# Initialize variable in Logstash ruby

**URL:** <https://discuss.elastic.co/t/initialize-variable-in-logstash-ruby/166950>\
**Category:** Logstash\
**Created:** [February 4, 2019, 12:01pm UTC](https://discuss.elastic.co/t/initialize-variable-in-logstash-ruby/166950 "2019-02-04T12:01:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [February 4, 2019, 12:01pm UTC](https://discuss.elastic.co/t/initialize-variable-in-logstash-ruby/166950/1 "2019-02-04T12:01:34Z")

</div>

Hello.

I have my pipeline configured as follows:

```auto
    ...
      mutate {
       add_field => { "append_request_history_array" => ["%{time_local}, host:%{host}, request_uri:%{request_uri}, user_agent:%{user_agent}] }
      }
      
     fingerprint {
       method => "MD5"
       source => ["myheader"]
       target => ["fingerprint"]
      }

      elasticsearch {
       hosts => ["localhost:9200"]
       index => "logs"
       query => '_id=%{fingerprint}'
       fields => { "request_history_array" => "request_history_array" }
      }

       ruby {
        code => '
         event.set("request_history_array", event.get(request_history_array) + ["append_request_history_array"])
        '
       }
    ...

```

I get error:

```auto
    [2019-02-04T12:53:50,742][ERROR][logstash.filters.ruby] Ruby exception occurred: undefined local variable or method `request_history_array' for #<LogStash::Filters::Ruby:0x5d573291>

```

Why is that? The requested field exists in elasticsearch index that I query.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [February 4, 2019, 12:48pm UTC](https://discuss.elastic.co/t/initialize-variable-in-logstash-ruby/166950/2 "2019-02-04T12:48:23Z")

</div>

The ruby code is referencing a variable `request_history_array` and this is not defined.

I think you will need that to be a string.

I think you are concatenating two arrays, one coming from a ES filter query and one from the mutate/add\_field done earlier.

For added clarity, I would make this a multiline ruby code block:

```auto
      ruby {
        code => '
          retrieved_array = event.get("request_history_array")
          append_array = event.get("append_request_history_array")
          # the plus operator here is an array concat operation, the second arrays elements are added to the first array,
          # duplicates are possible. Use (retrieved_array + append_array).uniq to remove dups.
          event.set("request_history_array", retrieved_array + append_array)
        '
       }

```

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [February 18, 2019, 1:16pm UTC](https://discuss.elastic.co/t/initialize-variable-in-logstash-ruby/166950/3 "2019-02-18T13:16:45Z")

</div>

Thank you for your suggestion.  
I was trying to merge two arrays.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2019, 1:16pm UTC](https://discuss.elastic.co/t/initialize-variable-in-logstash-ruby/166950/4 "2019-03-18T13:16:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
