# Match data from two arrays

**URL:** <https://discuss.elastic.co/t/match-data-from-two-arrays/294488>\
**Category:** Logstash\
**Created:** [January 15, 2022, 9:22pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488 "2022-01-15T21:22:07Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [January 15, 2022, 9:22pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/1 "2022-01-15T21:22:07Z")

</div>

Hi  
Can You help me for make a method for merge data between two arrays and match this into one document.

pattern- \> name of fields  
`[a-b-c-d-e]`

//we have a 3 events separated by the `|`  
`value_field = 5-7-10-12-9|5-7-9-14-15|5-7-9-14-15`

eligible output:

```auto
a1 = 5
b1 = 7
c1 = 10
d1 = 12
e1 = 9
a2 = 5
b2 = 7
c2 = 9
d2 = 14
e2 = 15
a3 = 6
b3 = 2
c3 = 2
d3 = 4
e3 = 6

```

I need this data in the same document. So this blocks are separated by '|' pipe shouldn't be splitted between document.  
It could be a trivial case but I'm a fresh with ruby  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 16, 2022, 2:28am UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/2 "2022-01-16T02:28:37Z")

</div>

The following works, but is extremely ugly.

```
    ruby {
        code => '
            f = event.get("value_field")
            if f
                fs = f.split("|")
                fs.each_index{ |x|
                    fss = fs[x].split("-")
                    fss.each_index { |y|
                        event.set("#{(97 + y).chr}#{x+1}", fss[y])
                    }
                }
            end
        '
    }

```

In ASCII a/b/c/d/e are character codes 97/98/99/100/100. Ruby array indices start at zero, so for the first character of the field name we want to convert 97 plus the array index to a character, then we want to convert 1 plus the other index to a string....

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [January 16, 2022, 11:11am UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/3 "2022-01-16T11:11:44Z")

</div>

Thanks @Badger I've found the way

```auto
  ruby {
        code => '
        name = ["a", "b", "c", "d"]
            f = event.get("bearers")
            if f
                fs = f.split("|")
                fs.each_index{ |x|
                    fss = fs[x].split("-")
                    fss.each_index { |y|
					name.each_with_index do |item, index|
                        event.set("#{item}_#{x+1}", fss[y])
					end
                    }
                }
            end
        '
    }

```

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [January 17, 2022, 9:07pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/4 "2022-01-17T21:07:24Z")

</div>

@Badger One more thing, if I will provide in input mixed value for ex. string instead of number,  
this arrays should be hash of array?  
input:  
`value_field = 5-7-10-none-9|5-7-9-disable-15|5-enable-9-14-15`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 17, 2022, 9:32pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/5 "2022-01-17T21:32:43Z")

</div>

> [@INS](#):
>
> One more thing, if I will provide in input mixed value for ex. string instead of number

That should not matter as long as the fields are delimited by -

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [January 17, 2022, 9:59pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/6 "2022-01-17T21:59:05Z")

</div>

So I've done some small exercise:  
decomposes this field but in reverse order, something is not right here, and it does not spit out the string in the value

input :  
`value_field = 5-7-10-none-9|5-7-9-disable-15|5-enable-9-14-15`

code:

```auto
ruby {
        code => '
        name = ["a", "b", "c", "d", "e"]
        
            f = event.get("value_field ")
 
            if f
                fs = f.split("|")
                fs.each_index{ |x|
                    fss = fs[x].split("-")
                    fss.each_index { |y|
                      name.each_with_index do |item, index|
                        event.set("x_#{item}_#{x+1}", fss[y])
					            end
                    }
                }
            end
        '
    }

```

output :

```auto
"x_a_1"	=>	"9",
"x_a_2"	=>	"15"
"x_a_3"	=>	"15",
"x_b_1"	=>	"9",
"x_b_2"	=>	"15",
"x_b_3"	=>	"15",
"x_c_1"	=>	"9",
"x_c_2"	=>	"15",
"x_c_3"	=>	"15",
"x_d_1"	=>	"9",
"x_d_2"	=>	"15",
"x_d_3"	=>	"15",
"x_e_1"	=>	"9",
"x_e_2"	=>	"15",
"x_e_3"	=>	"15",

```

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [January 18, 2022, 1:29pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/7 "2022-01-18T13:29:01Z")

</div>

@Badger How to correctly use `name.each_with_index` for expected output

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [January 18, 2022, 8:27pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/8 "2022-01-18T20:27:05Z")

</div>

@Badger Can You look once again on this case?

also I've tried to do something like this but it's not correct

```auto

event.set("#{name.each { |item| puts item}}_#{x+1}", fss[y])

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 18, 2022, 9:13pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/9 "2022-01-18T21:13:27Z")

</div>

I have no idea what you are asking. You specified a problem, I provided a solution. What issue do you have with the solution?

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [January 18, 2022, 10:34pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/10 "2022-01-18T22:34:11Z")

</div>

Yes Badger I’m very appreciate for take solution but i intended for use array not conversion from char 😉 as workaround

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 18, 2022, 11:23pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/11 "2022-01-18T23:23:13Z")

</div>

Probably

```
name = ["a", "b", "c", "d", "e"]
...
                fss.each_index { |y|
                    event.set("#{name[y]}#{x+1}", fss[y])
                }
```

---

<div class="post-metadata">

**Author:** ![INS](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ins/32/92827_2.png) [@INS](https://discuss.elastic.co/u/INS)\
**Post date:** [January 19, 2022, 9:33pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/12 "2022-01-19T21:33:45Z")

</div>

Thx! well done

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 16, 2022, 9:34pm UTC](https://discuss.elastic.co/t/match-data-from-two-arrays/294488/13 "2022-02-16T21:34:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
