# Logstash Ruby filter error

**URL:** <https://discuss.elastic.co/t/logstash-ruby-filter-error/140375>\
**Category:** Logstash\
**Created:** [July 17, 2018, 6:12pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375 "2018-07-17T18:12:24Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darshan\_Parab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/darshan_parab/32/51098_2.png) [@Darshan\_Parab](https://discuss.elastic.co/u/Darshan_Parab)\
**Post date:** [July 17, 2018, 6:12pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/1 "2018-07-17T18:12:24Z")

</div>

Hi All,

I have written a ruby filter to check if a pattern present in a message and drop the event if pattern is not present.

I'm getting below mentioned error after updating the logstash configuration,

`[2018-07-17T23:27:55,117][ERROR][logstash.filters.ruby] Could not process event: no implicit conversion of LogStash::Event into String {:script_path=>"/etc/logstash/conf.d/extra/scripts/avips.rb", :class=>"TypeError", :backtrace=>["org/jruby/RubyRegexp.java:1107:in`match'", "/etc/logstash/conf.d/extra/scripts/avips.rb:5:in `filter'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-ruby-3.1.4/lib/logstash/filters/ruby/script/context.rb:55:in`execute\_filter'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-ruby-3.1.4/lib/logstash/filters/ruby/script.rb:30:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-ruby-3.1.4/lib/logstash/filters/ruby.rb:98:in`file\_script'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-ruby-3.1.4/lib/logstash/filters/ruby.rb:84:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:145:in`do\_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:164:in `block in multi_filter'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:161:in `multi_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filter_delegator.rb:47:in`multi\_filter'", "(eval):8476:in `block in initialize'", "org/jruby/RubyArray.java:1734:in`each'", "(eval):8473:in `block in initialize'", "(eval):1519:in`block in filter\_func'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:445:in `filter_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:424:in`worker\_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:386:in `block in start_workers'"]}`

Below is the code written in ruby file.  
`  
def register(params)  
end

def filter(event)  
if /^._([sid:\s\d+])._$/.match(event)  
return event  
else  
return nil  
end  
end  
`

Below is the logstash filter code  
`filter { if "av" in [tags] and "test" in [tags] { ruby { path => "/etc/logstash/conf.d/extra/scripts/avips.rb" add_tag => ["ips"] } } }`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 17, 2018, 6:43pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/2 "2018-07-17T18:43:26Z")

</div>

```
if /^.([sid:\s\d+]).$/.match(event.get("message"))
    return [event]
else
    return []
end

```

The add\_tag appears not to work, which feels like a bug to me.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 18, 2018, 1:10am UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/3 "2018-07-18T01:10:04Z")

</div>

I believe your pattern may need a little tweaking: brackets and parens (`[`, `]`, `(`, and `)`) have special meaning and need escaping to match literal characters, so your pattern becomes:

```auto
/^\(\[sid:\s\d+\]\)/

