# Returning Multiple Events from Ruby Plugin

**URL:** <https://discuss.elastic.co/t/returning-multiple-events-from-ruby-plugin/227577>\
**Category:** Logstash\
**Created:** [April 11, 2020, 4:45am UTC](https://discuss.elastic.co/t/returning-multiple-events-from-ruby-plugin/227577 "2020-04-11T04:45:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mdt](https://avatars.discourse-cdn.com/v4/letter/m/e9c0ed/32.png) [@mdt](https://discuss.elastic.co/u/mdt)\
**Post date:** [April 11, 2020, 4:45am UTC](https://discuss.elastic.co/t/returning-multiple-events-from-ruby-plugin/227577/1 "2020-04-11T04:45:16Z")

</div>

I need to parse some incoming messages where for network reasons, one event as seen by Logstash is really a concatenation of multiple events. To do that I'm trying to use the ruby plugin, breaking the initial message into pieces, with the idea, at least, of passing those on to the remainder of the pipeline. The syntax is more complicated than the split filter plug-in can handle, but the goal is essentially the same.

The [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html) for the ruby plugin (3.1.5 -- the version I am using) says I need to use new\_event\_block.call(newevent) to create events, however in Logstash 7.6.1, at least, this generates an error:

```auto
Could not process event: undefined local variable or method `new_event_block' for #<LogStash::Filters::Ruby::Script::ExecutionContext:0x47f06865>

```

As an alternative, I tried creating an array containing the events and just returning that, but what happens in practice is that the array just grows and grows, and is never passed to the rest of the pipeline.

What's the best way to do this? Is the documentation simply wrong, or is some additional undocumented setup needed before I can use new\_event\_block?

Thanks!

---

<div class="post-metadata">

**Author:** ![mdt](https://avatars.discourse-cdn.com/v4/letter/m/e9c0ed/32.png) [@mdt](https://discuss.elastic.co/u/mdt)\
**Post date:** [April 18, 2020, 9:48am UTC](https://discuss.elastic.co/t/returning-multiple-events-from-ruby-plugin/227577/2 "2020-04-18T09:48:28Z")

</div>

So just to follow up, I still don't know why the documented new\_event\_block method fails. That looks like a Logstash bug. However I was able to solve the problem by another route, writing a codec that gets passed in to the tcp input plugin instead of using the ruby filter plugin. That seems to work well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2020, 9:48am UTC](https://discuss.elastic.co/t/returning-multiple-events-from-ruby-plugin/227577/3 "2020-05-16T09:48:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
