# Ruby filter to map different array elements into one record

**URL:** <https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219>\
**Category:** Logstash\
**Created:** [June 15, 2022, 5:57am UTC](https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219 "2022-06-15T05:57:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![santhoshi.p](https://avatars.discourse-cdn.com/v4/letter/s/43a26b/32.png) [@santhoshi.p](https://discuss.elastic.co/u/santhoshi.p)\
**Post date:** [June 15, 2022, 5:57am UTC](https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219/1 "2022-06-15T05:57:08Z")

</div>

Hi,

I have a response like below I'm unable to figure how i need to proceed further. Kindly provide any solution.

Response:  
{  
"columns": [  
[0] {  
"label": "ICMP",  
"ingress": true  
},  
[1] {  
"label": "ICMP",  
"ingress": false  
},  
[2] {  
"label": "snmp",  
"ingress": true  
},......  
],  
"timestamps": [  
[0] 1655089145032,  
[1] 1655089445032,  
[2] 1655089745032,  
.................],  
"values": [  
186710.61691104108,  
185786.64188565157,  
186711.51350526334,  
........],  
}

I need output like  
{  
"label": "ICMP",----\> column[0][0]  
"ingress": true,----\> column[0][1]  
"Value": 186710.61691104108, ---\> value[0]  
"timestamp" : 1655089145032 ---\> timestamp [0]  
}  
{  
// Like wise in all the records  
}.....

Thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 15, 2022, 4:48pm UTC](https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219/2 "2022-06-15T16:48:58Z")

</div>

You could try

```
    ruby {
        code => '
            columns = event.get("columns")
            timestamps = event.get("timestamps")
            values = event.get("values")
            if columns.is_a? Array and timestamps.is_a? Array and values.is_a? Array and
                    columns.length == timestamps.length and columns.length == values.length and
                    columns[0].is_a? Hash
                a = []
                columns.each_index { |x|
                    a << { "label" => columns[x]["label"],
                        "ingress" => columns[x]["ingress"],
                        "Value" => values[x],
                        "timestamp" => timestamps[x]
                    }
                }
                event.set("[@metadata][data]", a)
            end
        '
        remove_field => ["columns", "timestamps", "values"]
    }
    if [@metadata][data] {
        split { field => "[@metadata][data]" }
        ruby {
            code => '
                event.get("[@metadata][data]").each { |k, v|
                    event.set(k, v)
                }
            '
        }
    }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 13, 2022, 4:49pm UTC](https://discuss.elastic.co/t/ruby-filter-to-map-different-array-elements-into-one-record/307219/3 "2022-07-13T16:49:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
