ghanshyam\_baviskar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ghanshyam_baviskar/32/126739_2.png) [@ghanshyam\_baviskar](https://discuss.elastic.co/u/ghanshyam_baviskar)\
**Post date:** [October 21, 2023, 9:34am UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496/3 "2023-10-21T09:34:51Z")

</div>

I tried this, but this is giving following error:

```auto
[2023-10-21T15:04:14,562][ERROR][logstash.filters.ruby][dlq-pipeline][ceac6b40d2466837847c74300de9b46d022d4a7e2aa3091bc528f747c702c877] Ruby exception occurred: undefined method `[]' for #<LogStash::Event:0x6548fcaf>

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 21, 2023, 10:32am UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496/4 "2023-10-21T10:32:23Z")

</div>

Try:

```auto
  ruby {
    code => "event.set( 'stringified_event', event.get('[event][original]') )" 
  }

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 21, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496/5 "2023-10-21T13:24:30Z")

</div>

Can you share what is the output you are getting and what is the output you want? You didn't provide any information about this.

According to the [documentation](https://www.elastic.co/guide/en/logstash/current/dead-letter-queues.html#dlq-example) the `dead_letter_queue` input you will already have the entire event as a string in the `message` field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2023, 1:24pm UTC](https://discuss.elastic.co/t/how-do-i-stringify-entire-event-object-in-logstash-and-put-it-in-one-field/345496/6 "2023-11-18T13:24:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
