# How to pass mutate filter field value to Ruby filter

**URL:** <https://discuss.elastic.co/t/how-to-pass-mutate-filter-field-value-to-ruby-filter/180413>\
**Category:** Logstash\
**Created:** [May 9, 2019, 5:02pm UTC](https://discuss.elastic.co/t/how-to-pass-mutate-filter-field-value-to-ruby-filter/180413 "2019-05-09T17:02:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![saroja](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@saroja](https://discuss.elastic.co/u/saroja)\
**Post date:** [May 9, 2019, 5:02pm UTC](https://discuss.elastic.co/t/how-to-pass-mutate-filter-field-value-to-ruby-filter/180413/1 "2019-05-09T17:02:08Z")

</div>

```auto
input {
  http_poller {
          urls => {
               request1 => {
                   method => get
                   url => "http://localhost:8888/getAuthToken?uid=${uid}&password=${password}"
		
				   headers => {
                            Accept => "application/json"
                   } 
				  
	
                }
				    `indent preformatted text by 4 spaces`
            }
		#response string would be like below
		#{"token_type":"mybearer","mapi":"API Key","access_token":"wxyzppppqqqrrrsss","scope":"scope","refresh_token":"9999911222","@timestamp":"2019-05-09T10:07:01.265Z","expires_in":3600,"@version":"1"}
		
		request_timeout => 60
        #Supports "cron", "every", "at" and "in" schedules by rufus scheduler
        schedule => { cron => "*/1 * * * * UTC"}
		
        codec => "json"
		
        # A hash of request metadata info (timing, response headers, etc.) will be sent here
        #metadata_target => "http_poller_metadata"
		
		target => "response_message"
	}
		                  

}	

filter {

  grok {
      match => { "message" => "%{GREEDYDATA:response_message}"}
     }
	 
	mutate { 
    	add_field => { 
		"token_type" => "%{[response_message][token_type]}"  
		"access_token" => "%{[response_message][access_token]}" 
		"refresh_token" => "%{[response_message][refresh_token]}" 
		} 
		remove_field => ["response_message"]
    }
	mutate { 
    	add_field => { 
		 "[@metadata][token_type]" => "%{token_type}" 
		 "[@metadata][access_token]" => "%{access_token}" 
		} 
    }
	
 ruby {
        
	    code => "event.set( 'param1',%{[token_type]})"
	}
 ruby {
   
	   code => "event.set( 'param2',%{[access_token]})"
	}

  ruby {
    init => "
	        require 'net/http';
	        require 'json'"
    code => "   
		 event.set('param3',event.get('param1'));
		 event.set('param4',event.get('param2'));
		 uri = URI('http://127.0.0.1:8888/getDetails?tokentype=%{param3}&accesstoken=%{param4}')
         res = Net::HTTP.get_response(uri);
		 result = JSON.parse(res.body)
		 event.set('resmsg',result);
		 "
  }
  
  
  
  
}

output {
  stdout {
    codec => rubydebug 
  }
  
}

```

Not able to set the field value in ruby filter and getting output like bellow. Could you please help me out to resolve it. Thanks.

```auto
{
           "param1" => "[token_type]",
           "param3" => "[token_type]",
       
           "param4" => "[access_token]",
           "param2" => "[access_token]",
    }

```

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [May 9, 2019, 5:13pm UTC](https://discuss.elastic.co/t/how-to-pass-mutate-filter-field-value-to-ruby-filter/180413/2 "2019-05-09T17:13:56Z")

</div>

the code strings being passed to the ruby filter do not support sprintf string interpolation, because the code is transformed into a helper at filter startup that is shared across events.

You'll need to use the Event API's `Event#get(fieldname)` inside the code to get a value from the current event:

```auto
filter {
  ruby {
    code => "
      token_type = event.get('[token_type]')
      event.set('[param1]', token_type) unless token_type.nil?
    "
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2019, 5:26pm UTC](https://discuss.elastic.co/t/how-to-pass-mutate-filter-field-value-to-ruby-filter/180413/3 "2019-05-09T17:26:10Z")

</div>

> [@saroja](#):
>
> ruby { code =\> "event.set( 'param1',%{[token\_type]})" }

Why do this with ruby rather than [mutate+copy](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-copy) or mutate+add\_field?

> [@](#):
>
> ```
> code => "   
> event.set('param3',event.get('param1'));
> event.set('param4',event.get('param2'));
> uri = URI('http://127.0.0.1:8888/getDetails?tokentype=%{param3}&accesstoken=%{param4}')
> [...]
> "
> 
> ```

You can do that using

```
    ruby {
        code => '
     p1 = event.get("param1")
     p2 = event.get("param2")
     uri = URI("http://127.0.0.1:8888/getDetails?tokentype=#{p1}&accesstoken=#{p2}")

```

Why not use an [http](https://www.elastic.co/guide/en/logstash/current/plugins-filters-http.html) filter plugin?

---

<div class="post-metadata">

**Author:** ![saroja](https://avatars.discourse-cdn.com/v4/letter/s/eada6e/32.png) [@saroja](https://discuss.elastic.co/u/saroja)\
**Post date:** [May 9, 2019, 7:30pm UTC](https://discuss.elastic.co/t/how-to-pass-mutate-filter-field-value-to-ruby-filter/180413/4 "2019-05-09T19:30:13Z")

</div>

Hi Badger,

Thank you very much for your prompt response.I have used the mutate+copy with ruby filter.Now code is working properly. I am adding code here.

{  
input{  
#input wll geneate the json string.  
#{"token\_type":"mybearer","mapi":"API Key","access\_token":"wxyzppppqqqrrrsss","scope":"scope","refresh\_token":"9999911222","@timestamp":"2019-05-09T10:07:01.265Z","expires\_in":3600,"@version":"1"}  
}  
}

filter {  
mutate {  
add\_field =\> {  
"token\_type" =\> "%{[response\_message][token\_type]}"  
"access\_token" =\> "%{[response\_message][access\_token]}"  
"refresh\_token" =\> "%{[response\_message][refresh\_token]}"  
}  
remove\_field =\> ["response\_message"]  
}

mutate {  
copy =\> {  
"token\_type" =\> "param1"  
"access\_token" =\> "param2"  
}  
}

ruby {  
init =\> "  
require 'net/http';  
require 'json'"  
code =\> "  
p1 = event.get('param1');  
p2 = event.get('param2');  
uri = URI('[http://localhost:8888/getDetails?tokentype=p1&accesstoken=p2](http://localhost:8888/getDetails?tokentype=p1&accesstoken=p2)')  
res = Net::HTTP.get\_response(uri);  
#result = JSON.parse(res.body);  
event.set('resmsg',res.code);  
"  
}

}  
output {  
stdout {  
codec =\> rubydebug

}  
}

Thank you 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2019, 7:30pm UTC](https://discuss.elastic.co/t/how-to-pass-mutate-filter-field-value-to-ruby-filter/180413/5 "2019-06-06T19:30:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
