# Logstash - clone event (ruby code)

**URL:** <https://discuss.elastic.co/t/logstash-clone-event-ruby-code/32816>\
**Category:** Logstash\
**Created:** [October 23, 2015, 2:21am UTC](https://discuss.elastic.co/t/logstash-clone-event-ruby-code/32816 "2015-10-23T02:21:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![etfeet](https://avatars.discourse-cdn.com/v4/letter/e/4da419/32.png) [@etfeet](https://discuss.elastic.co/u/etfeet)\
**Post date:** [October 23, 2015, 2:21am UTC](https://discuss.elastic.co/t/logstash-clone-event-ruby-code/32816/1 "2015-10-23T02:21:15Z")

</div>

I've got some log lines that have a count entry and I would like to clone the event for the value of the count in the log line. I'm using a ruby code to do a for loop for the count #. However, the ruby code is outputting to stdout and no making new events. Any idea how I can use ruby code to make a new event similar to how the clone filter does?

I looked at the clone filter but could not find a way to wrap it in a for loop.

Oct 22 19:07:44 kibana sudo: rory : 3 incorrect password attempts ; TTY=pts/5 ; PWD=/home/rory ; USER=root ; COMMAND=/bin/echo 1234

```
    if [syslog_message] =~ "incorrect password attempts ;" {
            kv {}
            ruby { code => "event['clone_count'] = Integer(event['fail_count']) - 1" }
            mutate { add_tag => ["cloneme"] }
    }

    if "cloneme" in [tags] {
      if "cloned" not in [tags] {
        mutate { add_tag => ["cloned"] }
          ruby {
            code => "
              for i in 0..Integer(event['clone_count'])
                    puts event['message']
              end
            "
          }
      }
    }
```

---

<div class="post-metadata">

**Author:** ![Thorsten\_Nickel](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@Thorsten\_Nickel](https://discuss.elastic.co/u/Thorsten_Nickel)\
**Post date:** [October 27, 2015, 9:17am UTC](https://discuss.elastic.co/t/logstash-clone-event-ruby-code/32816/2 "2015-10-27T09:17:12Z")

</div>

Quite honestly, this looks far too complicated for me, especially since using ruby code should in my view only be the final option. Made a quick dig around, perhaps you should have a look at the 'clone' filter, which is used to duplicate events.  
Maybe this can help you getting your results.

Kind regards,  
Thorsten

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:25am UTC](https://discuss.elastic.co/t/logstash-clone-event-ruby-code/32816/3 "2017-07-06T05:25:18Z")

</div>


