# Ruby exception occurred: uninitialized constant when i am trying to devide a field value by 100

**URL:** https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058
**Category:** Logstash
**Created:** [August 13, 2022, 7:47pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058 "2022-08-13T19:47:20Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![Faiz\_Shamri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faiz_shamri/32/50097_2.png) [@Faiz\_Shamri](https://discuss.elastic.co/u/Faiz_Shamri)
#### Post date: [August 13, 2022, 7:47pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/1 "2022-08-13T19:47:20Z")

</div>

I am trying to devide filed value by 100 but i am getting `Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]} [ERROR] 2022-08-14 00:10:07.738 [[main]>worker2] ruby - Ruby exception occurred: uninitialized constant LogStash::Filters::Ruby::ReloadedAmount {:class=>"NameError", :backtrace=>["org/jruby/RubyModule.java:3766:in `const_missing'"`

here is my conf file:

```auto
 filter {
 mutate {
     convert => { "ReloadedAmount" => "integer" }
     }
       ruby{
             code => "event.set('ReloadedAmount', event.get('ReloadedAmount') / event.get('100'))"
    }
}

```

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 13, 2022, 9:30pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/2 "2022-08-13T21:30:08Z")

</div>

> [@Faiz\_Shamri](#):
>
> `code => "event.set('ReloadedAmount', event.get('ReloadedAmount') / event.get('100'))"`

Do you have a field named `100` ? Using `event.get('100')` will make the ruby filter try to get the value of the field named `100`.

You should try:

```auto
code => "event.set('ReloadedAmount', event.get('ReloadedAmount') / 100)"

```

You may also need to convert it to a numeric type like float before.

```auto
code => "event.set('ReloadedAmount', event.get('ReloadedAmount').to_f / 100)"

```

---

<div class="post-metadata">

### Author: ![Faiz\_Shamri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faiz_shamri/32/50097_2.png) [@Faiz\_Shamri](https://discuss.elastic.co/u/Faiz_Shamri)
#### Post date: [August 14, 2022, 5:38am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/3 "2022-08-14T05:38:29Z")

</div>

Hello @leandrojmp ,  
I did the changes you have suguested but still i am getting the same error:

`ruby - Ruby exception occurred: uninitialized constant LogStash::Filters::Ruby::ReloadedAmount {:class=>"NameError", :backtrace=>["org/jruby/RubyModule.java:3766:in `const_missing'",`

I am pasting below my entire conf file:

```auto
echo "
Time User AccBal accBalBef accBalAft amountReloaded
========================================================================================  
19:10:29 someUser someClient 24205700 331510000 307304300
" | /usr/share/logstash/bin/logstash -e 'input { stdin {} } filter {

	if [message] =~ /^=.*$/ {
     	  drop { }
   	} else if [message] =~ /^Time.*$/ {
     	  drop { }
     	}
   	if [message] == "" {
     		drop { }
   	}
        grok {
            match => { "message" => ["%{TIME:time}\s*%{USERNAME:User}\s*%{USER:ActorId}\s*%{NUMBER:AccountBef}\s*%{NUMBER:AccountAft}\s*%{NUMBER:ReloadedAmount}"] }           
        }
       
        grok {
           match => {"[log][file][path]" => "/%{GREEDYDATA}/balanceReload_%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:day}\.txt$"}
           add_field => ["Ndate", "%{year}-%{month}-%{day} %{time}"]
        }
       date {
            match => ["Ndate", "yyyy-MM-dd HH:mm:ss"]
            target => "@timestamp"
            timezone => "UTC"
            remove_field => ["year", "month", "day"]
      }
     mutate {
     add_field => { "[@metadata][field]" => "ReloadedAmount" } 
     convert => { "AccountBef" => "integer" }
     convert => { "AccountAft" => "integer" }
     convert => { "ReloadedAmount" => "integer" }
     }
      ruby {
       code => "event.set('ReloadedAmount', event.get('ReloadedAmount').to_f / 100)"

      } 
       
}
output {

  stdout {}
  
}'

```

below is the output i get:

```auto
[ERROR] 2022-08-14 10:02:07.766 [[main]>worker3] ruby - Ruby exception occurred: uninitialized constant LogStash::Filters::Ruby::ReloadedAmount {:class=>"NameError", :backtrace=>["org/jruby/RubyModule.java:3766:in `const_missing'", "(ruby filter code):2:in `block in filter_method'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.8/lib/logstash/filters/ruby.rb:96:in `inline_script'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-ruby-3.1.8/lib/logstash/filters/ruby.rb:89:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:159:in `do_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:178:in `block in multi_filter'", "org/jruby/RubyArray.java:1821:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:175:in `multi_filter'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:134:in `multi_filter'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:300:in `block in start_workers'"]}
{
             "event" => {
        "original" => "19:10:29 someUser SomeClient 24205700 331510000 307304300"
    },
        "@timestamp" => 2022-08-14T05:32:07.579729Z,
              "time" => "19:10:29",
        "AccountAft" => 331510000,
           "ActorId" => "someClient",
    "ReloadedAmount" => 307304300,
        "AccountBef" => 24205700,
              "User" => "someUser",
          "@version" => "1",
           "message" => "19:10:29 someName someClient 24205700 331510000 307304300",
              "host" => {
        "hostname" => "spider"
    },
              "tags" => [
        [0] "_grokparsefailure",
        [1] "_rubyexception"
    ]
}
[INFO] 2022-08-14 10:02:08.009 [[main]-pipeline-manager] javapipeline - Pipeline terminated {"pipeline.id"=>"main"}

```

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [August 14, 2022, 6:16am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/4 "2022-08-14T06:16:58Z")

</div>

Do not coneversion and ruby in the same mutate. Split in two mutate blocks.

