# Ruby exception occurred: undefined method \`\[\]' for #\<LogStash::Event:0x1f8ee438

**URL:** <https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521>\
**Category:** Logstash\
**Created:** [April 17, 2020, 1:18pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521 "2020-04-17T13:18:22Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jaikumar\_Ganesan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaikumar_ganesan/32/66507_2.png) [@Jaikumar\_Ganesan](https://discuss.elastic.co/u/Jaikumar_Ganesan)\
**Post date:** [April 17, 2020, 1:18pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521/1 "2020-04-17T13:18:23Z")

</div>

I'm using logstash 7.5.1. I would like to parse through all fields of my logstash and convert field starting with the word "time" to float. Please find below my configuration:

```auto
filter {
  # Parse Search Logs
  grok {
    match => ["message", "%{USERNAME:trans_id} %{USERNAME:trans_name} %{USERNAME:sub_trans_name} %{BASE16FLOAT:time_elapsed} %{USERNAME:trans_status} %{GREEDYDATA:payload}"]
  }

  # Extract the time based on the time of the query and
  # not the time the item got logged
  #date {
  # match => ["timestamp", "yyyy-MM-dd HH:mm:ss.SSSSSS"]
  #}

  # Drop the captured timestamp field since it has been moved to the
  # time of the event and drop user1 which are unwanted fields
  #mutate {
  # remove_field => ["timestamp"]
  #}

  mutate {
    add_field => { "%{sub_trans_name}_trans_status" => "%{trans_status}" }
    add_field => { "%{sub_trans_name}_payload" => "%{payload}" }
    add_field => { "time_elapsed_%{sub_trans_name}" => "%{time_elapsed}" }
    remove_field => ["sub_trans_name", "trans_status", "payload"]
  }

  ruby {
    code => "
      event.to_hash.keys.each { |k|
        if k.start_with?('time') and event[k].is_a?(String)
          event[k] = event[k].to_float
        end
     }
   "
  }

}

```

I get Ruby exception occurred: undefined method `' for #\<LogStash::Event:0x1f8ee438 when i try to parse logs:  
Sample Log: 980f884e7a2f11 search pre-process 0.622 1 {question: hello}

Any help would be great, as I have been stuck with this for the entire day.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 17, 2020, 2:13pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521/2 "2020-04-17T14:13:01Z")

</div>

The ability to refer to an event as a hash was removed years ago. You need to use the [event API](https://www.elastic.co/guide/en/logstash/current/event-api.html).

---

<div class="post-metadata">

**Author:** ![Jaikumar\_Ganesan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaikumar_ganesan/32/66507_2.png) [@Jaikumar\_Ganesan](https://discuss.elastic.co/u/Jaikumar_Ganesan)\
**Post date:** [April 17, 2020, 2:39pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521/3 "2020-04-17T14:39:33Z")

</div>

Thanks a lot @Badger I'm a bit new to ruby could you please help me out as to how to loop through fields or how to change the data type of fields starting with the word time?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 17, 2020, 2:50pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521/4 "2020-04-17T14:50:48Z")

</div>

> [@Jaikumar\_Ganesan](#):
>
> event[k] = event[k].to\_float

Change that to

```
event.set(k, event.get(k).to_f)

```

---

<div class="post-metadata">

**Author:** ![Jaikumar\_Ganesan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaikumar_ganesan/32/66507_2.png) [@Jaikumar\_Ganesan](https://discuss.elastic.co/u/Jaikumar_Ganesan)\
**Post date:** [April 17, 2020, 4:04pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521/5 "2020-04-17T16:04:51Z")

</div>

@Badger

```auto
  ruby {
    code => "
      event.to_hash.keys.each { |k|
        if k.start_with?('time') and event[k].is_a?(String)
          event.set(k, event.get(k).to_f)
        end
    }
  "
}

```

This is my code, it still throws ruby exception - Ruby exception occurred: undefined method `'

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 17, 2020, 5:06pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521/6 "2020-04-17T17:06:47Z")

</div>

You still have a reference to event[k]. I would rewrite that as

```
  event.to_hash.each { |k, v|
    if k.start_with?('time') and v.is_a?(String)
      event.set(k, v.to_f)
    end
}
```

---

<div class="post-metadata">

**Author:** ![Jaikumar\_Ganesan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaikumar_ganesan/32/66507_2.png) [@Jaikumar\_Ganesan](https://discuss.elastic.co/u/Jaikumar_Ganesan)\
**Post date:** [April 18, 2020, 2:25am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521/7 "2020-04-18T02:25:10Z")

</div>

> [@Badger](#):
>
> ```auto
> 
> ```

@Badger Oops sorry dint notice that, thanks a lot to have noticed it. Works now

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 16, 2020, 2:25am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-logstash-0x1f8ee438/228521/8 "2020-05-16T02:25:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
