# Ruby code to push whole map to event upon aggregate end\_of\_task

**URL:** <https://discuss.elastic.co/t/ruby-code-to-push-whole-map-to-event-upon-aggregate-end-of-task/228174>\
**Category:** Logstash\
**Created:** [April 15, 2020, 5:04pm UTC](https://discuss.elastic.co/t/ruby-code-to-push-whole-map-to-event-upon-aggregate-end-of-task/228174 "2020-04-15T17:04:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kevin\_branch](https://avatars.discourse-cdn.com/v4/letter/k/d26b3c/32.png) [@kevin\_branch](https://discuss.elastic.co/u/kevin_branch)\
**Post date:** [April 15, 2020, 5:04pm UTC](https://discuss.elastic.co/t/ruby-code-to-push-whole-map-to-event-upon-aggregate-end-of-task/228174/1 "2020-04-15T17:04:10Z")

</div>

I understand with aggregate that **push\_map\_as\_event\_on\_timeout** can be used to push the whole aggregated map to the event when there is a timeout, but that there is nothing like a **push\_map\_as\_event\_on\_end\_of\_task**.

What would be the Ruby code I could use in my closing aggregate section (where end\_of\_task =\>true) that would in one step push the entire map into the event? I have a variable set of map items I'll be aggregating, so enumerating them would be messy. I'm not strong with Ruby and the examples I've dug up so far are not quite getting me there.

Thanks in advance for your advice,  
Kevin

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2020, 5:57pm UTC](https://discuss.elastic.co/t/ruby-code-to-push-whole-map-to-event-upon-aggregate-end-of-task/228174/2 "2020-04-15T17:57:43Z")

</div>

> [@kevin\_branch](#):
>
> I have a variable set of map items I'll be aggregating, so enumerating them would be messy.

I think enumeration is exactly what your need. I haven't tested it, but something like

```
map.each { |k,v|
    event.set(k, v)
}

```

---

<div class="post-metadata">

**Author:** ![kevin\_branch](https://avatars.discourse-cdn.com/v4/letter/k/d26b3c/32.png) [@kevin\_branch](https://discuss.elastic.co/u/kevin_branch)\
**Post date:** [April 15, 2020, 8:17pm UTC](https://discuss.elastic.co/t/ruby-code-to-push-whole-map-to-event-upon-aggregate-end-of-task/228174/3 "2020-04-15T20:17:00Z")

</div>

Thank you so much for weighing in on this, Badger! I believe you nailed it perfectly.

Now in my closing aggregate section in Logstash which does not use a timeout but rather "end\_of\_task =\> true", I have this code line  
code =\> "map.each {|k,v| event.set(k,v)}"

which is successfully carrying over all the aggregated map elements into the event just like \*\*push\_map\_as\_event\_on\_timeout \*\*would do for a timeout-terminated aggregation section.

Again, thanks for your help!

Kevin Branch

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2020, 8:17pm UTC](https://discuss.elastic.co/t/ruby-code-to-push-whole-map-to-event-upon-aggregate-end-of-task/228174/4 "2020-05-13T20:17:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
