# "Undefined method \`gsub!'" when executes a Ruby filter to change timezone

**URL:** <https://discuss.elastic.co/t/undefined-method-gsub-when-executes-a-ruby-filter-to-change-timezone/180420>\
**Category:** Logstash\
**Created:** [May 9, 2019, 5:41pm UTC](https://discuss.elastic.co/t/undefined-method-gsub-when-executes-a-ruby-filter-to-change-timezone/180420 "2019-05-09T17:41:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcogarfias](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@marcogarfias](https://discuss.elastic.co/u/marcogarfias)\
**Post date:** [May 9, 2019, 5:41pm UTC](https://discuss.elastic.co/t/undefined-method-gsub-when-executes-a-ruby-filter-to-change-timezone/180420/1 "2019-05-09T17:41:12Z")

</div>

Hi,

I have an issue when I tried to parse a date string to a date fiel with a different timezone, below the info

--- Filter configuration

```
input {
 stdin { }
}
filter {
date {
      match => ["message", "yyyy-MM-dd HH:mm:ss"]
      target => "justtime"
     }
ruby {
       init => 'require "time"'
       code => ' event.set("newtime", Time.parse(event.get("justtime")).localtime("-05:00")).sfrtime("%Y-%m-%d %H:%M:%S")
               '
      }

     } # filter
output {
    stdout { codec => rubydebug }
}

```

---- Execution command

```
$ echo '2019-04-17 15:00:01' | /usr/share/logstash/bin/logstash -r -f "/usr/share/logstash/ruby-logstash.conf"

```

----- output  
[ERROR] 2019-05-09 10:40:40.036 [[main]\>worker1] ruby - Ruby exception occurred: undefined method `gsub!' for 2019-04-17T22:00:01.000Z:LogStash::Timestamp  
{  
"@version" =\> "1",  
"@timestamp" =\> 2019-05-09T17:40:39.252Z,  
"host" =\> "localhost.localdomain",  
"message" =\> "2019-04-17 15:00:01",  
"justtime" =\> 2019-04-17T22:00:01.000Z,  
"tags" =\> [  
[0] "\_rubyexception"  
]  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2019, 6:21pm UTC](https://discuss.elastic.co/t/undefined-method-gsub-when-executes-a-ruby-filter-to-change-timezone/180420/2 "2019-05-09T18:21:24Z")

</div>

Wouldn't it be easier to use the [timezone](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-timezone) option on the date filter?

Also, you are calling sftime (do you mean strftime) on whatever event.set returns, so that is a no-op.

---

<div class="post-metadata">

**Author:** ![marcogarfias](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@marcogarfias](https://discuss.elastic.co/u/marcogarfias)\
**Post date:** [May 9, 2019, 8:18pm UTC](https://discuss.elastic.co/t/undefined-method-gsub-when-executes-a-ruby-filter-to-change-timezone/180420/3 "2019-05-09T20:18:00Z")

</div>

Hi Badger,

I tried to use "timezone" in Date filter, my issue is that the input date is already in GMT and I need this value with my localtime to extract the "hour of day" and "day of week".

I mean the opposite function, I read other topics where it says the only way is using Ruby code to do that.

> [@Convert utc format to local time](https://discuss.elastic.co/t/convert-utc-format-to-local-time/164237/3):
>
> thank you. I have tried as your said. Athough no exception happens, the 'snapTime' filed still retainutc format rather than my local time zone. The filter as follows: filter{ ruby{ init =\> 'require "time"' code =\> "event.set('snapTime',Time.parse(event.get('snapTime')).localtime('+08:00'))" } } The rubydebug stdout as follows: { "snapTime" =\> 2019-01-10T02:39:12.000Z, "@version" =\> "1", "@timestamp" =\> 2019-01-15T07:22:59.390Z, "name" =\> "wangqh" } the field 'snapTime' st…

> <https://stackoverflow.com/questions/29302444/convert-timestamp-timezone-in-logstash-for-output-index-name>

Thanks for any advise

PD. I fixed the functions 'stfrtime' and I have the same error

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2019, 9:14pm UTC](https://discuss.elastic.co/t/undefined-method-gsub-when-executes-a-ruby-filter-to-change-timezone/180420/4 "2019-05-09T21:14:13Z")

</div>

I am unable to reproduce the issue, but this

```
input { generator { count => 1 lines => ['2018-11-02 14:31:01'] } }

filter {
    date {
        match => ["message", "yyyy-MM-dd HH:mm:ss"]
        target => "justtime"
    }
    ruby {
        init => 'require "time"'
        code => '
            t = event.get("justtime").to_s
            event.set("newtime", Time.parse(t).localtime("-07:00").strftime("%Y-%m-%d %H:%M:%S"))
        '
    }
}

```

produces

```
   "newtime" => "2018-11-02 11:31:01",
  "justtime" => 2018-11-02T18:31:01.000Z
```

---

<div class="post-metadata">

**Author:** ![marcogarfias](https://avatars.discourse-cdn.com/v4/letter/m/3ec8ea/32.png) [@marcogarfias](https://discuss.elastic.co/u/marcogarfias)\
**Post date:** [May 14, 2019, 9:04pm UTC](https://discuss.elastic.co/t/undefined-method-gsub-when-executes-a-ruby-filter-to-change-timezone/180420/5 "2019-05-14T21:04:54Z")

</div>

Thanks Badger,

It works, but I need to clarify to other people that checks this post using an example with ("-12:00") as parameter in Ruby code (I'm in Mexico and this post was wrote in May 14, 2019 at 16:00:01 localtime )

```
   "message" => "2019-05-14 21:00:01", --- Datetime GMT/UTC in my log file
"@timestamp" => 2019-05-14T21:00:45.406Z, --- Datetime right now in UTC/GMT
  "justtime" => 2019-05-15T04:00:01.000Z, --- "message" moved 7 hours to the future, Logstash is trying to put in GMT/UTC according their rules
   "newtime" => "2019-05-14 16:00:01", --- "Justtime" less 12 hours to be in my localtime
      "host" => "localhost.localdomain",
  "@version" => "1",
  "sequence" => 0
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2019, 9:04pm UTC](https://discuss.elastic.co/t/undefined-method-gsub-when-executes-a-ruby-filter-to-change-timezone/180420/6 "2019-06-11T21:04:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