Grok is also not ok.

---

<div class="post-metadata">

### Author: ![Faiz\_Shamri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/faiz_shamri/32/50097_2.png) [@Faiz\_Shamri](https://discuss.elastic.co/u/Faiz_Shamri)
#### Post date: [August 14, 2022, 6:23am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/5 "2022-08-14T06:23:11Z")

</div>

Hello @Rios,  
Ruby is outside of mutate block.. Can you plz elaborate more?

---

<div class="post-metadata">

### Author: ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)
#### Post date: [August 14, 2022, 6:52am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/6 "2022-08-14T06:52:28Z")

</div>

Ah sorry,my mistake, I'm reading on mobile.  
Ignore my previous comment

---

<div class="post-metadata">

### Author: ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)
#### Post date: [August 14, 2022, 4:42pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/7 "2022-08-14T16:42:45Z")

</div>

I had the same issue when I tried to run the same you are running it, passing the entire configuration in the cli, no idea what is the cause, probably some internal mixup with single quotes and double quotes.

But if you use the same configuration in a file, it will work without any issue.

I've tested with this configuration, just change the destination field to `ReloadedAmount_divided_by_100` to have the two fields and compare.

```auto
input { 
    stdin {} 
} 
filter {
    if [message] =~ /^=.*$/ {
        drop { }
    } else if [message] =~ /^Time.*$/ {
        drop { }
    }
    if [message] == "" {
        drop { }
    }
    grok {
        match => { "message" => ["%{TIME:time}\s*%{USERNAME:User}\s*%{USER:ActorId}\s*%{NUMBER:AccountBef}\s*%{NUMBER:AccountAft}\s*%{NUMBER:ReloadedAmount}"] }           
    }
    grok {
        match => {"[log][file][path]" => "/%{GREEDYDATA}/balanceReload_%{YEAR:year}%{MONTHNUM:month}%{MONTHDAY:day}\.txt$"}
        add_field => ["Ndate", "%{year}-%{month}-%{day} %{time}"]
    }
    date {
        match => ["Ndate", "yyyy-MM-dd HH:mm:ss"]
        target => "@timestamp"
        timezone => "UTC"
        remove_field => ["year", "month", "day"]
    }
    mutate {
        add_field => { "[@metadata][field]" => "ReloadedAmount" } 
        convert => { "AccountBef" => "integer" }
        convert => { "AccountAft" => "integer" }
        convert => { "ReloadedAmount" => "integer" }
    }
    ruby {
        code => "event.set('ReloadedAmount_divided_by_100', event.get('ReloadedAmount').to_f / 100)"
    }
}
output {
  stdout {} 
}

```

And running it as:

```auto
echo "
Time User AccBal accBalBef accBalAft amountReloaded
========================================================================================  
19:10:29 someUser someClient 24205700 331510000 307304300
" | /usr/share/logstash/bin/logstash --path.settings /etc/logstash/ -f /etc/logstash/pipelines/discuss.conf 

```

This is the result:

```auto
{
                             "time" => "19:10:29",
                          "ActorId" => "someClient",
                             "host" => "elk",
                             "User" => "someUser",
                       "AccountBef" => 24205700,
                          "message" => "19:10:29 someUser someClient 24205700 331510000 307304300",
                             "tags" => [
        [0] "_grokparsefailure"
    ],
                       "AccountAft" => 331510000,
    "ReloadedAmount_divided_by_100" => 3073043.0,
                   "ReloadedAmount" => 307304300,
                         "@version" => "1",
                       "@timestamp" => 2022-08-14T16:40:48.136Z
}

```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [August 14, 2022, 6:19pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/8 "2022-08-14T18:19:08Z")

</div>

In the bash shell, single quotes cannot occur in single quoted strings.

> [@Faiz\_Shamri](#):
>
> ```auto
> /usr/share/logstash/bin/logstash -e '....
> ruby {
> code => "event.set('ReloadedAmount', event.get('ReloadedAmount').to_f / 100)"
> } '
> 
> ```

has three single quoted strings joined by ReloadedAmount, so it reduces to

```auto
/usr/share/logstash/bin/logstash -e '....
      ruby {
       code => "event.set(ReloadedAmount, event.get(ReloadedAmount).to_f / 100)"
      } '

```

In Ruby, any "variable" that starts with an uppercase letter is a constant, so the error is telling you that there is no ReloadedAmount constant. If you use double quotes around the config string you can escape the double quotes within them, so

```auto
echo "" | /usr/share/logstash/bin/logstash --path.data $TMPDIR --path.settings /etc/logstash --log.level debug -e "
input { stdin {} }
filter { ruby { code => 'event.set(\"ReloadedAmount\", 1)' } }
output { stdout {} }"

```

works.

This quoting behaviour is specific to bash. ksh, csh, and true Bourne shell would do it differently.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 11, 2022, 6:19pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-uninitialized-constant-when-i-am-trying-to-devide-a-field-value-by-100/312058/9 "2022-09-11T18:19:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
