# Solved - Ruby exceptions - updating filter to new api

**URL:** <https://discuss.elastic.co/t/solved-ruby-exceptions-updating-filter-to-new-api/83320>\
**Category:** Logstash\
**Created:** [April 23, 2017, 10:48am UTC](https://discuss.elastic.co/t/solved-ruby-exceptions-updating-filter-to-new-api/83320 "2017-04-23T10:48:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AtomicWerks](https://avatars.discourse-cdn.com/v4/letter/a/3be4f8/32.png) [@AtomicWerks](https://discuss.elastic.co/u/AtomicWerks)\
**Post date:** [April 23, 2017, 10:48am UTC](https://discuss.elastic.co/t/solved-ruby-exceptions-updating-filter-to-new-api/83320/1 "2017-04-23T10:48:47Z")

</div>

Hi. I'm very new to the ELK stack and trying to get my logstash config updated from 4.x to 5.x and I'm having a problem with my ruby filter.

I have already in the config:  
\>ruby {  
code =\> "if event['event\_type'] == 'fileinfo'; event['fileinfo']['type']=event['fileinfo']['magic'].to\_s.split(',')[0]; end;"  
}

I'm would like to update to the new api as I'm getting exceptions.

I have tried updating it ,but I have not used Ruby before and I am stuck. Could someone kindly help me.

Here is what I have currently:

> ruby {  
> code =\> "if event.get('event\_type') == "fileinfo"; event.set('[fileinfo][type]', event.get('[fileinfo][magic].to\_s.split(',')[0]')); end;"  
> }

I am getting exception:

> [ERROR][logstash.filters.ruby] Ruby exception occurred : wrong number of arguments calling `get` (2 for 1)

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![AtomicWerks](https://avatars.discourse-cdn.com/v4/letter/a/3be4f8/32.png) [@AtomicWerks](https://discuss.elastic.co/u/AtomicWerks)\
**Post date:** [April 23, 2017, 4:56pm UTC](https://discuss.elastic.co/t/solved-ruby-exceptions-updating-filter-to-new-api/83320/2 "2017-04-23T16:56:27Z")

</div>

Found the answer. Here is what I ended up with. If there is a better way, please do tell.  
Thanks.

> ruby {  
> code =\> "  
> if event.get('[event\_type]') == 'fileinfo'  
> event.set('[fileinfo][type]', event.get('[fileinfo][magic]').to\_s.split(',')[0])  
> end  
> "  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2017, 4:58pm UTC](https://discuss.elastic.co/t/solved-ruby-exceptions-updating-filter-to-new-api/83320/3 "2017-05-21T16:58:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
