# Split command in ruby by new line

**URL:** <https://discuss.elastic.co/t/split-command-in-ruby-by-new-line/118999>\
**Category:** Logstash\
**Created:** [February 8, 2018, 8:58am UTC](https://discuss.elastic.co/t/split-command-in-ruby-by-new-line/118999 "2018-02-08T08:58:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 8, 2018, 8:58am UTC](https://discuss.elastic.co/t/split-command-in-ruby-by-new-line/118999/1 "2018-02-08T08:58:45Z")

</div>

Hi,

I am trying to split the message where ever a **new line** exist by **ruby filter**.

The command in the ruby code I use:

`message_array = event.get('message').split("\n")`

But the logstash doesn't start because of it.

It looks like logstash doesn't support the "\n"

`message_array = event.get('message').split(\""}`

Any workaround?

Regards,  
Sharon.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2018, 9:41am UTC](https://discuss.elastic.co/t/split-command-in-ruby-by-new-line/118999/2 "2018-02-08T09:41:26Z")

</div>

Don't mix single and double quotes inside the Ruby code. You can't use the same kind of quote that you're using the delimit the Ruby code block.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 8, 2018, 1:02pm UTC](https://discuss.elastic.co/t/split-command-in-ruby-by-new-line/118999/3 "2018-02-08T13:02:00Z")

</div>

Sure, great.

So what should I do?

What do I need to do in order to split the event in new lines?

Thanks in advanced,  
Sharon.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 8, 2018, 1:10pm UTC](https://discuss.elastic.co/t/split-command-in-ruby-by-new-line/118999/4 "2018-02-08T13:10:12Z")

</div>

As I said, use quotes consistently.

```
code => 'message_array = event.get("message").split("\n")'

```

Of course, to just split a string on newline characters you don't need a ruby filter, just use a mutate filter.

---

<div class="post-metadata">

**Author:** ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)\
**Post date:** [February 8, 2018, 1:11pm UTC](https://discuss.elastic.co/t/split-command-in-ruby-by-new-line/118999/5 "2018-02-08T13:11:18Z")

</div>

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 8, 2018, 1:11pm UTC](https://discuss.elastic.co/t/split-command-in-ruby-by-new-line/118999/6 "2018-03-08T13:11:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
