# Iteration/Ruby help in Logstash

**URL:** <https://discuss.elastic.co/t/iteration-ruby-help-in-logstash/47409>\
**Category:** Logstash\
**Created:** [April 14, 2016, 3:19pm UTC](https://discuss.elastic.co/t/iteration-ruby-help-in-logstash/47409 "2016-04-14T15:19:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dustman1977](https://avatars.discourse-cdn.com/v4/letter/d/cab0a1/32.png) [@Dustman1977](https://discuss.elastic.co/u/Dustman1977)\
**Post date:** [April 14, 2016, 3:19pm UTC](https://discuss.elastic.co/t/iteration-ruby-help-in-logstash/47409/1 "2016-04-14T15:19:57Z")

</div>

I'm Parsing an XML stream that I'm parsing with Logstash. I have one section of the message that is repetitive and in varying lengths 0 to 24 is the highest I've seen so far:

> ```
> <anomaly>
> <typeI>5.243618,20.591172,off</typeI>
> <typeII>off</typeII>
> <model id="nanori">0.000000,169.577650</model>
> <model id="kisorapubu">0.000000,100.000000</model>
> <model id="cenanoge">41.351352,300.157450</model>
> </anomaly>
> 
> ```

In my filter I first use the xml plugin:

> xml {  
> store\_xml =\> "false"  
> source =\> "message"  
> xpath =\> [  
> "/event/detail/anomaly/typeII/text()", "Anom\_TypeII",  
> "/event/detail/anomaly/typeI/text()", "Anom\_TypeI",  
> "/event/detail/anomaly/model/@id", "Anom\_ModelName",  
> "/event/detail/anomaly/model/text()", "Anom\_ModelValues",  
> ]  
> }

Which roles up the model into two arrays, Anom\_ModelName and Anom\_ModelValues (Taken from kibana)

Anom\_ModelName: nanori, kisorapubu, cenanoge  
Anom\_ModelValues: 0.000000,169.577650 0.000000,100.000000 41.351352,300.157450

I then use an if statement to break those fields up into model named specific output and threshold values.

> if [Anom\_ModelName][0] =~ /.+/ {  
> csv {  
> source =\> "[Anom\_ModelValues][0]"  
> columns =\> ["Model\_Out", "Model\_Thres"]  
> separator =\> ","  
> skip\_empty\_columns =\> "true"  
> }  
> mutate {  
> convert =\> { "Model\_Out" =\> "float" }  
> convert =\> { "Model\_Thres" =\> "float" }  
> add\_field =\> {  
> "Model\_%{Anom\_ModelName[0]}_Output" =\> "%{Model\_Out}"  
> "Model_%{Anom\_ModelName[0]}\_Threshold" =\> "%{Model\_Thres}"  
> }  
> remove\_field =\> ["Model\_Out", "Model\_Thres"]  
> }  
> }

And then I copy and paste that, so far I've only done it for the first 11 models, but I know there is probably a much cleaner way using Ruby. And I've tried to implement something like [Iteration in Logstash](https://discuss.elastic.co/t/iteration-in-logstash/26123) but failed miserably. Oh, and one slight problem, I don't know Ruby. 🙂 Any help?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:02am UTC](https://discuss.elastic.co/t/iteration-ruby-help-in-logstash/47409/2 "2017-07-06T05:02:15Z")

</div>


