# Logstash require 'sqlite3'

**URL:** <https://discuss.elastic.co/t/logstash-require-sqlite3/163309>\
**Category:** Logstash\
**Created:** [January 8, 2019, 7:11am UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309 "2019-01-08T07:11:20Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![pohsun.teh](https://avatars.discourse-cdn.com/v4/letter/p/f08c70/32.png) [@pohsun.teh](https://discuss.elastic.co/u/pohsun.teh)\
**Post date:** [January 8, 2019, 7:11am UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/1 "2019-01-08T07:11:20Z")

</div>

When I run my logstash, error shown

> no such file to load -- sqlite3

Is it because sqlite3 is not pre-installed with Logstash?  
Is it possible to install sqlite3 for logstash?

> gem install sqlite3

Reason being is that, I am required to access sqlite3 DB for some checking on certain fields.

Alternatively, I tried require 'sqlite3' at ruby init

```
ruby {
    init => "require 'sqlite3'"
    path => "./script.rb"
}

```

And it throw error message

> Could not process event: uninitialized constant #Class:0x35324446::SQLite3

Thanks in advance.  
Regards.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [January 8, 2019, 8:18am UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/2 "2019-01-08T08:18:37Z")

</div>

Hi @pohsun.teh,

you might need this guy -\> [Sqlite input plugin](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-sqlite.html)

More info -\> [Working with plugins](https://www.elastic.co/guide/en/logstash/current/working-with-plugins.html)

---

<div class="post-metadata">

**Author:** ![pohsun.teh](https://avatars.discourse-cdn.com/v4/letter/p/f08c70/32.png) [@pohsun.teh](https://discuss.elastic.co/u/pohsun.teh)\
**Post date:** [January 8, 2019, 1:26pm UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/3 "2019-01-08T13:26:33Z")

</div>

Hi, thanks for your reply.  
I have the plugin installed, but from the example, isn't the plugin is for INPUT?

What I am trying to achieve is accessing sqlite on ruby script on FILTER part

Regards.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [January 8, 2019, 1:36pm UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/4 "2019-01-08T13:36:54Z")

</div>

Could you describe a bit more what exactly you expect to happen?  
What is the source data?  
What do you want to do in the filter section?  
What is the output?

---

<div class="post-metadata">

**Author:** ![pohsun.teh](https://avatars.discourse-cdn.com/v4/letter/p/f08c70/32.png) [@pohsun.teh](https://discuss.elastic.co/u/pohsun.teh)\
**Post date:** [January 8, 2019, 2:35pm UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/5 "2019-01-08T14:35:29Z")

</div>

I'm sorry if I'm not clear before.

To start, it would be normal input from json file.

Next at filter, I have ruby script to manipulate the data from input to only select fields I want

At the ruby script, I need to access sqlite to check on source and destination IP (I have a map of IP to name). Once I get the name, new field will be added before inserting to Elasticsearch

So, the problem I'm having now is accessing sqlite at ruby script.

Thanks.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [January 8, 2019, 2:49pm UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/6 "2019-01-08T14:49:38Z")

</div>

I'm on very weak ice here so this is pure speculation. I don't know much Ruby...

I do not think Logstash needs to load the `sqlite3` gem, so I would remove the `init` specification. I imagine the `require 'sqlite3'` goes in the .rb script.  
I would also use a fully qualified path to the .rb script as I am not entirely sure what Logstash sees at the working path.

Without seeing the Ruby script it is hard (at least for me) to say anything more than that.

---

<div class="post-metadata">

**Author:** ![pohsun.teh](https://avatars.discourse-cdn.com/v4/letter/p/f08c70/32.png) [@pohsun.teh](https://discuss.elastic.co/u/pohsun.teh)\
**Post date:** [January 8, 2019, 3:17pm UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/7 "2019-01-08T15:17:19Z")

</div>

Well, I did try with require 'sqlite3' at .rb file. But it gives error.  
On top of that, I wouldn't want my script to require sqlite at every event. So, that is the reason I require it at `init`

Thanks for your insight. Couldn't find anywhere regarding this matter. Only thing Logstash have with sqlite3 is the input plugin.

---

<div class="post-metadata">

**Author:** ![A\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/a_b/32/17104_2.png) [@A\_B](https://discuss.elastic.co/u/A_B)\
**Post date:** [January 8, 2019, 3:29pm UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/8 "2019-01-08T15:29:07Z")

</div>

Got curious and found [this](https://github.com/elastic/logstash/issues/7016) on how to possibly add gem to Logstash.

---

<div class="post-metadata">

**Author:** ![pohsun.teh](https://avatars.discourse-cdn.com/v4/letter/p/f08c70/32.png) [@pohsun.teh](https://discuss.elastic.co/u/pohsun.teh)\
**Post date:** [January 8, 2019, 10:38pm UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/9 "2019-01-08T22:38:45Z")

</div>

Well, that's new.  
From the looks of it, seems Logstash doesn't have easier way for gem install.

Thanks a lot for the link. Might give it a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2019, 10:38pm UTC](https://discuss.elastic.co/t/logstash-require-sqlite3/163309/10 "2019-02-05T22:38:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
