# The performance of using ruby code in config file

**URL:** <https://discuss.elastic.co/t/the-performance-of-using-ruby-code-in-config-file/64366>\
**Category:** Logstash\
**Created:** [October 30, 2016, 9:38am UTC](https://discuss.elastic.co/t/the-performance-of-using-ruby-code-in-config-file/64366 "2016-10-30T09:38:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![WangXiangUSTC](https://avatars.discourse-cdn.com/v4/letter/w/8dc957/32.png) [@WangXiangUSTC](https://discuss.elastic.co/u/WangXiangUSTC)\
**Post date:** [October 30, 2016, 9:38am UTC](https://discuss.elastic.co/t/the-performance-of-using-ruby-code-in-config-file/64366/1 "2016-10-30T09:38:17Z")

</div>

I use logstash to solve logs, and include some ruby code in logstash's config file. I have total four server to run logstash, and every cpu has 32 cores. I found they can only solve about 10000 logs every second, and the use ratio of the cpu is alreay reach the limitation.  
So how to improve the performance of logstash? Is that the ruby code in config file reduce the performance? Any suggest for me?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 30, 2016, 10:03am UTC](https://discuss.elastic.co/t/the-performance-of-using-ruby-code-in-config-file/64366/2 "2016-10-30T10:03:55Z")

</div>

What does your config look like? What kind of processing are you doing with the ruby filter?

---

<div class="post-metadata">

**Author:** ![WangXiangUSTC](https://avatars.discourse-cdn.com/v4/letter/w/8dc957/32.png) [@WangXiangUSTC](https://discuss.elastic.co/u/WangXiangUSTC)\
**Post date:** [October 30, 2016, 10:32am UTC](https://discuss.elastic.co/t/the-performance-of-using-ruby-code-in-config-file/64366/3 "2016-10-30T10:32:39Z")

</div>

just analyze some field of the log, it looks like below:

```
indent preformatted text by 4 spaces`if event.include?('decrypted_body')
                    if event['decrypted_body'] == ''
                        return
                    end
                    if event['body_json'] == nil
                        event['body_json'] = Hash.new
                    end
                    name_hash = Hash['appchannel' => 'app_channel', 'loginchannel' => 'login_channel', 'paychannel' => 'pay_channel']
                    items = event['decrypted_body'].split('&')
                    i = 0
                    while i < items.size do
                        key_value = items[i].split('=')
                        i += 1
                        if key_value.size == 2
                            if ['appchannel', 'loginchannel', 'paychannel'].include?(key_value[0])
                                event['body_json'][name_hash[key_value[0]]] = key_value[1]
                            end
                        end
                    end

```

`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:32am UTC](https://discuss.elastic.co/t/the-performance-of-using-ruby-code-in-config-file/64366/4 "2017-07-06T04:32:01Z")

</div>


