# Logstash - Trying to assign an existing key to a new key's value

**URL:** <https://discuss.elastic.co/t/logstash-trying-to-assign-an-existing-key-to-a-new-keys-value/241017>\
**Category:** Logstash\
**Created:** [July 13, 2020, 5:48pm UTC](https://discuss.elastic.co/t/logstash-trying-to-assign-an-existing-key-to-a-new-keys-value/241017 "2020-07-13T17:48:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Acomra](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@Acomra](https://discuss.elastic.co/u/Acomra)\
**Post date:** [July 13, 2020, 5:48pm UTC](https://discuss.elastic.co/t/logstash-trying-to-assign-an-existing-key-to-a-new-keys-value/241017/1 "2020-07-13T17:48:38Z")

</div>

Hello,  
I’m pulling aggregated events from Opentsdb and I have a key/value where the key is the epoch event time and value is the agg count.  
Example:

```auto
"dps" => {
    "1594657920" => 12.0
},

```

I’m trying to find a way to break this key/value into two key/value fields, “epoch”: "1594657920" and “count”: 12.0. I’ve been trying but not successful. I’m new to Logstash and Ruby  
Any assistance would be appreciated!

Here’s my config:

```auto
input {
  http_poller {
    urls => {
      OpenTSDB => {
        # Supports all options supported by ruby's Manticore HTTP client
        method => get
        url => "http://some.very.long.url"
        headers => {
          Accept => "application/json"
        }
     }
    }
    request_timeout => 60
    # Supports "cron", "every", "at" and "in" schedules by rufus scheduler
    schedule => { cron => "* * * * * UTC"}
    codec => "json"
    # A hash of request metadata info (timing, response headers, etc.) will be sent here
    metadata_target => "http_poller_metadata"
  }
}
filter {
  ruby {
    code => "
      wanted_fields = ['@timestamp','dps','tags']
        event.to_hash.keys.each { |k|
        event.remove(k) unless wanted_fields.include? k
      }
        event.get('[dps]').each { |key, value|
        event.set('[' + key + ']', value)
      }
    "
  }
  if [tags][response_code] {
    mutate {
      add_field => {
        "response_code" => "%{[tags][response_code]}"
        "SnRC" => "%{[tags][response_code]}/%{[tags][error_reason_code]}"
      }
    }
  }
}
output {
  stdout {
    codec => rubydebug
  }
}

```

Here’s my output so far:

```auto
{
       "@timestamp" => 2020-07-13T16:33:01.105Z,
             "tags" => {
                      "api" => "GET-/what/you/want",
            "response_code" => "200",
            "business_flow" => "NULL",
               "partner_id" => "NULL",
        "error_reason_code" => "NULL",
          "app_instance_id" => "0",
                "component" => "some-api",
                     "host" => "someservername"
    },
    "response_code" => "200",
             "SnRC" => "200/NULL",
              "dps" => {
        "1594657920" => 12.0
    },
} 

```

Thanks in advance

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 13, 2020, 5:55pm UTC](https://discuss.elastic.co/t/logstash-trying-to-assign-an-existing-key-to-a-new-keys-value/241017/2 "2020-07-13T17:55:07Z")

</div>

I ask pretty much same question and got answer here

[https://discuss.elastic.co/t/flatten-json-and-create-dynamic-field/240360/9](https://discuss.elastic.co/t/flatten-json-and-create-dynamic-field/240360/9)

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [July 13, 2020, 6:00pm UTC](https://discuss.elastic.co/t/logstash-trying-to-assign-an-existing-key-to-a-new-keys-value/241017/3 "2020-07-13T18:00:22Z")

</div>

but for you case it is even simple

```
if [dps] {
   ruby {
     code => '
         event.get("[dps]").each { |k,v|
           event.set("epoch", k)
           event.set("count", v)
         }
         event.remove("dps")
   '
   }
}

```

this code says if you have something in field dps  
go throucsh eash key,value pair  
and set epoch = key and count=value  
and remove field dps

---

<div class="post-metadata">

**Author:** ![Acomra](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@Acomra](https://discuss.elastic.co/u/Acomra)\
**Post date:** [July 13, 2020, 6:05pm UTC](https://discuss.elastic.co/t/logstash-trying-to-assign-an-existing-key-to-a-new-keys-value/241017/4 "2020-07-13T18:05:58Z")

</div>

That worked great, thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2020, 6:06pm UTC](https://discuss.elastic.co/t/logstash-trying-to-assign-an-existing-key-to-a-new-keys-value/241017/5 "2020-08-10T18:06:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
