# Ruby filter plugin: how to indicate failure

**URL:** <https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055>\
**Category:** Logstash\
**Created:** [January 21, 2019, 1:47pm UTC](https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055 "2019-01-21T13:47:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![darefilz](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@darefilz](https://discuss.elastic.co/u/darefilz)\
**Post date:** [January 21, 2019, 1:47pm UTC](https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055/1 "2019-01-21T13:47:11Z")

</div>

Hi,  
currently I use a small Ruby filter script to request a REST API and get some data.  
If valid data is returned the script is "successful" and the ruby filter applies the `add_tag` option and adds some tags. But of course it is possible that no data is found and the script is not successful and thus the filter should not apply any tags.  
**How to indicate inside the ruby script whether the filter is successful or not?**  
Currently I raise an exception for invalid or no data, but that causes an error log for each affected event and the _\_rubyexception_ tag is added which both is undesirable.  
Can you please help me out with that?  
Thank you!

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 21, 2019, 4:01pm UTC](https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055/2 "2019-01-21T16:01:21Z")

</div>

The upcoming release of Logstash 6.6.0 will include the new [http filter (docs)](https://www.elastic.co/guide/en/logstash-versioned-plugins/current/filter-http-index.html#filter-http-index). You can install this on older versions of Logstash though.  
`bin/logstash-plugin install logstash-filter-http`

You might like to try it as a solution instead.

If the http filter does not work for you then read on.  
This is what the ruby filter does internally.

```ruby
  def inline_script(event, &block)
    filter_method(event, &block)
    filter_matched(event)
  rescue Exception => e
    @logger.error("Ruby exception occurred: #{e}")
    event.tag(@tag_on_exception)
  end

```

`filter_method` is a generated method encapsulating your ruby filter code.  
`filter_matched` is where the add\_field, add\_tag, remove\_field and remove\_tag functions are executed.

You have three scenarios.

1. All good
2. HTTP call worked but invalid data is returned
3. Something goes wrong and an exception is raised in `filter_method`

For 1) and 2) you need to handle the add\_tag yourself in the code block when you have invalid data.  
`event.tag('invalid_data_http')`  
For 3) if you don't want an error message logged this you should wrap your code in the same `begin rescue end` construct.

```auto
begin
    # your http code here
  rescue Exception => e
    event.tag('http_rest_call_failed')
  end

```

If you do this make sure you remove the standard `add_field, add_tag, remove_field and remove_tag` settings from the ruby filter settings.

---

<div class="post-metadata">

**Author:** ![darefilz](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@darefilz](https://discuss.elastic.co/u/darefilz)\
**Post date:** [January 22, 2019, 11:05am UTC](https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055/3 "2019-01-22T11:05:55Z")

</div>

Okay, I see, thanks. Guess I'll wait for the filter plugin. When is the release (planned)?

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 22, 2019, 11:11am UTC](https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055/4 "2019-01-22T11:11:05Z")

</div>

> You can install this on older versions of Logstash though.  
> `bin/logstash-plugin install logstash-filter-http`

The plugin has been uploaded. You can use it now. When we say released, we mean - it is the first time the plugin is included in the Logstash distribution by default and it is mentioned in the release notes.

The plugin is in the download location and the docs are in Elastic's docs on Logstash plugins.

---

<div class="post-metadata">

**Author:** ![darefilz](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@darefilz](https://discuss.elastic.co/u/darefilz)\
**Post date:** [January 22, 2019, 12:40pm UTC](https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055/5 "2019-01-22T12:40:51Z")

</div>

Ay, great.

---

<div class="post-metadata">

**Author:** ![darefilz](https://avatars.discourse-cdn.com/v4/letter/d/d07c76/32.png) [@darefilz](https://discuss.elastic.co/u/darefilz)\
**Post date:** [January 22, 2019, 3:37pm UTC](https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055/6 "2019-01-22T15:37:41Z")

</div>

This plugin works very well and it's damn fast. Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2019, 3:41pm UTC](https://discuss.elastic.co/t/ruby-filter-plugin-how-to-indicate-failure/165055/7 "2019-02-19T15:41:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
