# Ruby filter

**URL:** <https://discuss.elastic.co/t/ruby-filter/273055>\
**Category:** Logstash\
**Created:** [May 14, 2021, 6:21pm UTC](https://discuss.elastic.co/t/ruby-filter/273055 "2021-05-14T18:21:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![paulbrown4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulbrown4/32/42327_2.png) [@paulbrown4](https://discuss.elastic.co/u/paulbrown4)\
**Post date:** [May 14, 2021, 6:21pm UTC](https://discuss.elastic.co/t/ruby-filter/273055/1 "2021-05-14T18:21:57Z")

</div>

I am not very familiar with ruby, more so how it interacts with logstash, but I am trying to parse an array of CSVs. For whatever reason the ruby filter I am trying to use is not expanding the variables as a valid field reference.

**sample data**

```auto
"rawkpidata" : [
            "",
            "node, memory,73%",
            "node, disk, 10%",
            "\"liadmf/0\", cpu, 3%",
            "\"rsrcmgr/0\", cpu, 0%",
            "\"lidf/0\", cpu, 0%",
            "\"apimgr/0\", cpu, 0%",
            "\"vnfctrl/0\", cpu, 3%",
            "\"dbmgr/0\", cpu, 0%",
            "\"hactrl/0\", cpu, 0%",
            "\"gtpctrl/0\", cpu, 30%",
            "\"ffemgr/0\", cpu, 0%",
            "\"crldl/0\", cpu, 13%",
            "\"ffe/0\", cpu, 0%",
            "\"mepmgr/0\", cpu, 73%",
            "\"connmgr/0\", cpu, 0%",
            "\"connmgr/1\", cpu, 0%",
            "\"sysstatslog/0\", cpu, 0%"
]

```

**filter**

```auto
ruby {
      code => '
        if event.get("rawkpidata") == nil
        
          event.set("kpi", nil)
          
        else
        
          kpis = event.get("[rawkpidata]")
          
          for kpi in kpis
                      
            if kpi[0] 
              parentField = kpi[0].delete(" \"")
              childField = kpi[1].delete(" ")
              value = kpi[2].delete("%")
            
            
              fieldname = "\[#{parentField}\]\[#{childField}\]"
              event.set(fieldname,value)
           end
            
          end
          
        end
      '
    }

```

**logstash log error**

```auto
Ruby exception occurred: Invalid FieldReference: `[][l]`

```

Any pointers on how to get this to work properly would be very appreciated.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 14, 2021, 6:49pm UTC](https://discuss.elastic.co/t/ruby-filter/273055/2 "2021-05-14T18:49:53Z")

</div>

rawkpidata is an array of strings. For the second one ("node, memory,73%") you are creating a field [n][o] with value d. You need to split the string into an array. Add

```
kpi = kpi.split(/,\s*/)

```

at the start of your loop. Also, you do not need to escape the square brackets in fieldname.

---

<div class="post-metadata">

**Author:** ![paulbrown4](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulbrown4/32/42327_2.png) [@paulbrown4](https://discuss.elastic.co/u/paulbrown4)\
**Post date:** [May 14, 2021, 6:52pm UTC](https://discuss.elastic.co/t/ruby-filter/273055/3 "2021-05-14T18:52:40Z")

</div>

Thanks, I previously had `kpi.split(",")` but, that didn't work either. I'll try your recommendation and see how it goes.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2021, 6:52pm UTC](https://discuss.elastic.co/t/ruby-filter/273055/4 "2021-06-11T18:52:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
