# Kibana didn't load the data when using ruby filter in logstash

**URL:** <https://discuss.elastic.co/t/kibana-didnt-load-the-data-when-using-ruby-filter-in-logstash/94308>\
**Category:** Logstash\
**Created:** [July 24, 2017, 10:28am UTC](https://discuss.elastic.co/t/kibana-didnt-load-the-data-when-using-ruby-filter-in-logstash/94308 "2017-07-24T10:28:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![moabbas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moabbas/32/19231_2.png) [@moabbas](https://discuss.elastic.co/u/moabbas)\
**Post date:** [July 24, 2017, 10:28am UTC](https://discuss.elastic.co/t/kibana-didnt-load-the-data-when-using-ruby-filter-in-logstash/94308/1 "2017-07-24T10:28:34Z")

</div>

I wrote ruby code in logstash conf file like this  
mutate {  
add\_field =\> {"[location]" =\> "[0,0]"}  
}  
ruby{  
code =\> 'event.set("[location]", [(event.get("%{[lt][py]}").to\_f \* 5.6) / 10), event.get("[lt][px]"])) '  
}

what i found in the logstash log file is that:  
[2017-07-24T12:17:46,538][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://elastic:xxxxxx@127.0.0.1:9200/](http://elastic:xxxxxx@127.0.0.1:9200/), :path=\>"/"}  
[2017-07-24T12:17:46,638][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>#Java::JavaNet::URI:0x3dff0f9b}  
[2017-07-24T12:17:46,639][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2017-07-24T12:17:46,666][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>50001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=\>false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2017-07-24T12:17:46,671][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>[#Java::JavaNet::URI:0x4907425a]}

I couldn't find data in kibana. After i removed the ruby code logstash worked fine.  
Does anyone know how to deal with that ?

Thanks,  
Muhammad Abbas

---

<div class="post-metadata">

**Author:** ![moabbas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moabbas/32/19231_2.png) [@moabbas](https://discuss.elastic.co/u/moabbas)\
**Post date:** [July 24, 2017, 1:21pm UTC](https://discuss.elastic.co/t/kibana-didnt-load-the-data-when-using-ruby-filter-in-logstash/94308/2 "2017-07-24T13:21:14Z")

</div>

Any suggestions for the above !

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [July 24, 2017, 2:24pm UTC](https://discuss.elastic.co/t/kibana-didnt-load-the-data-when-using-ruby-filter-in-logstash/94308/3 "2017-07-24T14:24:48Z")

</div>

You have too many brackets etc.

This should work:

```auto
mutate {
  # set [location] as a path to an Array.
  add_field => {"[location]" => [0, 0]}  
}
ruby {
  # overwrite previous array, path [location]
  code => 'event.set("[location]", [0.56 * event.get("[lt][py]").to_f, event.get("[lt][px]")])'
}

```

This almost works but does not ☹ :

```auto
mutate {
  add_field => {"[location]" => [], "[location][1]" => "%{[lt][px]}"}
}
ruby{
  code => 'event.set("[location][0]", 0.56 * event.get("[lt][py]").to_f)'
}
# setting an field in 'add_field' uses sprintf and creates a String in "[location][1]".
# Event: {"@timestamp"=>2017-07-24T13:44:29.892Z, "@version"=>"1", "lt"=>{"px"=>11, "py"=>560}, "location"=>[313.6, "11"]}

```

To experiment on your dev box/laptop...  
You can do this kind of thing:

```auto
$ bin/bundle console
Resolving dependencies...................
irb: warn: can't alias context from irb_context.
irb(main):001:0> require 'logstash/event'
=> true
irb(main):002:0> event = LogStash::Event.new
=> #<LogStash::Event:0x62b635fe>
irb(main):003:0> event.set("[location]", [0,0])
=> [0, 0]
irb(main):004:0> event.to_hash
=> {"@timestamp"=>2017-07-24T13:44:29.892Z, "@version"=>"1", "location"=>[0, 0]}
irb(main):005:0> event.set("[lt]", {"py" => 560, "px" => 11})
=> {"py"=>560, "px"=>11}
irb(main):006:0> event.to_hash
=> {"@timestamp"=>2017-07-24T13:44:29.892Z, "@version"=>"1", "lt"=>{"px"=>11, "py"=>560}, "location"=>[0, 0]}
irb(main):007:0> event.set("[location]", [0.5 * event.get("[lt][py]").to_f, 2 * event.get("[lt][px]").to_f])
=> [280.0, 22.0]
irb(main):008:0> event.to_hash
=> {"@timestamp"=>2017-07-24T13:44:29.892Z, "@version"=>"1", "lt"=>{"px"=>11, "py"=>560}, "location"=>[280.0, 22.0]}

```

---

<div class="post-metadata">

**Author:** ![moabbas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moabbas/32/19231_2.png) [@moabbas](https://discuss.elastic.co/u/moabbas)\
**Post date:** [July 24, 2017, 2:47pm UTC](https://discuss.elastic.co/t/kibana-didnt-load-the-data-when-using-ruby-filter-in-logstash/94308/4 "2017-07-24T14:47:52Z")

</div>

Hi @guyboertje  
i tried this code but it doesn't work

> [@guyboertje](#):
>
> mutate {
> 
> # set [location] as a path to an Array.
> 
> add\_field =\> {"[location]" =\> [0, 0]}  
> }  
> ruby {
> 
> # overwrite previous array, path [location]
> 
> code =\> 'event.set("[location]", [0.56 \* event.get("[lt][py]").to\_f, event.get("[lt][px]")])'  
> }

when i try this the same output for logstash log file came out. and i couldn't find any data in kibana

 ![](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e4e81867247950814bc0a8dec1ac5bcc3a8f6a17.png)  
Here is my log file for logstash after applying the code above.  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/1/2103181e389411ba3eb6038d1ec4bf511cde3a64.png)

---

<div class="post-metadata">

**Author:** ![moabbas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moabbas/32/19231_2.png) [@moabbas](https://discuss.elastic.co/u/moabbas)\
**Post date:** [July 24, 2017, 4:17pm UTC](https://discuss.elastic.co/t/kibana-didnt-load-the-data-when-using-ruby-filter-in-logstash/94308/5 "2017-07-24T16:17:53Z")

</div>

The first one was the solution for me after try it many times  
Thanks @guyboertje

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2017, 4:17pm UTC](https://discuss.elastic.co/t/kibana-didnt-load-the-data-when-using-ruby-filter-in-logstash/94308/6 "2017-08-21T16:17:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
