# Unable to create new document/event in logstash Ruby filter using yield

**URL:** <https://discuss.elastic.co/t/unable-to-create-new-document-event-in-logstash-ruby-filter-using-yield/236995>\
**Category:** Logstash\
**Created:** [June 13, 2020, 7:49pm UTC](https://discuss.elastic.co/t/unable-to-create-new-document-event-in-logstash-ruby-filter-using-yield/236995 "2020-06-13T19:49:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nani\_20](https://avatars.discourse-cdn.com/v4/letter/n/4491bb/32.png) [@Nani\_20](https://discuss.elastic.co/u/Nani_20)\
**Post date:** [June 13, 2020, 7:49pm UTC](https://discuss.elastic.co/t/unable-to-create-new-document-event-in-logstash-ruby-filter-using-yield/236995/1 "2020-06-13T19:49:19Z")

</div>

I am trying to calculate **elapsed time between the first and last line of a file** using a Ruby filter and push the field in a **new event** using the below Ruby filter

```
ruby {
		init => "@save_the_path = 'none'"
		code => "
			if event.get('path') == @save_the_path
				@save_the_lasttimestamp = event.get('@timestamp')
			else
				if @save_the_firsttimestamp
					generated = LogStash::Event.new(
						{'reqtime' => @save_the_lasttimestamp - @save_the_firsttimestamp,
						 'path' => @save_the_path
						})
					new_event_block.call(generated)
					yeild generated
				end
				@save_the_firsttimestamp = event.get('@timestamp')
				@save_the_path = event.get('path')
			end
			"
	}

```

I am expecting above ruby filter to create a new event as soon as logstash receives a new file. But it is not working as expected. Am I doing it in the right way?

P.S.: I was able to do this in **Aggregate filter** but would like to do this in Ruby as I need to do few other operations in Ruby

Any help is highly appreciated. Thanks in advance

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [June 15, 2020, 10:48am UTC](https://discuss.elastic.co/t/unable-to-create-new-document-event-in-logstash-ruby-filter-using-yield/236995/2 "2020-06-15T10:48:48Z")

</div>

Your code says `yeild`, not `yield`. But that shoudn't even be necessary, as `new_event_block.call(generated)` should send the new event already: [https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html#\_inline\_ruby\_code](https://www.elastic.co/guide/en/logstash/current/plugins-filters-ruby.html#_inline_ruby_code) (I've done that myself in the past without `yield`)

---

<div class="post-metadata">

**Author:** ![Nani\_20](https://avatars.discourse-cdn.com/v4/letter/n/4491bb/32.png) [@Nani\_20](https://discuss.elastic.co/u/Nani_20)\
**Post date:** [June 16, 2020, 6:38pm UTC](https://discuss.elastic.co/t/unable-to-create-new-document-event-in-logstash-ruby-filter-using-yield/236995/3 "2020-06-16T18:38:00Z")

</div>

@Jenni

I removed the yield and yeah it worked perfectly fine 😀

Thanks a ton!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2020, 6:38pm UTC](https://discuss.elastic.co/t/unable-to-create-new-document-event-in-logstash-ruby-filter-using-yield/236995/4 "2020-07-14T18:38:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
