# Initializing a new grok filter from ruby filter

**URL:** <https://discuss.elastic.co/t/initializing-a-new-grok-filter-from-ruby-filter/311722>\
**Category:** Logstash\
**Created:** [August 9, 2022, 12:16pm UTC](https://discuss.elastic.co/t/initializing-a-new-grok-filter-from-ruby-filter/311722 "2022-08-09T12:16:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![who](https://avatars.discourse-cdn.com/v4/letter/w/cdc98d/32.png) [@who](https://discuss.elastic.co/u/who)\
**Post date:** [August 9, 2022, 12:16pm UTC](https://discuss.elastic.co/t/initializing-a-new-grok-filter-from-ruby-filter/311722/1 "2022-08-09T12:16:50Z")

</div>

I'm going to declare and call grok filter from inside a ruby filter like this:

```auto
ruby {
	code => "@grok = LogStash::Filters::Grok
			 @grok.new(event.get("message"), "\d+")

			 #call grok plugin for this pipleline
			"
}

```

What's the correct parameter for grok's initializing method, and how to build that? Because Logstash gives this error with 2 parameters:

> Ruby exception occurred: wrong number of arguments (given 2, expected 1)

Also, how to add the created grok filter to the pipeline after initializing that? And make sure this grok filter, with this specific pattern, ONLY processes this event? (every event should have its specific grok)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 9, 2022, 12:44pm UTC](https://discuss.elastic.co/t/initializing-a-new-grok-filter-from-ruby-filter/311722/2 "2022-08-09T12:44:54Z")

</div>

The [syslog filter](https://github.com/logstash-plugins/logstash-input-syslog/blob/7a544560fd7171105f27ffd66db7dc49b542345e/lib/logstash/inputs/syslog.rb#L103) shows how to call a grok filter from ruby.

---

<div class="post-metadata">

**Author:** ![who](https://avatars.discourse-cdn.com/v4/letter/w/cdc98d/32.png) [@who](https://discuss.elastic.co/u/who)\
**Post date:** [August 21, 2022, 6:19am UTC](https://discuss.elastic.co/t/initializing-a-new-grok-filter-from-ruby-filter/311722/3 "2022-08-21T06:19:00Z")

</div>

Thanks, I was testing different aspects of this case, so it took time to post the reply here.  
Any way, here's the summarized method from what @Badger mentioned in previous post; to initiate and use grok filter plugin (or any other filter generally):

# init section:

1. initialize

```auto
@grok_filter = LogStash::Filters::Grok.new(
        "match" => { "message" => "PATTERN" },
        "tag_on_failure" => ["_grokparsefailure"]
# .... and literally any other config option you'd pass into grok plugin in filter pipeline
  )

```

1. Register  
`@grok_filter.register`

* * *

# code section:

1. Utilize  
`@grok_filter.filter(event)`

However, I faced a relevant new issue which will post in [another topic](https://discuss.elastic.co/t/determining-which-item-in-patterns-array-of-a-grok-plugin-was-matched/312538). Thank you @Badger

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 18, 2022, 6:19am UTC](https://discuss.elastic.co/t/initializing-a-new-grok-filter-from-ruby-filter/311722/4 "2022-09-18T06:19:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
