# The new variable in the filter ruby event must be set() before it can be used?

**URL:** <https://discuss.elastic.co/t/the-new-variable-in-the-filter-ruby-event-must-be-set-before-it-can-be-used/301406>\
**Category:** Logstash\
**Created:** [April 3, 2022, 1:23am UTC](https://discuss.elastic.co/t/the-new-variable-in-the-filter-ruby-event-must-be-set-before-it-can-be-used/301406 "2022-04-03T01:23:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [April 3, 2022, 1:23am UTC](https://discuss.elastic.co/t/the-new-variable-in-the-filter-ruby-event-must-be-set-before-it-can-be-used/301406/1 "2022-04-03T01:23:40Z")

</div>

```auto
   ruby {
     code => "
       pubtime_new = event.get('[pubtime]').to_i * 1000
       event.set('pubtime_new',pubtime_new) >>>> If I don't register pubtime_new then below can't get the value of pubtime_new.
       timeset = event.get('[timestamp_us]').to_i - event.get('[pubtime_new]').to_i
       event.set('timeset',timeset)
       event.set('delay_time_us', event.get('[pubtime]').to_i - event.get('[device_timestamp]').to_i)
       event.set('pub_subtime_us', timeset + event.get('[transaction_duration_us]').to_i )
    "
   }

```

Maybe I don't understand it correctly, and I don't know much about ruby, I just want to ask if there are other ways to directly refer to the new variable.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 3, 2022, 2:03am UTC](https://discuss.elastic.co/t/the-new-variable-in-the-filter-ruby-event-must-be-set-before-it-can-be-used/301406/2 "2022-04-03T02:03:47Z")

</div>

> [@wajika](#):
>
> ```auto
> pubtime_new = event.get('[pubtime]').to_i * 1000
> event.set('pubtime_new',pubtime_new) >>>> If I don't register pubtime_new then below can't get the value of pubtime_new.
> timeset = event.get('[timestamp_us]').to_i - event.get('[pubtime_new]').to_i
> 
> ```

You can do

```
   pubtime_new = event.get('[pubtime]').to_i * 1000
   timeset = event.get('[timestamp_us]').to_i - pubtime_new

```

and reference the ruby variable, just as you do with timeset.

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [April 3, 2022, 4:08am UTC](https://discuss.elastic.co/t/the-new-variable-in-the-filter-ruby-event-must-be-set-before-it-can-be-used/301406/3 "2022-04-03T04:08:51Z")

</div>

I wrote it like this at the beginning, but the value of pub\_subtime\_us is wrong.  
`timeset = event.get('[timestamp_us]').to_i - pubtime_new`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2022, 4:09am UTC](https://discuss.elastic.co/t/the-new-variable-in-the-filter-ruby-event-must-be-set-before-it-can-be-used/301406/4 "2022-05-01T04:09:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
