# Ruby filter to modify nested json field failing

**URL:** <https://discuss.elastic.co/t/ruby-filter-to-modify-nested-json-field-failing/357128>\
**Category:** Logstash\
**Created:** [April 10, 2024, 10:44am UTC](https://discuss.elastic.co/t/ruby-filter-to-modify-nested-json-field-failing/357128 "2024-04-10T10:44:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![elastico12](https://avatars.discourse-cdn.com/v4/letter/e/97f17d/32.png) [@elastico12](https://discuss.elastic.co/u/elastico12)\
**Post date:** [April 10, 2024, 10:44am UTC](https://discuss.elastic.co/t/ruby-filter-to-modify-nested-json-field-failing/357128/1 "2024-04-10T10:44:42Z")

</div>

Hi,

I have never used ruby before, or logstash.

i have been trying to modify nested JSON field using ruby. JSON looks like below.

{ "a" : { "b" : "c=d; e=f; g=h" }

My end goal is to remove e=f from the nested key b. But to reach that, my first step was to see if i can replace or even access the field "a". but logger.info doesn't seem to print anything.

```auto
filter {
    ruby {
        code => "
           logger.info(event.get("[a]")
        "
    }
}

```

Somethings i tried..

```auto
filter {
  ruby {
    code => '
      bField = event.get("[a][b]")
      if bField
        bField.gsub!("e=[^;]+;?", "") # Replace e=f; field and its value along with trailing semicolon if any
        event.set("[a][b]", bField)
      end
    '
  }
}

```

Any help is very much appreciated

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 10, 2024, 4:37pm UTC](https://discuss.elastic.co/t/ruby-filter-to-modify-nested-json-field-failing/357128/2 "2024-04-10T16:37:49Z")

</div>

There are several changes here

```
input { generator { count => 1 lines => ['{ "a" : { "b" : "c=d; e=f; g=h" } }'] codec => json } }

output { stdout { codec => rubydebug { metadata => false } } }
filter {
    mutate { remove_field => ["event", "host", "log"] }

    ruby {
        code => '
           logger.info(event.get("[a]").to_s)
        '
    }
    ruby {
        code => '
            bField = event.get("[a][b]")
            if bField
                bField = bField.sub(/e=[^;]+;?/, "") # Replace e=f; field and its value along with trailing semicolon if any
                event.set("[a][b]", bField)
            end
        '
    }
}

```

will produce

```
[2024-04-10T12:34:44,347][INFO][logstash.filters.ruby][main][63456446ae6b8cb04b40b83b5f63d3cb9ea7285a9839ed04258565074977ed3e] {"b"=>"c=d; e=f; g=h"}
{
         "a" => {
    "b" => "c=d; g=h"
},
"@timestamp" => 2024-04-10T16:34:44.245990419Z,
  "@version" => "1"
}

```
