# Ruby Filter for Compressed Binary OID Table

**URL:** <https://discuss.elastic.co/t/ruby-filter-for-compressed-binary-oid-table/285691>\
**Category:** Logstash\
**Created:** [October 1, 2021, 3:14pm UTC](https://discuss.elastic.co/t/ruby-filter-for-compressed-binary-oid-table/285691 "2021-10-01T15:14:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bennrtc](https://avatars.discourse-cdn.com/v4/letter/b/6bbea6/32.png) [@bennrtc](https://discuss.elastic.co/u/bennrtc)\
**Post date:** [October 1, 2021, 3:14pm UTC](https://discuss.elastic.co/t/ruby-filter-for-compressed-binary-oid-table/285691/1 "2021-10-01T15:14:32Z")

</div>

Hello all,

I'm working within an OID that returns values in compressed binary. I've been able to successfully come up with a config (below) that polls a single SNMP OID with compressed binary value using 'get' and then convert the string into a readable fashion.

I'm new to Ruby so my issue comes when I try to convert this config to translate compressed binary OIDs that are part of an SNMP table. Below is my working config for a single OID value.

Can you help me convert this config to work when polling a table instead?

```auto
input {
  snmp {
    hosts => [{host => "udp:xxx.xxx.xxx.xxx/161" version => "1" community => "public"}]
    get => ["IndividualOID"]

    interval => 60
  }
}
filter {
  ruby {
    code => " 
     value = event.get('iso.org.dod.internet.private.enterprises.IndividualOID');

      valArray = value.split(':');
      event.set('LinkState',valArray[0].hex.to_i());
      event.set('LinkWorkingMode',valArray[1].hex.to_i());
      event.set('SessionId',valArray[2..5].join('').hex.to_i());
    "
  }
  mutate {
    remove_field => ["iso.org.dod.internet.private.enterprises.IndividualOID"]
  }
}

output {
  stdout {}
}

```

---

<div class="post-metadata">

**Author:** ![bennrtc](https://avatars.discourse-cdn.com/v4/letter/b/6bbea6/32.png) [@bennrtc](https://discuss.elastic.co/u/bennrtc)\
**Post date:** [October 6, 2021, 3:40pm UTC](https://discuss.elastic.co/t/ruby-filter-for-compressed-binary-oid-table/285691/2 "2021-10-06T15:40:16Z")

</div>

So the solution to this problem ended up being much simpler than we imagined...

```auto
input {
  snmp {
    hosts => [{host => "udp:xxx.xxx.xxx.xxx/161" version => "1" community => "public"}]
    tables => [
      {
        "name" => "RAD"
        "columns" => [
          "tableOID"
        ]
      }
    ]
    interval => 60
  }
}
filter {

  split {
    field => "RAD"
  }

  mutate {
    copy => { "[RAD][tableOID]" => "contentStuff" }
    copy => { "[RAD][index]" => "deviceIndex" }
  }

  ruby {
    code => "
      value = event.get('contentStuff');

      valArray = value.split(':');
      event.set('LinkState',valArray[0].hex.to_i());
      event.set('LinkWorkingMode',valArray[1].hex.to_i());
      event.set('SessionId',valArray[2..5].join('').hex.to_i());

    "
  }

  mutate {
    remove_field => ["RAD","contentStuff"]
  }
}

output {
  stdout {}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2021, 3:40pm UTC](https://discuss.elastic.co/t/ruby-filter-for-compressed-binary-oid-table/285691/3 "2021-11-03T15:40:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
