# Ruby filter in Logstash, how to pass parameters to external Ruby script

**URL:** <https://discuss.elastic.co/t/ruby-filter-in-logstash-how-to-pass-parameters-to-external-ruby-script/120333>\
**Category:** Logstash\
**Created:** [February 18, 2018, 4:12am UTC](https://discuss.elastic.co/t/ruby-filter-in-logstash-how-to-pass-parameters-to-external-ruby-script/120333 "2018-02-18T04:12:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Heckler\_GlobalOperat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/heckler_globaloperat/32/115896_2.png) [@Heckler\_GlobalOperat](https://discuss.elastic.co/u/Heckler_GlobalOperat)\
**Post date:** [February 18, 2018, 4:12am UTC](https://discuss.elastic.co/t/ruby-filter-in-logstash-how-to-pass-parameters-to-external-ruby-script/120333/1 "2018-02-18T04:12:05Z")

</div>

Hi everyone,  
I'm preparing a Logstash configuration which use Grok to extract fields from incoming messages and Ruby to process those fields.

Below is a simple version of my configuration, I want to extract the Timestamp and Server values from the incoming messages, then pass those parameters to a Ruby script (named **ruby\_process.rb** ) via "_script\_params_"

> grok {  
> match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp}, %{WORD:server} %{WORD:state}"]  
> }
> 
> ruby {   
> path =\> "E:\logstash-6.1.2\config\scripts\ruby\_process.rb"  
> script\_params =\> {
> 
> "server" =\> "event.get('server')"
> 
> "timestamp" =\> "event.get('timestamp')"  
> }  
> }

In **ruby\_process.rb** , I read the Server and Timestamp params into Ruby variables

> def register(params)  
> @server = params["server"]  
> @epoc = params["timestamp"]  
> end

But it just doesn't work, the value of @server is the literal string "event.get('server')", not the value itself. I have looked around the Google but found no example for this usecase

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 18, 2018, 2:12pm UTC](https://discuss.elastic.co/t/ruby-filter-in-logstash-how-to-pass-parameters-to-external-ruby-script/120333/2 "2018-02-18T14:12:47Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#sprintf)

However, what you're trying to do doesn't make sense. The script parameters are passed to the ruby filter's register function (as you've noticed) but that code is run when the pipeline starts up. At that point there is no event context so you can't possibly pass field values from an event.

If you really want to access field values in your ruby filter you can just access them via the event object straight in your code.

---

<div class="post-metadata">

**Author:** ![Heckler\_GlobalOperat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/heckler_globaloperat/32/115896_2.png) [@Heckler\_GlobalOperat](https://discuss.elastic.co/u/Heckler_GlobalOperat)\
**Post date:** [February 19, 2018, 3:09pm UTC](https://discuss.elastic.co/t/ruby-filter-in-logstash-how-to-pass-parameters-to-external-ruby-script/120333/3 "2018-02-19T15:09:04Z")

</div>

Thank you, I forgot that I can access the fields in the Filter method in Ruby script 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2018, 3:09pm UTC](https://discuss.elastic.co/t/ruby-filter-in-logstash-how-to-pass-parameters-to-external-ruby-script/120333/4 "2018-03-19T15:09:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
