# \[SOLVED\] \[logstash 2.3\] ruby error using event.get

**URL:** <https://discuss.elastic.co/t/solved-logstash-2-3-ruby-error-using-event-get/112020>\
**Category:** Logstash\
**Created:** [December 15, 2017, 5:05pm UTC](https://discuss.elastic.co/t/solved-logstash-2-3-ruby-error-using-event-get/112020 "2017-12-15T17:05:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mobidyc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mobidyc/32/42027_2.png) [@mobidyc](https://discuss.elastic.co/u/mobidyc)\
**Post date:** [December 15, 2017, 5:05pm UTC](https://discuss.elastic.co/t/solved-logstash-2-3-ruby-error-using-event-get/112020/1 "2017-12-15T17:05:13Z")

</div>

Hello,

I try to do a substraction on a float number and i'm facing this issue:

```
# echo '{"ts":"123124.094", "rq":"0.020"}' | \
    /opt/logstash/bin/logstash -e \
    "input { 
        stdin { codec => json }
    } output {
        stdout { codec => rubydebug }
    } filter { 
        ruby { code => \"event.set('total', event.get('ts') - event.get('rq'))\" }
    }"

Settings: Default pipeline workers: 4
Pipeline main started
Ruby exception occurred: undefined method `get' for #<LogStash::Event:0x60e932d7> {:level=>:error}
{
            "ts" => "123124.094",
            "rq" => "0.020",
      "@version" => "1",
    "@timestamp" => "2017-12-15T17:00:31.650Z",
          "host" => "es-traces.novalocal",
          "tags" => [
        [0] "_rubyexception"
    ]
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

I could not find the event.(get|set) description in the logstash 2.3 documentation, so maybe it is not handled in this version.  
Upgrading logstash is not an option for me unfortunately.

Can you share how to achieve that kind of substraction?

Thank you

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 18, 2017, 6:28am UTC](https://discuss.elastic.co/t/solved-logstash-2-3-ruby-error-using-event-get/112020/3 "2017-12-18T06:28:41Z")

</div>

In Logstash 2.3 you can access the event fields directly (both read and write) like you would access the key in a normal Ruby hash, i.e. `event['fieldname']`.

---

<div class="post-metadata">

**Author:** ![mobidyc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mobidyc/32/42027_2.png) [@mobidyc](https://discuss.elastic.co/u/mobidyc)\
**Post date:** [December 19, 2017, 11:35am UTC](https://discuss.elastic.co/t/solved-logstash-2-3-ruby-error-using-event-get/112020/4 "2017-12-19T11:35:54Z")

</div>

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 16, 2018, 11:35am UTC](https://discuss.elastic.co/t/solved-logstash-2-3-ruby-error-using-event-get/112020/5 "2018-01-16T11:35:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
