# Ruby filter double event.set not index the content

**URL:** <https://discuss.elastic.co/t/ruby-filter-double-event-set-not-index-the-content/217359>\
**Category:** Logstash\
**Created:** [January 31, 2020, 11:17am UTC](https://discuss.elastic.co/t/ruby-filter-double-event-set-not-index-the-content/217359 "2020-01-31T11:17:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vmoragar](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@vmoragar](https://discuss.elastic.co/u/vmoragar)\
**Post date:** [January 31, 2020, 11:17am UTC](https://discuss.elastic.co/t/ruby-filter-double-event-set-not-index-the-content/217359/1 "2020-01-31T11:17:34Z")

</div>

Hi,  
With Logstasth --\> 7.5.1

The problem is when ia put:  
event.set('[jolokia][metrics][threadpool][webcontainer][activecount]', item['current'])  
event.set('[jolokia][metrics][threadpool][webcontainer][highwatermark]',

But I put only one and then it's workfine.

> code =\> "  
> message\_array = event.get('[jolokia][metrics][threadpool][webcontainer][stats][statistics]')  
> if message\_array.each\_with\_index {|item, index|  
> logger.info('the file-suffix is:', 'value' =\> index.to\_s)  
> logger.info('item:', 'value' =\> item)  
> logger.info('item[name]:', 'value' =\> item['name'])  
> if item['name'] == 'ActiveCount'  
> logger.info('ActiveCount', 'value' =\> item['current'])  
> logger.info('highWaterMark', 'value' =\> item['highWaterMark'])  
> event.set('[jolokia][metrics][threadpool][webcontainer][activecount]', item['current'])  
> event.set('[jolokia][metrics][threadpool][webcontainer][highwatermark]', item['highWaterMark'])

```
   end
   if item['name'] == 'PoolSize'
      logger.info('PoolSize', 'value' => item['current'])
      event.set('[jolokia][metrics][threadpool][webcontainer][poolsize]', item['current'])
   end

   }
  end
"

```

Error is:  
[2020-01-31T12:17:29,752][WARN][logstash.outputs.elasticsearch][main] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"fortuny.metricbeat.2020.01", :\_type=\>"\_doc", :routing=\>nil}, #LogStash::Event:0x24b1d5dc], :response=\>{"index"=\>{"\_index"=\>"fortuny.metricbeat.2020.01", "\_type"=\>"\_doc", "\_id"=\>"tEJR-28BWdp4Tf2y9BIO", "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Limit of total fields [1000] in index [fortuny.metricbeat.2020.01] has been exceeded"}}}}

---

<div class="post-metadata">

**Author:** ![vmoragar](https://avatars.discourse-cdn.com/v4/letter/v/6de8d8/32.png) [@vmoragar](https://discuss.elastic.co/u/vmoragar)\
**Post date:** [February 3, 2020, 11:21am UTC](https://discuss.elastic.co/t/ruby-filter-double-event-set-not-index-the-content/217359/2 "2020-02-03T11:21:10Z")

</div>

I solved, thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 11:21am UTC](https://discuss.elastic.co/t/ruby-filter-double-event-set-not-index-the-content/217359/3 "2020-03-02T11:21:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
