# Logstash count events using ruby filter

**URL:** <https://discuss.elastic.co/t/logstash-count-events-using-ruby-filter/300256>\
**Category:** Logstash\
**Created:** [March 22, 2022, 12:22am UTC](https://discuss.elastic.co/t/logstash-count-events-using-ruby-filter/300256 "2022-03-22T00:22:24Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 22, 2022, 3:20am UTC](https://discuss.elastic.co/t/logstash-count-events-using-ruby-filter/300256/4 "2022-03-22T03:20:35Z")

</div>

> [@gnam](#):
>
> Is there any difference between with-in filter (or) separate file?

A script file returns an array of events (1 or 2 in this case), so that is an easy way to create a second event.

You may be able to use a new\_event\_block as described in the [code option](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-code) of an aggregate filter but I have not tested it. I do not know if that is specific to aggregate or whether you can use it a ruby filter. @Jenni's post [here](https://discuss.elastic.co/t/unable-to-create-new-document-event-in-logstash-ruby-filter-using-yield/236995/2) suggests it _can_ be used in a ruby filter.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-count-events-using-ruby-filter/300256)._
