# Logstash ruby filter

**URL:** <https://discuss.elastic.co/t/logstash-ruby-filter/324590>\
**Category:** Logstash\
**Created:** [February 3, 2023, 2:20am UTC](https://discuss.elastic.co/t/logstash-ruby-filter/324590 "2023-02-03T02:20:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sheetal3](https://avatars.discourse-cdn.com/v4/letter/s/f08c70/32.png) [@sheetal3](https://discuss.elastic.co/u/sheetal3)\
**Post date:** [February 3, 2023, 2:20am UTC](https://discuss.elastic.co/t/logstash-ruby-filter/324590/1 "2023-02-03T02:20:15Z")

</div>

Getting Error:  
[2023-02-02T19:25:48,535][ERROR][logstash.filters.ruby][main][b7126651d97050c2a450765cb1ad946624dc0b4a1ea72baecc762eb17b892bdd] Ruby exception occurred: undefined method `each' for #<String:0xa01d55c> {:class=>"NoMethodError", :backtrace=>["(ruby filter code):5:in `block in filter\_method'", "/opt/logstash/logstash-7.16.2/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.7/lib/logstash/filters/ruby.rb:93:in `inline_script'", "/opt/logstash/logstash-7.16.2/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.7/lib/logstash/filters/ruby.rb:86:in `filter'", "/opt/logstash/logstash-7.16.2/logstash-core/lib/logstash/filters/base.rb:159:in `do_filter'", "/opt/logstash/logstash-7.16.2/logstash-core/lib/logstash/filters/base.rb:178:in `block in multi\_filter'", "org/jruby/RubyArray.java:1821:in `each'", "/opt/logstash/logstash-7.16.2/logstash-core/lib/logstash/filters/base.rb:175:in `multi\_filter'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:134:in `multi_filter'", "/opt/logstash/logstash-7.16.2/logstash-core/lib/logstash/java_pipeline.rb:299:in `block in start\_workers'"]}

sample JSONMessage:  
2023-02-02T16:21:34.352-06:00 [INFO] {"APP\_LOGS":{"Header":{"ApplicationID":"ABC","ServiceName":"INFO","ComponentName":"EventingLog.process","Hostname":"hostname123","Timestamp":"2023-02-02T22:21:34.352Z","TransactionDomain":"ABC","TransactionType":"Eventing","TransactionID":"Customer::123\_456","BusinessID":"Customer::123\_456","ApplicationDomain":"SyncUp","BusinessID2":"NA"},"Category":"Eventing","Status":"InfoLog","TransactionBefore":"Customer Doc created/updated in Target Bucket. Additional Channels retained from existing Customer target Doc. ,Tax attrbt updated from source TaxRateDoc to target Customer document with ID: Customer::123\_456","TransactionAfter":"Issue is creating eventing process","LogLevel":"1"}}

Code:  
filter {  
grok {  
tag\_on\_failure =\> ["\_notAPP"]  
match =\> ["message", "%{TIMESTAMP\_ISO8601:logTimestamp} %{SYSLOG5424SD:logLevel} %{GREEDYDATA:logJSONMessage}"]  
}  
json {  
tag\_on\_failure =\> ["\_notAPP"]  
source =\> "logJSONMessage"  
target =\> "jsonMessage"  
}  
ruby {  
tag\_on\_exception =\> "\_notAPP"  
code =\> '  
jsonObj = event.get("jsonMessage")  
return if jsonObj.nil?  
jsonObj.each { |k, v|  
event.set("logType",k)  
event.set("logMessage",v)  
event.set("elkMessage",event.get("logType")=="APP\_LOGS"?v["TransactionBefore"]:v["TransactionData"])  
event.set("afterTransaction", event.get("logType")=="APP\_LOGS"?v["TransactionAfter"]:v["DumpAnalysis"])  
event.set("transactionId", v["Header"]["TransactionID"])  
}  
event.remove("doc")  
'  
}  
uuid {  
target =\> "uuid"  
}  
mutate {  
add\_field =\> {  
"[key][id]" =\> "%{uuid}"  
"[key][application]" =\> "ABC"  
"[key][table]" =\> ""  
}  
}  
mutate {  
rename =\> { "[logJSONMessage]" =\> "[@metadata][logJSONMessage]" }  
rename =\> { "[logMessage]" =\> "[@metadata][logMessage]" }  
rename =\> { "[logLevel]" =\> "[@metadata][logLevel]" }  
rename =\> { "[logTimestamp]" =\> "[@metadata][logTimestamp]" }  
rename =\> { "[jsonMessage]" =\> "[@metadata][jsonMessage]" }  
rename =\> { "[logType]" =\> "[@metadata][logType]" }  
rename =\> { "[host]" =\> "[@metadata][host]" }  
rename =\> { "[message]" =\> "[@metadata][message]" }  
rename =\> { "[key]" =\> "[@metadata][key]" }  
rename =\> { "[type]" =\> "[@metadata][type]"}  
add\_field =\> {"message" =\> "%{transactionId}-%{elkMessage}-%{afterTransaction}"}  
remove\_field =\> ["uuid" , "transactionId" ,"elkMessage" ,"afterTransaction"]  
}  
if "\_notAPP" in [tags] {  
mutate {  
remove\_tag =\> ["\_notAPP"]  
replace =\> { "message" =\> "%{[@metadata][message]}"}  
}  
}  
}

Can someone please help on what is wrong here ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2023, 2:21am UTC](https://discuss.elastic.co/t/logstash-ruby-filter/324590/2 "2023-03-03T02:21:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
