# Problem with Ruby Filter

**URL:** <https://discuss.elastic.co/t/problem-with-ruby-filter/231408>\
**Category:** Logstash\
**Created:** [May 6, 2020, 8:59pm UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408 "2020-05-06T20:59:13Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![rildo](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@rildo](https://discuss.elastic.co/u/rildo)\
**Post date:** [May 6, 2020, 8:59pm UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408/1 "2020-05-06T20:59:14Z")

</div>

Hello People,

I would like a help with my problem. Currently I have a database with postgresql and I have some queries in logstash to extract some information and send it to elasticsearch.One query return a list of data as a example below:

parser\_result: "{"sgis\_vulnerability": false, "service": "ssh", "timestamp": "2020-05-05 22:41:12", "target\_ips": {"172.0.0.0": {"port": "22"}}, "source\_ip": "200.133.1.1", "other\_logs": "Inicio Ataque:\"2010-05-05 22:41:12\"\nFinal do Ataque:\"2010-05-05 22:41:12\"\nNome e Vers\u00e3o do Cliente:SSH-2.0-libssh-0.6.3\nUsu\u00e1rio:Tom\nPassword:tom", "source\_hostname": "-", "source\_port": "49608", "subject": "Tentativas de acesso n\u00e3o autorizadas a sistemas por for\u00e7a bruta"}"

I have a script in ruby that extract all information that I need, but I don't have know how to change it to work in logstash filter.

# My script in ruby is :

```auto
require 'json'

json_string = "{\"sgis_vulnerability\": false, \"service\": \"ssh\", \"timestamp\": \"2020-05-05 22:41:12\", \"target_ips\": {\"172.0.0.0\": {\"port\": \"22\"}}, \"source_ip\": \"200.133.1.1\", \"other_logs\": \"Inicio Ataque:\\\"2010-05-05 22:41:12\\\"\\nFinal do Ataque:\\\"2010-05-05 22:41:12\\\"\\nNome e Vers\\u00e3o do Cliente:SSH-2.0-libssh-0.6.3\\nUsu\\u00e1rio:Tom\\nPassword:tom\", \"source_hostname\": \"-\", \"source_port\": \"49608\", \"subject\": \"Tentativas de acesso n\\u00e3o autorizadas a sistemas por for\\u00e7a bruta\"}"

json = JSON.parse(json_string)

puts ""
puts "sgis_vulnerability: " + json["sgis_vulnerability"].to_s
puts "service: " + json["service"].to_s
puts ""
puts "timestamp: " + json["timestamp"].to_s
puts ""
...

```

Someone could explain how is possible to get this script and use it in logstash filter ?

Thank you

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 7, 2020, 2:29am UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408/2 "2020-05-07T02:29:48Z")

</div>

any reason why you don’t pass the data to json filter ?

if you insist on ruby then pass the field containing the json string to the code portion inside ruby filter block. something like

`json_string = event.get(json_string)`

then you can set the output value of your script to a field with

`event.set(field_name) = (returned_value)`

I’d go with json filter though. it’s simpler

---

<div class="post-metadata">

**Author:** ![rildo](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@rildo](https://discuss.elastic.co/u/rildo)\
**Post date:** [May 7, 2020, 12:05pm UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408/3 "2020-05-07T12:05:00Z")

</div>

Hello ptamba, First of all , thank you for your support

The reason is that I'm new and I don't know about json filter, I will look for some information to do it with json filter.

If you have any information how is possible to start it with json filter I will appreciate.

Best Regards

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 7, 2020, 12:33pm UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408/4 "2020-05-07T12:33:32Z")

</div>

using your data example i will start with :

```
filter {
  json { 
    source => “parser_result”
  }
}

```

with ruby it will be something like

```
filter { 
  ruby { 
    code => ‘
          require json
          json_string = event.get(“parser_result”)
          json = JSON.parse(json_string)
          (— rest of the code —-) 
         #return the result 
          event.set(”sgis_vulnerability, json[“sgis_vulnerability”].to_s)
         ‘
   }
}
```

---

<div class="post-metadata">

**Author:** ![rildo](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@rildo](https://discuss.elastic.co/u/rildo)\
**Post date:** [May 7, 2020, 1:21pm UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408/5 "2020-05-07T13:21:02Z")

</div>

Amazing ptamba, Thank you

I use filter json and It almost work

The problem is related with the field target\_ips because it is a dictionary and when I use filter json my Elastic exceed the number 1000 fields like this:  
target\_ips.172.0.0.0  
target\_ips.172.0.0.1  
target\_ips.172.0.0.2  
etc

I tried to remove it with the filter mutate  
mutate {  
remove\_field =\> ["[parser\_result][target\_ips]" ]

But it doesn't work because field target\_ips is dynamic , is possible to help me ?

Thank you again

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 7, 2020, 1:36pm UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408/6 "2020-05-07T13:36:14Z")

</div>

you could just remove the target\_ips field if you don’t need it. or use pass it to grok filter if you want to extract information from it.

---

<div class="post-metadata">

**Author:** ![rildo](https://avatars.discourse-cdn.com/v4/letter/r/eb9ed0/32.png) [@rildo](https://discuss.elastic.co/u/rildo)\
**Post date:** [May 7, 2020, 3:23pm UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408/7 "2020-05-07T15:23:40Z")

</div>

> [@ptamba](#):
>
> could just remove the target\_ips field if you don’t need it. or use pass it to grok filter if you want to extract information from it.

Thank you ptamba, I solved the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2020, 3:23pm UTC](https://discuss.elastic.co/t/problem-with-ruby-filter/231408/8 "2020-06-04T15:23:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