```

* * *

However, what you're looking to do can be achieved in normal Logstash flow control using the [Drop Filter Plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-drop.html):

```auto
filter {
  if [message] !~ /^\(\[sid:\s\d+\]\)/ {
    drop { }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Darshan\_Parab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/darshan_parab/32/51098_2.png) [@Darshan\_Parab](https://discuss.elastic.co/u/Darshan_Parab)\
**Post date:** [July 18, 2018, 4:29am UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/4 "2018-07-18T04:29:57Z")

</div>

Logstash is throwing a ruby exception. That I guess is a reason that add\_tag is not working

---

<div class="post-metadata">

**Author:** ![Darshan\_Parab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/darshan_parab/32/51098_2.png) [@Darshan\_Parab](https://discuss.elastic.co/u/Darshan_Parab)\
**Post date:** [July 18, 2018, 4:33am UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/5 "2018-07-18T04:33:54Z")

</div>

I want to use regex to match a message and then add a tag accordingly. using if statement seems to be solving the problem. However, I'm still not sure, if ruby filter is returning a Logstash::Event object or array, how to convert that to a string so that logstash can process it further.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 18, 2018, 2:17pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/6 "2018-07-18T14:17:21Z")

</div>

> [@Darshan\_Parab](#):
>
> Logstash is throwing a ruby exception. That I guess is a reason that add\_tag is not working

No, sir. Even if you fix the exception it still ignores the add\_tag.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 18, 2018, 3:18pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/7 "2018-07-18T15:18:50Z")

</div>

In general, decoration only occurs in Logstash filter plugins on success, _by design_. It is up to each plugin to respect this, so there may be a few that behave incorrectly, but generally that is the rule.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 18, 2018, 3:23pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/8 "2018-07-18T15:23:01Z")

</div>

> [@Darshan\_Parab](#):
>
> if ruby filter is returning a Logstash::Event object or array, how to convert that to a string so that logstash can process it further.

The `Event` is the base unit in a Logstash pipeline -- it has fields and metadata that are manipulated by the filters and used by the outputs. The Ruby filter should return an array of zero or more `Event`s.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 18, 2018, 3:30pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/9 "2018-07-18T15:30:17Z")

</div>

It does not decorate. Even when it succeeds.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [July 18, 2018, 6:37pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/10 "2018-07-18T18:37:41Z")

</div>

> [@Badger](#):
>
> It does not decorate. Even when it succeeds.

🤔 confirmed:

> <https://github.com/logstash-plugins/logstash-filter-ruby/issues/45>
>
> In the path-based scripting mode, common filter decoration directives (e.g., \`ad…d\_field\`, \`add\_tag\`) are not run on a successful execution of the ruby filter.
> 
> e.g., with the following ruby script:
> \> ~~~
> \> def filter(event)
> \> logger.info("processing event")
> \> \[event\]
> \> end
> \> ~~~
> \> – \`success.logstash-filter.rb\`
> 
> And the following pipeline config:
> \> ~~~
> \> input {
> \> generator { count =\> 1 }
> \> }
> \> filter {
> \> ruby {
> \> path =\> "${PWD}/success.logstash-filter.rb"
> \> add\_field =\> {"ruby" =\> "success"}
> \> }
> \> }
> \> output {
> \> stdout { codec =\> rubydebug }
> \> }
> \> ~~~
> \> – \`pipeline.conf\`
> 
> The event succeeds, but is not decorated:
> 
> \> ~~~
> \> ╭─{ yaauie@castrovel:~/src/elastic/discuss-scratch/140375-ruby-filter-error }
> \> ╰─○ logstash-6.3.0/bin/logstash -f pipeline.conf
> \> Sending Logstash's logs to /Users/yaauie/src/elastic/discuss-scratch/140375-ruby-filter-error/logstash-6.3.0/logs which is now configured via log4j2.properties
> \> \[2018-07-18T18:34:19,521\]\[WARN \]\[logstash.config.source.multilocal\] Ignoring the 'pipelines.yml' file because modules or command line options are specified
> \> \[2018-07-18T18:34:20,093\]\[INFO \]\[logstash.runner \] Starting Logstash {"logstash.version"=\>"6.3.0"}
> \> \[2018-07-18T18:34:22,191\]\[INFO \]\[logstash.filters.ruby.script\] Test run complete {:script\_path=\>"/Users/yaauie/src/elastic/discuss-scratch/140375-ruby-filter-error/success.logstash-filter.rb", :results=\>{:passed=\>0, :failed=\>0, :errored=\>0}}
> \> \[2018-07-18T18:34:23,234\]\[INFO \]\[logstash.pipeline \] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>8, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}
> \> \[2018-07-18T18:34:23,325\]\[INFO \]\[logstash.pipeline \] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x739da9e8 run\>"}
> \> \[2018-07-18T18:34:23,414\]\[INFO \]\[logstash.agent \] Pipelines running {:count=\>1, :running\_pipelines=\>\[:main\], :non\_running\_pipelines=\>\[\]}
> \> \[2018-07-18T18:34:23,527\]\[INFO \]\[logstash.filters.ruby.script.context\] processing event
> \> \[2018-07-18T18:34:23,898\]\[INFO \]\[logstash.agent \] Successfully started Logstash API endpoint {:port=\>9600}
> \> {
> \> "@version" =\> "1",
> \> "message" =\> "Hello world!",
> \> "@timestamp" =\> 2018-07-18T18:34:23.363Z,
> \> "host" =\> "castrovel.local",
> \> "sequence" =\> 0
> \> }
> \> \[2018-07-18T18:34:23,948\]\[INFO \]\[logstash.pipeline \] Pipeline has terminated {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x739da9e8 run\>"}
> \> logstash-6.3.0/bin/logstash -f pipeline.conf 78.29s user 2.42s system 384% cpu 20.964 total
> \> \[success (21.000s)\]
> \> ~~~

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2018, 6:40pm UTC](https://discuss.elastic.co/t/logstash-ruby-filter-error/140375/11 "2018-08-15T18:40:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
