# Output writing wrong event data

**URL:** <https://discuss.elastic.co/t/output-writing-wrong-event-data/198002>\
**Category:** Logstash\
**Created:** [September 4, 2019, 8:17am UTC](https://discuss.elastic.co/t/output-writing-wrong-event-data/198002 "2019-09-04T08:17:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pablo\_Gutierrez](https://avatars.discourse-cdn.com/v4/letter/p/7ab992/32.png) [@Pablo\_Gutierrez](https://discuss.elastic.co/u/Pablo_Gutierrez)\
**Post date:** [September 4, 2019, 8:17am UTC](https://discuss.elastic.co/t/output-writing-wrong-event-data/198002/1 "2019-09-04T08:17:56Z")

</div>

Heyy! I'm newbie with Logstash so I need some help here with a filter done in .rb file. Situation:

1. I'm reading from csv file a code, for example 1500.

2. Then, in filter I use a ruby file to look for that 1500 as a key inside a json file. With read data, I set two events that should be written in the output.

3. Most of output lines are right, but sometimes key and read data got mixed between some lines. Looking the log, I saw the problem used to be that one output row has the .json data from the next one. I logged the .rb file searches and all key-value are correctly read from .json file, so the problem should be with the speed it writes the output.

I tried to return read data with return from .rb file, but I couldn't. So I thought maybe I can make the output wait for the event overwritten or something similar, but I prefer to ask for the better practice as I'm learning.

Thank you and regards!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 4, 2019, 1:19pm UTC](https://discuss.elastic.co/t/output-writing-wrong-event-data/198002/2 "2019-09-04T13:19:35Z")

</div>

Are you familiar with the [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter?

What does the code look like? Could you be getting multi-threading issues? Do they go away of you set '--pipeline.workers 1'?

---

<div class="post-metadata">

**Author:** ![Pablo\_Gutierrez](https://avatars.discourse-cdn.com/v4/letter/p/7ab992/32.png) [@Pablo\_Gutierrez](https://discuss.elastic.co/u/Pablo_Gutierrez)\
**Post date:** [September 4, 2019, 1:36pm UTC](https://discuss.elastic.co/t/output-writing-wrong-event-data/198002/3 "2019-09-04T13:36:15Z")

</div>

Thanks for answering!

I just solved it. Problem was saving event.get("key") in a @variable. I directly use now event.get and it works perfectly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2019, 1:36pm UTC](https://discuss.elastic.co/t/output-writing-wrong-event-data/198002/4 "2019-10-02T13:36:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
