# Push\_previous\_map\_as\_event into fields

**URL:** <https://discuss.elastic.co/t/push-previous-map-as-event-into-fields/239310>\
**Category:** Logstash\
**Created:** [June 30, 2020, 1:10pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-into-fields/239310 "2020-06-30T13:10:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [June 30, 2020, 1:10pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-into-fields/239310/1 "2020-06-30T13:10:51Z")

</div>

Hi,

I'm trying to use push\_previous\_map\_as\_event to aggregate and save everything as key/value fields in a document.

My data looks like this:

device: router1  
property: mem\_prop1 ( there are twelve properties per component-name for a device)  
component-name: FPC1:CPU1  
value: 1  
sequence: 1000 (this appears to be unique per device and component-name)

device: router2  
property: mem\_prop2  
component-name: FPC2:CPU2  
value: 2  
sequence: 2000

This is my aggregate filter which is storing the property-name and value inside an array:

```auto
     if [component-name] and [property-name] and [property-value] {
            aggregate {
                task_id => "%{device}-%{sequence}-%{component-name}"
                timeout_task_id_field => "task_id"
                timeout_timestamp_field => "@timestamp"
                code => "
                    map['sequence'] ||= event.get('sequence')
                    map['device'] ||= event.get('device')
                    map['component-name'] ||= event.get('component-name')
                    map['properties'] ||= []
                    map['properties'] << {event.get('property-name') => event.get('property-value')}
                "
                push_map_as_event_on_timeout => true
                push_previous_map_as_event => true
                timeout => 60
            }
        }
        else {
            drop {}
        }

```

My output looks like this:

```auto
    "properties": [
          {
            "mem-util-packet-dma-utilization": 9
          },
          {
            "mem-util-kernel-flow-table-allocations-failed": 0
          },
          {
            "mem-util-kernel-toe-pkt-transfer-allocations-failed": 0
          },
          {
            "mem-util-kernel-cos-allocations-failed": 0
          },
          {
            "mem-util-kernel-filter-allocations-failed": 0
          },
          {
            "mem-util-kernel-rtt-allocations-failed": 0
          },
          {
            "mem-util-kernel-rt-allocations-failed": 0
          },
          {
            "mem-util-kernel-iff-allocations-failed": 0
          },
          {
            "mem-util-kernel-ifl-allocations-failed": 0
          },
          {
            "mem-util-kernel-size": 3221225472
          },
          {
            "mem-util-kernel-utilization": 26
          },
          {
            "mem-util-kernel-bytes-allocated": 860475368
          }
        ]

```

I'd like to flatten properties out so that all of the property-names and values get saved as key/value fields in the aggregated document. How do I do that?

Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 30, 2020, 4:13pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-into-fields/239310/2 "2020-06-30T16:13:40Z")

</div>

> [@mohsin106](#):
>
> ```auto
> map['properties'] ||= []
> map['properties'] << {event.get('property-name') => event.get('property-value')}
> 
> ```

Replace that with

```
map['properties'] ||= {}
map['properties'][event.get('property-name')] = event.get('property-value')

```

or even

```
map[event.get('property-name')] = event.get('property-value')

```

BTW are you sure you want both of these?...

```
            push_map_as_event_on_timeout => true
            push_previous_map_as_event => true

```

---

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [June 30, 2020, 6:23pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-into-fields/239310/3 "2020-06-30T18:23:26Z")

</div>

@Badger  
Thank you. Your suggestion worked. As for your question, I'm now using only

> push\_previous\_map\_as\_event =\> true

Do I need to set a timeout (timeout =\> 60) when using push\_previous\_map\_as\_event?

I configured my aggregate filter like this (without timeout) and it's working.

> aggregate {  
> task\_id =\> "%{device}-%{sequence}-%{component-name}"  
> timeout\_task\_id\_field =\> "task\_id"  
> timeout\_timestamp\_field =\> "@timestamp"  
> code =\> "  
> map['sequence'] ||= event.get('sequence')  
> map['device'] ||= event.get('device')  
> map['component-name'] ||= event.get('component-name')  
> map['properties'] ||= {}  
> map[event.get('property-name')] = event.get('property-value')  
> "  
> push\_previous\_map\_as\_event =\> true  
> }

I also have another question about the "code =\>" syntax. Is that all pure Ruby code between the double quotes or is it some sort of trimmed down version of it? I haven't learned Ruby yet but are there any references that I can read up on that would show me how to utilize Ruby with Elastic Search? I know there is an Event API in ES that we can utilize to get and set events, but just needed more reading material on how we use map['...'] to dynamically create fields and assign values to them. Thank you!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 30, 2020, 6:38pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-into-fields/239310/4 "2020-06-30T18:38:26Z")

</div>

You do not need to set timeout if using push\_previous\_map\_as\_event

Yes, it is pure Ruby code in the code option of a ruby filter. I cannot think of a reference to suggest.

---

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [June 30, 2020, 6:41pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-into-fields/239310/5 "2020-06-30T18:41:49Z")

</div>

Got it. Thanks again for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2020, 6:41pm UTC](https://discuss.elastic.co/t/push-previous-map-as-event-into-fields/239310/6 "2020-07-28T18:41:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
