# How to pass variable from Logstash filter into ruby parameter

**URL:** <https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438>\
**Category:** Logstash\
**Created:** [May 26, 2023, 1:48pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438 "2023-05-26T13:48:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jirka\_Liska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jirka_liska/32/117513_2.png) [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Post date:** [May 26, 2023, 1:48pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438/1 "2023-05-26T13:48:31Z")

</div>

Hi

I'm trying to create a variable which holds information from input file path. I'm able to do so for example for creating index in Kibana but I'm unable to pass this variable into ruby /plugin/ code. Anyone knows what I'm doing wrong here?

Thanks in advance

here I'm creating variable PK from file path

```auto
    grok {
      match => {
        "[log][file][path]" => ["(?:%{BASE10NUM:PK}-)"]
      }
    }

```

Here I'm trying to pass it into ruby as parameter

```auto
      ruby {
        path => "/usr/local/supporting-scripts/webhook.rb"
        script_params => {
        "primary_key" => "PK"
        }
      }

```

I have tried different possibilities like

```auto
"[PK]"; "%{[PK]}"; "[PK]"; 

```

nothing worked

---

<div class="post-metadata">

**Author:** ![Ofir\_Edi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ofir_edi/32/78181_2.png) [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Post date:** [May 28, 2023, 8:03am UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438/2 "2023-05-28T08:03:34Z")

</div>

Hi,  
From what I can see you are extracting `PK` from the original event and after the grok filter it should be a field on your event.

Since it is part of your event you can access it via the filter function in the ruby code and you don't need to pass it as script\_param. the following script addes a new field with the Dynamic value of `PK`:

```auto
# the value of `params` is the value of the hash passed to `script_params`
# in the logstash configuration

def register(params)

end

# the filter method receives an event and must return a list of events.
# Dropping an event means not including it in the return array,
# while creating new ones only requires you to add a new instance of
# LogStash::Event to the returned array

def filter(event)

event.set("testField", event.get("[PK]"));

return [event]

end

```

Hopes this is helpful.

---

<div class="post-metadata">

**Author:** ![Jirka\_Liska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jirka_liska/32/117513_2.png) [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Post date:** [May 28, 2023, 11:45am UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438/3 "2023-05-28T11:45:18Z")

</div>

Thanks for your reply, it make sense but when I use it like this I'm getting this error:

Could not process event: undefined local variable or method `testField' for

```auto
def filter(event)
    event.set("testField", event.get("[PK]"));

    url = URI('http://rest_api:8000/api/' + testField.to_s + "/")
   
   return []

end

```

---

<div class="post-metadata">

**Author:** ![Ofir\_Edi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ofir_edi/32/78181_2.png) [@Ofir\_Edi](https://discuss.elastic.co/u/Ofir_Edi)\
**Post date:** [May 28, 2023, 1:27pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438/4 "2023-05-28T13:27:41Z")

</div>

Hi @Jirka_Liska ,  
you need to use the `event.get` api to access the variable or to first get it and then use it as a variable.  
also, you must return the event (returning an empty array is like drop). In addition, you need to import uri module.

Kindly try the following (I have ommited to\_s as PK is probably already a string)

```auto
require 'uri';
def filter(event)
    primary_key = event.get("[PK]");

    url = URI('http://rest_api:8000/api/' + primary_key + "/")
   
   return [event]

end

```

Also please notice that you are not manipulating the event in the filter (you init url variable but not using it).

Ofir

---

<div class="post-metadata">

**Author:** ![Jirka\_Liska](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jirka_liska/32/117513_2.png) [@Jirka\_Liska](https://discuss.elastic.co/u/Jirka_Liska)\
**Post date:** [May 28, 2023, 3:59pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438/5 "2023-05-28T15:59:27Z")

</div>

Hi @Ofir_Edi, thanks a lot for your kind support! This solved my problem, thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2023, 3:59pm UTC](https://discuss.elastic.co/t/how-to-pass-variable-from-logstash-filter-into-ruby-parameter/334438/6 "2023-06-25T15:59:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
