# Use ruby filter decode base64 field cannot replace oldfields

**URL:** <https://discuss.elastic.co/t/use-ruby-filter-decode-base64-field-cannot-replace-oldfields/113315>\
**Category:** Logstash\
**Created:** [December 27, 2017, 12:30pm UTC](https://discuss.elastic.co/t/use-ruby-filter-decode-base64-field-cannot-replace-oldfields/113315 "2017-12-27T12:30:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuki\_Tsao](https://avatars.discourse-cdn.com/v4/letter/y/45deac/32.png) [@yuki\_Tsao](https://discuss.elastic.co/u/yuki_Tsao)\
**Post date:** [December 27, 2017, 12:30pm UTC](https://discuss.elastic.co/t/use-ruby-filter-decode-base64-field-cannot-replace-oldfields/113315/1 "2017-12-27T12:30:11Z")

</div>

I have a k,v pairs, some of them was base64 encoded.  
like this

```
"requestMsg" => {
            "userInfo" => "eyJ1c2VySWQiOiIxNTIyMjY3NTY5NCIsInR5cGUiOiIxIn0=",
              "random" => "462091",
              "originalType" => "1",
              "serial" => "475192",
             "appInfo" => "eyJhcHBJZCI6IjE1NThjN2NkMjgzNWI2Njk2ODE1NmZiZTRkNGZjZGI4ZjZkMWZjM2IiLCJzaWduIjoiNzc5MDkzOTQ2IiwiaGFzaCI6IjE3MGFjNTBjZTNiMDNkNmM0MDdkNzdhYzczNTQ4MDFlIiwic2RrVmVyc2lvbiI6IjEuMCJ9",             
             "devInfo" => "eyJpbWVpIjoiODY2NTkyMDMyMTU1NTMyJjg2NjU5MjAzMjIzMDQxOCIsImVxdWlwbWVudE1vZGVsIjoiU1RGLUFMMTAiLCJjcHVBYmkiOiJhcm1lYWJpLXY3YSIsImNwdUNvdW50Ijo4LCJkZXZfdHlwZSI6IkFuZHJvaWQiLCJwaG9uZV9udW0iOiIiLCJzeXN0ZW1fdmVyc2lvbiI6IjcuMCIsIm1hbnVmYWN0dXJlciI6IkhPTk9SIiwicmlza0luZm8iOnsicm9vdCI6IjAiLCJob29rIjoiMCJ9LCJjb25mVmVyc2lvbiI6IjIwIn0=",
              "header" => "eyJvcCI6InpyYXV0aC5hcHAuYnVzaW5lc3MucmFuZG9tLmRlY3J5cHRpb24iLCJ1cHYiOnsibWFqb3IiOiIzIiwibWlub3IiOiIwIn19",
             "appCode" => "1002",
            "sotpRandom" => "569316"
    }

```

I want use Ruby plugin to loop the nested k,v pairs and decode the certain fields,Finally, the decoded value all in the right place. like this:

```
            "requestMsg" => {
            "userInfo" => "{"userId":"15222675694","type":"1"}",
             .....
             .....
              "header" => "{\"op\":\"zrauth.app.business.random.decryption\",\"upv\":{\"major\":\"3\",\"minor\":\"0\"}}",
          "sotpRandom" => "569316"
    }

```

but I use the ruby code：

```
ruby {
    init => "require 'base64'"
    code => "
        tobase64fields = ['userInfo','appInfo','devInfo','header']
        fieldArray = event.get('[msg][requestMsg]')
        fieldArray.each{|k,v| if tobase64fields.include?k then event.set('[msg][requestMsg][k]', 
Base64.decode64(v)) end }
    "
} 

```

but it cannot work , it will have the result like this:

```
"requestMsg" => {
           ......
            "k" => "{\"op\":\"zrauth.app.business.random.decryption\",\"upv\":{\"major\":\"3\",\"minor\":\"0\"}}",
          .......
          .......
    },

```

the field name is "K"? what's wrong with it ? thx all !

---

<div class="post-metadata">

**Author:** ![yuki\_Tsao](https://avatars.discourse-cdn.com/v4/letter/y/45deac/32.png) [@yuki\_Tsao](https://discuss.elastic.co/u/yuki_Tsao)\
**Post date:** [December 29, 2017, 3:35am UTC](https://discuss.elastic.co/t/use-ruby-filter-decode-base64-field-cannot-replace-oldfields/113315/2 "2017-12-29T03:35:37Z")

</div>

I almostly solved this question, the Ruby code change to this:

```
ruby {
    init => "require 'base64'"
    code => "
        tobase64fields = ['userInfo','appInfo','devInfo','header']
        fieldArray = event.get('[msg][requestMsg]')
        fieldArray.each{|k,v| if tobase64fields.include?k then event.set('[msg][requestMsg]' + k, Base64.decode64(v)) end }
    "
}

```

the nested field name follows the "+k", it can point the certain fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2018, 3:36am UTC](https://discuss.elastic.co/t/use-ruby-filter-decode-base64-field-cannot-replace-oldfields/113315/3 "2018-01-26T03:36:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
