# Logstash 5 beta 1: Ruby exception occurred: undefined method \`\[\]'

**URL:** <https://discuss.elastic.co/t/logstash-5-beta-1-ruby-exception-occurred-undefined-method/62376>\
**Category:** Logstash\
**Created:** [October 6, 2016, 12:20pm UTC](https://discuss.elastic.co/t/logstash-5-beta-1-ruby-exception-occurred-undefined-method/62376 "2016-10-06T12:20:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [October 6, 2016, 12:20pm UTC](https://discuss.elastic.co/t/logstash-5-beta-1-ruby-exception-occurred-undefined-method/62376/1 "2016-10-06T12:20:11Z")

</div>

Hi,  
I am currently playing around with logstash 5 beta 1.

When I use my filter settings, which are fine with 2.3.4 I get now a ruby exception:

Ruby exception occurred: undefined method `[]'...

my filter code is as followed:

```
filter
{
        ruby
        {
            code =>
            "
                m = event['message'].to_s
                puts m
                event['added_field'] = 'hallo'.to_s
            "
        }
}

```

I used event[] to add, update or read from fields of the event.  
What do I need to use in Logstash 5? Is there a syntax which is working in logstash 1.5 to 5.0 ?

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [October 6, 2016, 12:30pm UTC](https://discuss.elastic.co/t/logstash-5-beta-1-ruby-exception-occurred-undefined-method/62376/2 "2016-10-06T12:30:32Z")

</div>

ok, I shortly after I posted I found the solution:

> [@\_rubyexception when accessing 'event' array in ruby code](https://discuss.elastic.co/t/-rubyexception-when-accessing-event-array-in-ruby-code/57071):
>
> Hi! I would like to get help with the code in ruby filter. logstash version is 5.0.0 alpha4. I am testing the code in ruby filter as below but I am getting \_rubyexception. ruby { code =\> " event['newfield'] = 'test' " } The logstash.log shows as below, :timestamp=\>"2016-08-03T15:26:47.291000+0900", :message=\>"Ruby exception occurred: undefined method[]=' for 2016-08-03T06:26:46.829Z test %{message}:LogStash::Event", :level=\>:error}` I cant find the reason why ruby filter…

> <https://github.com/elastic/logstash/issues/5141>
>
> As per #5140 we have decided to remove Ruby hash-like API and expose new getter …and setter in 5.0. 
> 
> This is a \*\*WIP proposal\*\* and is open for discussions. The identified \*\*undefined behaviours\*\* will probably be the most discussed. Lets keep in mind that this is only the new getter and setter API, other new API proposals should be in their own issue which #5140 will track. 
> \#### Ruby Event API Proposal
> \- A \*\*field reference\*\* is a string using the field reference syntax which is either a bare field name string like \`"foo"\` or using the nested syntax \`"\[foo\]"\` or \`"\[foo\]\[bar\]"\`.
> \##### Setter
> 
> \`\`\` ruby
> \# @param fieldref \[String\] field reference string
> \# @param value \[Object\] the value to set in that field reference
> \# @return \[Event\] this event or self for chainable calls
> event.set(fieldref, value)
> \`\`\`
> \- Values are either string, numeric or timestamp \_scalar\_ values, for example:
>   
> \`\`\` ruby
> event.set("foo", "baz")
> event.set("\[foo\]", "zab")
> event.set("\[foo\]\[bar\]", 1)
> event.set("\[foo\]\[bar\]", 1.0)
> event.set("\[@metadata\]\[foo\]", "baz")
> \`\`\`
> \- Values can be arrays or hashes or nested
>   
> \`\`\` ruby
> event.set("\[foo\]\[bar\]", \[1, 2, 3\])
> event.set("\[foo\]\[bar\]", {"a" =\> 1, "b" =\> 2})
> event.set("\[foo\]\[bar\]", {"a" =\> 1, "b" =\> 2, "c" =\> \[1, 2\]})
> \`\`\`
> \- When setting hash collections, the hash keys will become fields accessible as fieldref
>   
> \`\`\` ruby
> event.set("\[foo\]\[bar\]", {"a" =\> 1, "b" =\> 2, "c" =\> \[1, 2\]})
>   
> event.get("\[foo\]\[bar\]\[a\]") # =\> 1
> event.get("\[foo\]\[bar\]\[c\]") # =\> \[1, 2\]
> \`\`\`
> \- Mutating a collections after setting it in the Event has an \*\*undefined behaviour\*\*
>   
> \`\`\` ruby
> h = {"a" =\> 1, "b" =\> 2, "c" =\> \[1, 2\]}
> event.set("\[foo\]\[bar\]", h)
>   
> h\["c"\] = \[3, 4\]
> event.get("\[foo\]\[bar\]\[c\]") # =\> ????? but most probably \[1, 2\]
> \`\`\`
>   
> This behaviour is certainly up for discussion, the main idea is that if you want to set or update a value in the event you have to use the explicit setter it cannot be assumed that mutating an object that was set in the event will also update it in the event, like this:
>   
> \`\`\` ruby
> h = {"a" =\> 1, "b" =\> 2, "c" =\> \[1, 2\]}
> event.set("\[foo\]\[bar\]", h)
>   
> h\["c"\] = \[3, 4\]
> event.set("\[foo\]\[bar\]", h)
> # or better
> event.set("\[foo\]\[bar\]\[c\]", \[3, 4\]) 
> \`\`\`
>   
> We say it is \*\*undefined\*\* because it is implementation specific and could change at any time so any observed behaviour is not an API contract. 
> \##### Getter
> 
> \`\`\` ruby
> \# @param fieldref \[String\] field reference string
> \# @return \[Object\] the value at this field reference or nil if none
> event.get(fieldref)
> \`\`\`
> \- Returned values are either string, numeric or timestamp \_scalar\_ values, for example:
>   
> \`\`\` ruby
> event.get("foo" ) # =\> "baz"
> event.get("\[foo\]") # =\> "zab"
> event.get("\[foo\]\[bar\]") # =\> 1
> event.get("\[foo\]\[bar\]") # =\> 1.0
> event.get("\[@metadata\]\[foo\]") # =\> "baz"
> \`\`\`
> \- Returned values can be arrays or hashes or nested
>   
> \`\`\` ruby
> event.get("\[foo\]\[bar\]") # =\> \[1, 2, 3\]
> event.get("\[foo\]\[bar\]") # =\> {"a" =\> 1, "b" =\> 2}
> event.get("\[foo\]\[bar\]") # =\> {"a" =\> 1, "b" =\> 2, "c" =\> \[1, 2\]}
> \`\`\`
> \- Mutating a collections after getting it from the Event has an \*\*undefined behaviour\*\*
>   
> \`\`\` ruby
> h = event.get("\[foo\]\[bar\]") # =\> {"a" =\> 1, "b" =\> 2, "c" =\> \[1, 2\]}
> h\["c"\] = \[3, 4\]
> h = event.get("\[foo\]\[bar\]\[c\]) # =\> ????? but most probably \[1, 2\]
> \`\`\`
>   
> One way to avoid an \*\*undefined behaviour\*\* here would be to always return deep clones of the value at \_fieldref\_. This has obviously a rather high cost and I am unsure if this is a cost worth paying?

So I need to use the following code, then it works:

```
filter
{
        ruby
        {
            code =>
            "
                m = event.get('message').to_s
                puts m
                event.set('added_field', 'hallo'.to_s)
            "
        }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:35am UTC](https://discuss.elastic.co/t/logstash-5-beta-1-ruby-exception-occurred-undefined-method/62376/3 "2017-07-06T04:35:24Z")

</div>


