# Removing item from array based on string value from another field

**URL:** <https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279>\
**Category:** Logstash\
**Created:** [July 9, 2021, 12:24pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279 "2021-07-09T12:24:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mad\_dog](https://avatars.discourse-cdn.com/v4/letter/m/ac91a4/32.png) [@mad\_dog](https://discuss.elastic.co/u/mad_dog)\
**Post date:** [July 9, 2021, 12:24pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279/1 "2021-07-09T12:24:43Z")

</div>

I have a ruby filter that puts all mac addresses (access points and stations macs) in a log to mac\_addresses field and this works fine.  
I also have another grok filter which puts only station mac addresses to station\_mac field.  
I'm trying to remove station\_mac address from mac\_addresses array if it has more than one address and then save result in different field.  
The code below should be working but it doesn't remove station\_mac from array so in result I get new field ap\_macs with the same value as in mac\_addresses.

```auto
ruby {
  code => "
    if event.get('mac_addresses').length > 1
      event.set('ap_macs', event.get('mac_addresses').delete_if { |a| a == event.get('station_mac')})
    end"
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2021, 4:46pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279/2 "2021-07-09T16:46:23Z")

</div>

Are you expecting [mac\_addresses] to be modified? That's not going to happen unless you make a call to event.set with the modified clone.

---

<div class="post-metadata">

**Author:** ![mad\_dog](https://avatars.discourse-cdn.com/v4/letter/m/ac91a4/32.png) [@mad\_dog](https://discuss.elastic.co/u/mad_dog)\
**Post date:** [July 9, 2021, 5:27pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279/3 "2021-07-09T17:27:19Z")

</div>

I was thinking of creating a new field [ap\_macs] but if it's possible to modify [mac\_addresses] then it could be even better. Unfortunatelly I'm not able to get it working either way.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2021, 5:35pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279/4 "2021-07-09T17:35:37Z")

</div>

When I run

```
input { generator { count => 1 lines => [''] } }
filter {
    mutate { add_field => { mac_addresses => ["1", "2", "3"] "station_mac" => "2" } }
    ruby {
        code => '
            if event.get("mac_addresses").length > 1
                event.set("ap_macs", event.get("mac_addresses").delete_if { |a| a == event.get("station_mac")})
            end
        '
    }
}

```

I get

```
"mac_addresses" => [
    [0] "1",
    [1] "2",
    [2] "3"
],
      "ap_macs" => [
    [0] "1",
    [1] "3"
],
  "station_mac" => "2",

```

What exactly does your data look like? Try

```
output { stdout { codec => rubydebug } }
```

---

<div class="post-metadata">

**Author:** ![mad\_dog](https://avatars.discourse-cdn.com/v4/letter/m/ac91a4/32.png) [@mad\_dog](https://discuss.elastic.co/u/mad_dog)\
**Post date:** [July 9, 2021, 6:06pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279/5 "2021-07-09T18:06:05Z")

</div>

This is what I get when I use this filter

```auto
{
           "message" => "syslog: eventd_to_syslog():User[d0:87:e2:07:1d:59] leave WLAN[AVS-Media] at AP[R500 GoldMarvin@2c:c5:d3:3b:3c:80] with Session Time[495.20 sec] RX Bytes[16214] TX Bytes[62483] ",
           "ap_macs" => [
        [0] "d0:87:e2:07:1d:59",
        [1] "2c:c5:d3:3b:3c:80"
    ],
          "severity" => 6,
     "mac_addresses" => [
        [0] "d0:87:e2:07:1d:59",
        [1] "2c:c5:d3:3b:3c:80"
    ],
              "wlan" => "AVS-Media",
          "priority" => 134,
          "facility" => 16,
       "station_mac" => "d0:87:e2:07:1d:59",
    "facility_label" => "local0",
              "tags" => [
        [0] "ruby",
        [1] "logstash-1"
    ],
            "ap_mac" => "2c:c5:d3:3b:3c:80",
              "host" => "10.0.1.101",
        "input_type" => "syslog",
           "ap_name" => [
        [0] "R500 GoldMarvin"
    ],
          "@version" => "1",
    "severity_label" => "Informational",
        "@timestamp" => 2021-07-09T18:02:12.900Z
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2021, 6:14pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279/6 "2021-07-09T18:14:03Z")

</div>

Your ruby code seems OK. There must be something else in the logic of the pipeline ... station\_mac not set when the ruby filter executes, ruby filter in a conditional, or something else.

---

<div class="post-metadata">

**Author:** ![mad\_dog](https://avatars.discourse-cdn.com/v4/letter/m/ac91a4/32.png) [@mad\_dog](https://discuss.elastic.co/u/mad_dog)\
**Post date:** [July 9, 2021, 6:27pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279/7 "2021-07-09T18:27:00Z")

</div>

I can't believe it but you were right. I had my filter for [station\_mac] just below this ruby filter. No comments about that.

Thanks for help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2021, 6:27pm UTC](https://discuss.elastic.co/t/removing-item-from-array-based-on-string-value-from-another-field/278279/8 "2021-08-06T18:27:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
