# Reading environment variables set with exec plugin

**URL:** <https://discuss.elastic.co/t/reading-environment-variables-set-with-exec-plugin/259189>\
**Category:** Logstash\
**Created:** [December 20, 2020, 7:16am UTC](https://discuss.elastic.co/t/reading-environment-variables-set-with-exec-plugin/259189 "2020-12-20T07:16:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lukasz\_Geras](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukasz_geras/32/81151_2.png) [@Lukasz\_Geras](https://discuss.elastic.co/u/Lukasz_Geras)\
**Post date:** [December 20, 2020, 7:16am UTC](https://discuss.elastic.co/t/reading-environment-variables-set-with-exec-plugin/259189/1 "2020-12-20T07:16:51Z")

</div>

Hello, could you please help me with reading environment variables set with exec plugin in logstash. Generally, my input looks like this:

```auto
input{   
    exec{
       command=>
       „export FILENAME=$(ls -Arst /path/to/file | tail -n 1);
       unzip -p /path/to/file/$(ls -Arst /path/to/file | tail -n 1) folder\\\\file.json;
       zip -d /path/to/file/$(ls -Arst /path/to/file | tail -n 1) folder\\\\file.json > /dev/null 2>/dev/null;”
       Interval => 60
   }
    codec => json{charset => utf-16}
}

```

And thus, i unzip the json and print it to message. Since I can’t add anything to the output, not to spoil the json parsing, I would like to save the filename to environment variable and read it during the filtering.

I tried reading the variable few ways:

`mutate{ add_field => { „my_field” => „${FILENAME}} }`  
or

` ruby{ code => „str = ENV[‚FILENAME’]; event.set(„filename”,str.flatten)”}`

But it returns the error, telling me that it couldn’t find the environment variable set.  
Did any of You succeed in implementing such operation? I’d be grateful if anyone could help me in making such a parser.

I made few working parsers that adds the filename at the beggining of the output, but in that case, json input doesn’t work and i need to split the whole message with regex. It would be more elegant to do this in envvar.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 20, 2020, 4:01pm UTC](https://discuss.elastic.co/t/reading-environment-variables-set-with-exec-plugin/259189/2 "2020-12-20T16:01:33Z")

</div>

> [@Lukasz\_Geras](#):
>
> Did any of You succeed in implementing such operation?

No. The exec input creates a new process. Any environment variables set in that process will be available to that process. If you export them they will also be available to its child processes. They will never be available to the parent that did the exec.

---

<div class="post-metadata">

**Author:** ![Lukasz\_Geras](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukasz_geras/32/81151_2.png) [@Lukasz\_Geras](https://discuss.elastic.co/u/Lukasz_Geras)\
**Post date:** [December 20, 2020, 11:17pm UTC](https://discuss.elastic.co/t/reading-environment-variables-set-with-exec-plugin/259189/3 "2020-12-20T23:17:10Z")

</div>

Thank you for info. That's a pity that it's impossible.  
In my case the only solution was to do it entirely in filter{} section like this:

```auto
ruby{
    code => "str = `$(ls -Arst /path/to/file | tail -n 1)`
        event.set('field', str)"
}

```

So, it would work well, provided that none of the files changed during execution of the script. If the server is not very busy it may serve well.

Thanks a lot Badger!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 20, 2020, 11:31pm UTC](https://discuss.elastic.co/t/reading-environment-variables-set-with-exec-plugin/259189/4 "2020-12-20T23:31:41Z")

</div>

Forking a process just to be able to run ls is really expensive. You might want to consider using [File::Stat](https://ruby-doc.org/core-2.5.0/File/Stat.html) in the ruby filter instead, which would be far cheaper.

---

<div class="post-metadata">

**Author:** ![Lukasz\_Geras](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukasz_geras/32/81151_2.png) [@Lukasz\_Geras](https://discuss.elastic.co/u/Lukasz_Geras)\
**Post date:** [December 21, 2020, 5:56am UTC](https://discuss.elastic.co/t/reading-environment-variables-set-with-exec-plugin/259189/5 "2020-12-21T05:56:59Z")

</div>

Thanks for the suggestion again. This is not a big system, I use it to gather forensic artifacts from certain hosts in my network, but building something bigger I will definitely test it!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2021, 5:57am UTC](https://discuss.elastic.co/t/reading-environment-variables-set-with-exec-plugin/259189/6 "2021-01-18T05:57:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
