# Sort array before concatenated fingerprint hash?

**URL:** <https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602>\
**Category:** Logstash\
**Created:** [November 16, 2020, 11:53pm UTC](https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602 "2020-11-16T23:53:19Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sliddjur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sliddjur/32/65260_2.png) [@sliddjur](https://discuss.elastic.co/u/sliddjur)\
**Post date:** [November 16, 2020, 11:53pm UTC](https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602/1 "2020-11-16T23:53:20Z")

</div>

I have src\_ip and dst\_ip fields. I have copied both those values to "[fw][talkers]" field to produce this:

```
"fw": {
  "talkers": [
    "172.16.216.118",
    "172.23.253.22"
  ]

```

Now I run fingerprint on this value to produce hash

```
  fingerprint {
    method => "MURMUR3"
    source => "[fw][talkers]"
    target => "[fw][talkers_hash]"
    concatenate_sources => true

```

and that gives me

```
  "fw.talkers_hash": 2828631464

```

all good so far, but how can I _sort_ this array before running it through fingerprint?

I want the end result with the **same [fw][talkers] pair, but in another order** to give me the same hash, like this:

```
"fw": {
  "talkers": [
    "172.23.253.22",
    "172.16.216.118"
  ]
  "fw.talkers_hash": 2828631464

```

Is it possible? Am I doing the wrong approach?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 17, 2020, 2:07am UTC](https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602/2 "2020-11-17T02:07:23Z")

</div>

> [@sliddjur](#):
>
> Is it possible?

Pretty much anything is possible in logstash. If you are willing to write enough ruby code you could make logstash a C++ compiler.

If you want to sort the array before hashing its contents you could use

```
ruby { code => 'event.set("[fw][talkers]", event.get("[fw][talkers]").sort)' }

```

Error handling is left as an exercise for the reader.

---

<div class="post-metadata">

**Author:** ![sliddjur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sliddjur/32/65260_2.png) [@sliddjur](https://discuss.elastic.co/u/sliddjur)\
**Post date:** [November 17, 2020, 8:27am UTC](https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602/3 "2020-11-17T08:27:04Z")

</div>

Hello @Badger I read more on your example in the ruby guide [https://www.elastic.co/guide/en/logstash/current/event-api.html#\_ruby\_filter](https://www.elastic.co/guide/en/logstash/current/event-api.html#_ruby_filter)  
But I am getting this error when I enable this filter:

`logstash[1295285]: [2020-11-17T09:17:06,424][ERROR][logstash.filters.ruby][main][ca13ca727f3e3e61e11487fa488986ef3fbf2b6304b19d7e97a0b57b11a25f93] Ruby exception occurred: undefined method `sort' for nil:NilClass`

And the event field is not sorted.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 17, 2020, 1:48pm UTC](https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602/4 "2020-11-17T13:48:06Z")

</div>

> [@sliddjur](#):
>
> `undefined method ` sort' for nil:NilClass`

That is telling you that the [fw][talkers] field does not exist, so event.get("[fw][talkers]") is returning nil. That is what I was referring to when I said "Error handling is left as an exercise for the reader".

Note that the fingerprint filter [sorts](https://github.com/logstash-plugins/logstash-filter-fingerprint/blob/7292935638b14b433ba26096f7451a1f5342ca76/lib/logstash/filters/fingerprint.rb#L148) all the hashes in an event to ensure that fingerprints are consistent regardless of initial order. If the same needs to be done for arrays then that would probably be regarded as a bug.

---

<div class="post-metadata">

**Author:** ![sliddjur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sliddjur/32/65260_2.png) [@sliddjur](https://discuss.elastic.co/u/sliddjur)\
**Post date:** [November 17, 2020, 6:54pm UTC](https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602/5 "2020-11-17T18:54:20Z")

</div>

I appreciate your effort to making us learn and understand better. But I spent hours trying to wrap my head around why this field doesnt exist as you say. I don't understand, as I can see the json in elasticsearch. Are nested fields called in another way in ruby code filter? I tried using `fw.talkers` and some other combinations, but that didnt help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 17, 2020, 6:56pm UTC](https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602/6 "2020-11-17T18:56:02Z")

</div>

In logstash a nested field is referred to using square brackets around each field -- [fw][talkers]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 15, 2020, 6:56pm UTC](https://discuss.elastic.co/t/sort-array-before-concatenated-fingerprint-hash/255602/7 "2020-12-15T18:56:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
