# Logstash Persistent Variables

**URL:** <https://discuss.elastic.co/t/logstash-persistent-variables/194853>\
**Category:** Logstash\
**Created:** [August 12, 2019, 1:33pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853 "2019-08-12T13:33:54Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![sho1](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@sho1](https://discuss.elastic.co/u/sho1)\
**Post date:** [August 12, 2019, 1:33pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/1 "2019-08-12T13:33:54Z")

</div>

I wanted to create a persistent boolean that I can change whenever a certain message appears. Based on this boolean I would change my output{ elastic search{ index file reference}}.  
E.g.  
log GET  
log dog  
Log PUT  
log 1234  
The boolean should be set to true when it sees a 'log GET', and parses the 'log dog' with index config 1. When I receive 'log PUT', the boolean should be set to false and parse the 'log 1234' with index config 2. I would really appreciate any help on this issue! Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 3:12pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/2 "2019-08-12T15:12:28Z")

</div>

You can use a ruby filter as described [here](https://discuss.elastic.co/t/method-to-timestamp-my-logstash-events/135888/9). It requires '--pipeline.workers 1' and pipeline.java\_execution has to be false until [this](https://github.com/elastic/logstash/issues/10938) bug is fixed.

---

<div class="post-metadata">

**Author:** ![sho1](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@sho1](https://discuss.elastic.co/u/sho1)\
**Post date:** [August 12, 2019, 3:38pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/3 "2019-08-12T15:38:14Z")

</div>

Do you know how to declare a boolean, and if you use the ruby filter or not? Sorry, I am very new to Ruby...

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 3:43pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/4 "2019-08-12T15:43:41Z")

</div>

Something like this

```
    ruby {
        init => '@b = false'
        code => '
            m = event.get("message")
            if m and m =~ /log get/i
                @b = true
            end
            if m and m =~ /log put/i
                @b = false
            end
            event.set("someField", @b)
        '
    }

```

will add a field [someField] which will be a boolean.

---

<div class="post-metadata">

**Author:** ![sho1](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@sho1](https://discuss.elastic.co/u/sho1)\
**Post date:** [August 12, 2019, 4:07pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/5 "2019-08-12T16:07:24Z")

</div>

Thanks so much for that. My issue is that how do I reference that field after I receive the next log. So when I get 'log dog' how do I reference the someField event from the preceding log. (In this case, 'log get' ALWAYS precedes 'log dog'. Once again, thanks a log

When I reference in output:  
if event.get("someField") == 'true' I receive an error

edit: added example error

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 4:26pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/6 "2019-08-12T16:26:38Z")

</div>

```
if [someField] {
...
}
```

---

<div class="post-metadata">

**Author:** ![sho1](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@sho1](https://discuss.elastic.co/u/sho1)\
**Post date:** [August 12, 2019, 4:54pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/7 "2019-08-12T16:54:51Z")

</div>

Ok it is almost working. When I do  
mutate{  
add\_field =\> {"someField" =\> "event.get("someField")"}  
}  
I am getting an issue. How do I set someField = to the event.get(someField) rather than the string "event.get(someField)"? Thanks so much badger!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 5:28pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/8 "2019-08-12T17:28:48Z")

</div>

The [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-add_field) includes examples of sprintf references in add\_field.

---

<div class="post-metadata">

**Author:** ![sho1](https://avatars.discourse-cdn.com/v4/letter/s/7cd45c/32.png) [@sho1](https://discuss.elastic.co/u/sho1)\
**Post date:** [August 12, 2019, 5:43pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/9 "2019-08-12T17:43:11Z")

</div>

Yeah I took a look at that, however it was still not working even when I did  
"%{event.get(someField)}".  
I believe the reason for this is because perhaps the event.set("someField") is NOT persistent? And it is not able to see the last update to @put.  
E.g.  
log GET  
@b is set to false  
event.set(someField)  
log dog  
(I do not set any boolean value, I want to reference whatever value the boolean was last)

If you can help me solve this I will love you forever lmao

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 6:07pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/10 "2019-08-12T18:07:16Z")

</div>

event.set and event.get only work in ruby filters. In the rest of the logstash configuration you would reference a field as [someField], and in a sprintf reference as %{[someField]}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2019, 6:07pm UTC](https://discuss.elastic.co/t/logstash-persistent-variables/194853/11 "2019-09-09T18:07:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
