# Unexpected tCONSTANT in Ruby Script

**URL:** <https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709>\
**Category:** Logstash\
**Created:** [November 8, 2023, 1:42pm UTC](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709 "2023-11-08T13:42:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kris\_Felscher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_felscher/32/125461_2.png) [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Post date:** [November 8, 2023, 1:42pm UTC](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709/1 "2023-11-08T13:42:30Z")

</div>

We have a ton (200+) of applications that are all logging to the same index. Because of this, we are seeing a few field type collisions that cause messages to get bounced (to the tune of approximately 26 million bounced events per day).

I put together a quick ruby script in our main processing pipeline to handle these fields:

```auto
ruby {
    code => '
        fields = ["container", "destination", "host", "process", "source", "url", "user"]

        fields.each { |f|
            if event.include? f && event.get(f).is_a? String
                event.set(f + "_val", event.get(f))
                event.remove(f)
            end
        }
    '
}

```

However, I'm getting the error:

```auto
(ruby filter code):6: syntax error, unexpected tCONSTANT\n...f && event.get(f).is_a? String\r\n

```

I'm sure this is something simple, but the black-box that is developing and debugging logstash pipelines has made it difficult for me, as I have a limited grasp of Ruby.

Can someone help out?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 8, 2023, 4:22pm UTC](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709/2 "2023-11-08T16:22:16Z")

</div>

> [@Kris\_Felscher](#):
>
> ```auto
> if event.include? f && event.get(f).is_a? String
> event.set(f + "_val", event.get(f))
> event.remove(f)
> end
> 
> ```

Try

```
        if event.include? f and event.get(f).is_a? String
            event.set(f + "_val", event.remove(f))
        end

```

---

<div class="post-metadata">

**Author:** ![Kris\_Felscher](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kris_felscher/32/125461_2.png) [@Kris\_Felscher](https://discuss.elastic.co/u/Kris_Felscher)\
**Post date:** [November 8, 2023, 5:42pm UTC](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709/3 "2023-11-08T17:42:01Z")

</div>

That worked! You are my hero

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 6, 2023, 5:42pm UTC](https://discuss.elastic.co/t/unexpected-tconstant-in-ruby-script/346709/4 "2023-12-06T17:42:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
