# Ruby exception occurred: -1

**URL:** <https://discuss.elastic.co/t/ruby-exception-occurred-1/107148>\
**Category:** Logstash\
**Created:** [November 10, 2017, 7:50am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148 "2017-11-10T07:50:50Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [November 10, 2017, 7:50am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/1 "2017-11-10T07:50:50Z")

</div>

I'm running Elastic stack 5.6.3. Since this version or 5.6.2. I'm getting random LS error:  
`[2017-11-09T07:50:24,829][ERROR][logstash.filters.ruby] Ruby exception occurred: -1`

I've tried to recreate it, but as it looks like it appears at random.

Is there a way to get more a wider error message?  
Has anyone an idea what could cause this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 14, 2017, 8:08pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/2 "2017-11-14T20:08:01Z")

</div>

What does your ruby filter look like?

---

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [November 15, 2017, 6:49am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/3 "2017-11-15T06:49:57Z")

</div>

```auto
ruby {
		code => "
			a = event.get('message').split('|').delete_if{|x| !x.match(/=/)}
			a.each {|y| b = y.split('=', 2)
				event.set(b[0].strip, b[1])
			}
			event.set('acronym', event.get('acronym').upcase)"
	}

```

To explain my ruby code:

- I had problem with `kv` filter not splitting how it should, so I wrote my own splitter.  
This is explained here:  
[How to handle '=' in values, splitting on | but KV takes over all '=' not only the first](https://discuss.elastic.co/t/how-to-handle-in-values-splitting-on-but-kv-takes-over-all-not-only-the-first/97851)
- Also I've had problem with uppercase so I wrote my own upercase in ruby.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 15, 2017, 6:53am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/4 "2017-11-15T06:53:10Z")

</div>

And what does an event that this ruby filter has problems with look like?

---

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [November 15, 2017, 7:02am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/5 "2017-11-15T07:02:09Z")

</div>

I've couldn't pin point it. I'm leaning towards that this happens on random.  
I had created a new index and inserted data from a day that I found in the logs and nothing happened.  
In the temp index I've altered the ruby filter to this:

```auto
ruby {
		code => "
			a = event.get('message').split('|').delete_if{|x| !x.match(/=/)}
			a.each {|y| b = y.split('=', 2)
				event.set(b[0].strip, b[1])
			}
			begin
				event.set('acronym', event.get('acronym').upcase)
			rescue
				event.set('acronym', 'ERROR')
			end"
	}

```

Acronym is in my case a required parameter, so it will allways be there.

Here's an example of my logline:  
`|cir=C2|date=13.11.2017 15:26:00|acronym=MKL|libraryCode=55851|user=someuser|type=11|transactionHostDepartment=45|membIdentificNumb=4200699|patronId=4200699|inventoryNo=90171047239|cobissId=292179456|note=W|patronCategory=006|patronEducation=7|gender=2|busStopId=18|district=023|lastVisitDate=13.11.2017|libraryDept=42|firstsignUpDate=07.03.2016|bibl001c=m|biblUDK675s=82|biblLanguage101a=slv|biblType001b=a|biblTargetAudienceCode100e=m|parentDepartment=45|materialType=01|loanDate=13.11.2017|returnDate=04.12.2017`

Should I run my altered ruby code on my primary index or is there another way to catch this.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 15, 2017, 8:04am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/6 "2017-11-15T08:04:11Z")

</div>

If you get rid of the leading `|`, why not parse this with a [kv filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html#plugins-filters-kv) instead?

```auto
kv {
  field_split => "|"
}

```

---

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [November 15, 2017, 8:25am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/7 "2017-11-15T08:25:18Z")

</div>

Leading `|` was not the problem with kv filter.  
In my second post, there's a link to the topic which explains my problem with kv.  
To sum up:  
The problem was, that my value could contain `=` and kv is not smart enough to just take the first `=` and after that take all for the value part.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 15, 2017, 8:44am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/8 "2017-11-15T08:44:06Z")

</div>

OK, missed that thread.

---

<div class="post-metadata">

**Author:** ![Ramu\_Pedada](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramu_pedada/32/17157_2.png) [@Ramu\_Pedada](https://discuss.elastic.co/u/Ramu_Pedada)\
**Post date:** [November 15, 2017, 10:49am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/9 "2017-11-15T10:49:11Z")

</div>

For the example log you mentioned doesn't the following work

```
kv {
                    source => "message"
                    field_split => "|"
                    value_split => "="
    }
```

---

<div class="post-metadata">

**Author:** ![Mojster](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mojster/32/21209_2.png) [@Mojster](https://discuss.elastic.co/u/Mojster)\
**Post date:** [November 15, 2017, 10:57am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/10 "2017-11-15T10:57:07Z")

</div>

As mentioned above, you cannot split this with kv:  
`cir=C3|date=18.07.2012 09:05:57|acronym=BS|… |firstsignUpDate=30.07.2007|bibl001c=m|biblUDK675s=(038)33=111=163.6|…`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2017, 10:57am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-1/107148/11 "2017-12-13T10:57:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
