# Read actual and previous line using plugin file in Logstash

**URL:** <https://discuss.elastic.co/t/read-actual-and-previous-line-using-plugin-file-in-logstash/259823>\
**Category:** Logstash\
**Created:** [December 29, 2020, 7:56pm UTC](https://discuss.elastic.co/t/read-actual-and-previous-line-using-plugin-file-in-logstash/259823 "2020-12-29T19:56:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dooger21](https://avatars.discourse-cdn.com/v4/letter/d/b4bc9f/32.png) [@dooger21](https://discuss.elastic.co/u/dooger21)\
**Post date:** [December 29, 2020, 7:56pm UTC](https://discuss.elastic.co/t/read-actual-and-previous-line-using-plugin-file-in-logstash/259823/1 "2020-12-29T19:56:53Z")

</div>

Hello everyone,

I need to read a log in tail mode and for each record read in real time to also obtain the previous record. That is, whatever you read the row (11) that has the date 20200607-00:10:00 also get the previous row (10) that has the date 20200607-00:09:00.

The objective of structuring my index like this is to create a visualization that allows me to compare the current value of my COL1 with the previous value (Ex: current 87, previous 7) if both values ​​are greater than 10 that an alert is painted (timeseries annotations - visual builder)

Log:  
 ![Captura](https://us1.discourse-cdn.com/elastic/original/3X/0/0/004d1e0b431b9cf1a43138b58b2f9c8c704332ae.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 29, 2020, 10:59pm UTC](https://discuss.elastic.co/t/read-actual-and-previous-line-using-plugin-file-in-logstash/259823/2 "2020-12-29T22:59:45Z")

</div>

I would do that using a ruby filter:

```
ruby {
    code => '
        @previousMessage ||= ""
        event.set("previousMessage", @previousMessage)
        @previousMessage = event.get("message")
    '
}

```

You must set pipeline.workers to 1 for this to work, and make sure pipeline.ordered has the value you want (true) (or auto in 7.x but not 8.x).

---

<div class="post-metadata">

**Author:** ![dooger21](https://avatars.discourse-cdn.com/v4/letter/d/b4bc9f/32.png) [@dooger21](https://discuss.elastic.co/u/dooger21)\
**Post date:** [December 30, 2020, 4:36pm UTC](https://discuss.elastic.co/t/read-actual-and-previous-line-using-plugin-file-in-logstash/259823/3 "2020-12-30T16:36:31Z")

</div>

It works perfectly. I use the default logstash configuration, do not change any configuration files. Thank you @Badger

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2021, 4:36pm UTC](https://discuss.elastic.co/t/read-actual-and-previous-line-using-plugin-file-in-logstash/259823/4 "2021-01-27T16:36:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
