# Ruby filter error

**URL:** <https://discuss.elastic.co/t/ruby-filter-error/225306>\
**Category:** Logstash\
**Created:** [March 26, 2020, 11:00pm UTC](https://discuss.elastic.co/t/ruby-filter-error/225306 "2020-03-26T23:00:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Stefano\_Bossi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefano_bossi/32/41743_2.png) [@Stefano\_Bossi](https://discuss.elastic.co/u/Stefano_Bossi)\
**Post date:** [March 26, 2020, 11:00pm UTC](https://discuss.elastic.co/t/ruby-filter-error/225306/1 "2020-03-26T23:00:25Z")

</div>

Dear Elastic Forum,

I am trying to understand how the ruby filter works in order to apply a complicated reindexing of some data in my cluster.  
I wrote a simple ruby filter example which doesn't work:

```auto
input {
      elasticsearch {
        hosts => [
            "my-test-cluser.node.it"
        ]
        index => "index-*"
        query => '{ "query": { "match": { "_id": "yQmB_HABNyEH-HqOD0uw" } } }'
        codec => "json"
    }
}
filter {
    ruby {
        code => "test = event['@timestamp']"
    }
}

output {
    stdout { codec => rubydebug }
}

```

This simple example doesn't work and the error is:

`[ERROR] 2020-03-26 23:48:54.385 [[colpi-reindex]>worker7] ruby - Ruby exception occurred: undefined method '[]' for #<LogStash::Event:0x71f2a29>`

I can't really understand the error.

The output anyway is:

```auto
{
             "@version" => "1",
       "estensimetro_0" => -2,
        "colpiPerPezzo" => 3,
       "estensimetro_2" => 1,
    "maxForzaColonna_3" => 0,
               "encPos" => 357.8906,
            "exception" => "",
             "facility" => "local1",
           "@timestamp" => 2020-03-21T09:47:50.197Z,
           "sysloghost" => "datalog01.myserver.it",
        "consumoMotore" => 150,
               "logger" => "",
       "estensimetro_1" => 0,
              "evFreno" => false,
    "maxForzaColonna_1" => 368,
                 "tags" => [
        [0] "colpo",
        [1] "_rubyexception"
    ],
       "estensimetro_3" => 0,
              "appname" => "csvconverter",
    "maxForzaColonna_0" => 305,
             "severity" => "EMERG",
                 "type" => "Colpo",
                 "host" => "127.0.0.1:33456",
          "maxForzaTot" => 1452,
           "colpoPezzo" => 3,
              "colpoID" => 1584784069000,
           "evFrizione" => false,
    "maxForzaColonna_2" => 416
}

```

Thanks,  
S.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 26, 2020, 11:14pm UTC](https://discuss.elastic.co/t/ruby-filter-error/225306/2 "2020-03-26T23:14:34Z")

</div>

> [@Stefano\_Bossi](#):
>
> ruby { code =\> "test = event['@timestamp']" }

Referring to the event as a hash was disabled years ago. Use the event [API](https://www.elastic.co/guide/en/logstash/current/event-api.html).

---

<div class="post-metadata">

**Author:** ![Stefano\_Bossi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stefano_bossi/32/41743_2.png) [@Stefano\_Bossi](https://discuss.elastic.co/u/Stefano_Bossi)\
**Post date:** [March 29, 2020, 2:41pm UTC](https://discuss.elastic.co/t/ruby-filter-error/225306/3 "2020-03-29T14:41:48Z")

</div>

Thanks!!!  
All the old examples I found on internet drove me in the wrong direction.

Regards,  
S.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2020, 2:41pm UTC](https://discuss.elastic.co/t/ruby-filter-error/225306/4 "2020-04-26T14:41:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
