# Logstash Filter with wrong result for deal with lots event at the same time

**URL:** <https://discuss.elastic.co/t/logstash-filter-with-wrong-result-for-deal-with-lots-event-at-the-same-time/231113>\
**Category:** Logstash\
**Created:** [May 5, 2020, 9:36am UTC](https://discuss.elastic.co/t/logstash-filter-with-wrong-result-for-deal-with-lots-event-at-the-same-time/231113 "2020-05-05T09:36:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stanwang](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@stanwang](https://discuss.elastic.co/u/stanwang)\
**Post date:** [May 5, 2020, 9:36am UTC](https://discuss.elastic.co/t/logstash-filter-with-wrong-result-for-deal-with-lots-event-at-the-same-time/231113/1 "2020-05-05T09:36:02Z")

</div>

Hi,

I use Winlogbeat to transmit Windows Event Log. My Logstash Filter use for parsing the "message" in the Json.  
The message content will like this, "RuleName: technique\_id=T1047,technique\_name=Windows Management Instrumentation." And, my purpose is splitting the message into three part, "RuleName, Technique\_id and Technique\_name." Here is my code. I write the filter in Ruby.

```auto
filter {
  ruby {
    code => '
      # Initialize
      rulename_input = " "
      technique_id = " "
      technique_name = " "

      array = event.get("[message]").split("\n")
      Message = array[1]
      RuleName = Message.split(": ")

      if RuleName[1] == " " or RuleName[1] == nil
        rulename_input = " "
        technique_id = " "
        technique_name = " "
      else 
        rulename_input = RuleName[1]
        tech = RuleName[1].split(",")

        tec = tech[0].split("=")
        technique_id = tec[1]

        tec = tech[1].split("=")
        technique_name = tec[1]
      end

      event.set("RuleName",rulename_input)
      event.set("Technique_id",technique_id)
      event.set("Technique_name",technique_name)
    '
  }
}

```

The filter result is usually correct in most situation. Below is correct picture by Kibana.

 ![correct](https://us1.discourse-cdn.com/elastic/original/3X/5/5/55123229f87f0c70a77ce4b1f7a49a2bb5a1aeac.png)

But, if there are lots of event log send from Winlogbeat at the same time, it will be wrong. The wrong result as below:

 ![wrong](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d8e072f8b67767542f6894b235ca7d7c60f1b27f.png)  
 ![wrong2](https://us1.discourse-cdn.com/elastic/original/3X/0/6/060c4bc966d68fe97b3ca389cd00e947eb932dde.png)

How do I fix it?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 5, 2020, 3:48pm UTC](https://discuss.elastic.co/t/logstash-filter-with-wrong-result-for-deal-with-lots-event-at-the-same-time/231113/2 "2020-05-05T15:48:06Z")

</div>

> [@stanwang](#):
>
> How do I fix it?

In ruby, any "variable" that starts with a capital letter is a constant. I am not going to explain the scope of constants in ruby, but suffice to say that if you configure

```
input { generator { count => 1 lines => ['first', 'second'] } }
filter {
    ruby {
        code => '
            if event.get("message") =="first"
                Constant = "Foo"
            end
            event.set("someField", Constant)
        '
    }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

then you get

```
{
   "message" => "first",
  "@version" => "1",
"@timestamp" => 2020-05-05T15:44:14.523Z,
  "sequence" => 0,
 "someField" => "Foo"
}
{
   "message" => "second",
  "@version" => "1",
"@timestamp" => 2020-05-05T15:44:14.536Z,
  "sequence" => 0,
 "someField" => "Foo"
}

```

whereas if you configure

```
input { generator { count => 1 lines => ['first', 'second'] } }
filter {
    ruby {
        code => '
            if event.get("message") =="first"
                constant = "Foo"
            end
            event.set("someField", constant)
        '
    }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

then you get

```
{
   "message" => "first",
  "@version" => "1",
"@timestamp" => 2020-05-05T15:43:59.981Z,
  "sequence" => 0,
 "someField" => "Foo"
}
{
   "message" => "second",
  "@version" => "1",
"@timestamp" => 2020-05-05T15:44:00.114Z,
  "sequence" => 0,
 "someField" => nil
}

```

so rename "Message" and "RuleName" as "message" and "ruleName".

---

<div class="post-metadata">

**Author:** ![stanwang](https://avatars.discourse-cdn.com/v4/letter/s/6f9a4e/32.png) [@stanwang](https://discuss.elastic.co/u/stanwang)\
**Post date:** [May 7, 2020, 2:42am UTC](https://discuss.elastic.co/t/logstash-filter-with-wrong-result-for-deal-with-lots-event-at-the-same-time/231113/3 "2020-05-07T02:42:11Z")

</div>

Thank you for your help , and now it works correctly! Thank you so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2020, 2:42am UTC](https://discuss.elastic.co/t/logstash-filter-with-wrong-result-for-deal-with-lots-event-at-the-same-time/231113/4 "2020-06-04T02:42:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
