# Use script in Logstash

**URL:** <https://discuss.elastic.co/t/use-script-in-logstash/121004>\
**Category:** Logstash\
**Created:** [February 22, 2018, 7:59am UTC](https://discuss.elastic.co/t/use-script-in-logstash/121004 "2018-02-22T07:59:47Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adren/32/27681_2.png) [@Adren](https://discuss.elastic.co/u/Adren)\
**Post date:** [February 22, 2018, 7:59am UTC](https://discuss.elastic.co/t/use-script-in-logstash/121004/1 "2018-02-22T07:59:48Z")

</div>

Hello,

I have a question, can we use a script in Logstash pipeline? I found that we can use ruby code in the pipeline but can we use another language or maybe execute the script file we want ?

This is the pipeline I want to use:

```
input {
  udp {
   	port => 514
   	type => "syslog"
	} 
}
filter {
    grok {
      match => { "message" => "<%{NUMBER:sev}>%{GREEDYDATA:kvlist}" }
    }
    kv {
      source => "kvlist"
      remove_field => ["kvlist"]
    }
}
output {
      elasticsearch {
        	hosts => ["localhost:9200"]
   	     	user => elastic
       		password => elasticlourd
          index => "syslog-%{+YYYY.MM.dd}"
          }
      #stdout { codec => rubydebug }
}

```

the "sev" field is the information I need for the script, can I give it to my script and then the script write the result in a variable created in logstash?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2018, 8:05am UTC](https://discuss.elastic.co/t/use-script-in-logstash/121004/2 "2018-02-22T08:05:43Z")

</div>

There's no generic "run script" filter but you can run a script from within a ruby filter.

---

<div class="post-metadata">

**Author:** ![Adren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adren/32/27681_2.png) [@Adren](https://discuss.elastic.co/u/Adren)\
**Post date:** [February 22, 2018, 9:25am UTC](https://discuss.elastic.co/t/use-script-in-logstash/121004/3 "2018-02-22T09:25:21Z")

</div>

Ok then, so if I need to get the field "sev" I created in the conf file in my ruby code, do I need to do this:  
`log = event.get("sev").value`  
and if I want to create a new field for the logs do I need to do this :  
`event.set("log description", var)`  
?  
Regards.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2018, 9:38am UTC](https://discuss.elastic.co/t/use-script-in-logstash/121004/4 "2018-02-22T09:38:03Z")

</div>

No need for `.value` but otherwise correct.

---

<div class="post-metadata">

**Author:** ![Adren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adren/32/27681_2.png) [@Adren](https://discuss.elastic.co/u/Adren)\
**Post date:** [February 22, 2018, 9:38am UTC](https://discuss.elastic.co/t/use-script-in-logstash/121004/5 "2018-02-22T09:38:58Z")

</div>

I'll test that, thank you.

---

<div class="post-metadata">

**Author:** ![Adren](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adren/32/27681_2.png) [@Adren](https://discuss.elastic.co/u/Adren)\
**Post date:** [February 28, 2018, 3:45pm UTC](https://discuss.elastic.co/t/use-script-in-logstash/121004/6 "2018-02-28T15:45:03Z")

</div>

It's me again, I used this configuration of Logstash and it was working until now, I don't know what changed, but when I use the script in the conf file it doesn't sent logs to elasticsearch, but when I take it away, it works. With the plugin "ruby" in, it says an error like this  
Ruby exception occurred: no implicit conversion of nil into String

my conf file:

```
input {
  udp {
   	port => 5514
   	type => "syslog"
	} 
}
filter {
    grok {
      match => { "message" => "<%{NUMBER:sev}>%{GREEDYDATA:kvlist}" }
    }
    kv {
      source => "kvlist"
      remove_field => ["kvlist"]
    }
    ruby{
      code => 'category = ["0 Kern",
                "1 user",
                "2 mail",
                "3 daemon",
                "4 auth",
                "5 syslog",
                "6 lpr",
                "7 news",
                "8 uucp",
                "9 clock daemon",
                "10 authpriv",
                "11 FTP",
                "12 NTP system",
                "13 log audit",
                "14 log alert",
                "15 cron",
                "16 local0",
                "17 local1",
                "18 local2",
                "19 local3",
                "20 local4",
                "21 local5",
                "22 local6",
                "23 local7"]
gravity = [
                  "0 Emergency",
                  "1 Alert",
                  "2 Critical",
                  "3 Error",
                  "4 Warning",
                  "5 Notice",
                  "6 Informational",
                  "7 Debugging"]
$log = event.get("sev")
$temp = $log.to_i
$i = 0
$y = 0
while ((($i+1)*8)<$temp) do 
  $i+=1 
end 
while (($i * 8) + ($y+1) != $temp) do 
  $y+=1
end
$message = category[$i] + " " + gravity[$y]
event.set("log description", $message)
'
    }
}
output {
      elasticsearch {
        	hosts => ["localhost:9200"]
   	     	user => elastic
       		password => elasticlourd
          index => "syslog-%{+YYYY.MM.dd}"
          }
      stdout { codec => rubydebug }
}

```

I have no idea what could be wrong because it worked until now ..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2018, 3:45pm UTC](https://discuss.elastic.co/t/use-script-in-logstash/121004/7 "2018-03-28T15:45:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
