# Using a variable like an index of an array in logstash pipeline

**URL:** <https://discuss.elastic.co/t/using-a-variable-like-an-index-of-an-array-in-logstash-pipeline/233304>\
**Category:** Logstash\
**Created:** [May 19, 2020, 11:26am UTC](https://discuss.elastic.co/t/using-a-variable-like-an-index-of-an-array-in-logstash-pipeline/233304 "2020-05-19T11:26:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Md\_Iburahimsha\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/md_iburahimsha_s/32/47142_2.png) [@Md\_Iburahimsha\_S](https://discuss.elastic.co/u/Md_Iburahimsha_S)\
**Post date:** [May 19, 2020, 11:26am UTC](https://discuss.elastic.co/t/using-a-variable-like-an-index-of-an-array-in-logstash-pipeline/233304/1 "2020-05-19T11:26:50Z")

</div>

```auto
filter{

    ruby { code => 'event.set("patternmatch1", event.get("message").scan(/TEXT.*?(\w[\w,.]*)\r?$/))'
    }

    # Retrieve the length of the array containing all the matches
    ruby { code => 'event.set("number_of_elements", event.get("patternmatch4").length-1)'
    }

```

I would like to use the array length as the index of a ruby array of patterns to choose index pattern that i want. I am looking for element in last index of array

The below way is working like a charm,

```auto
mutate{
       add_field => {"gross_profit" => "%{[patternmatch4][9]}"}}
}

```

I tried this way for dynamic index,

```auto
mutate{
   add_field => {"gross_profit" => "%{[patternmatch4][%{[number_of_elements]}}"}
}

```

Simply how to use the variable which is given by ruby filter in array index.

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [May 19, 2020, 12:27pm UTC](https://discuss.elastic.co/t/using-a-variable-like-an-index-of-an-array-in-logstash-pipeline/233304/2 "2020-05-19T12:27:53Z")

</div>

Hi, it may not be possible to do this with logstash notation.

How about setting `"gross_profit"` with ruby, in the same code block you set `"number_of_elements"` ?

I guess that in ruby you can use `"patternmatch4[number_of_elements]"` or something alike.

---

<div class="post-metadata">

**Author:** ![Md\_Iburahimsha\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/md_iburahimsha_s/32/47142_2.png) [@Md\_Iburahimsha\_S](https://discuss.elastic.co/u/Md_Iburahimsha_S)\
**Post date:** [May 19, 2020, 1:34pm UTC](https://discuss.elastic.co/t/using-a-variable-like-an-index-of-an-array-in-logstash-pipeline/233304/3 "2020-05-19T13:34:34Z")

</div>

I tried, its returning exception.

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [May 19, 2020, 3:01pm UTC](https://discuss.elastic.co/t/using-a-variable-like-an-index-of-an-array-in-logstash-pipeline/233304/4 "2020-05-19T15:01:11Z")

</div>

If the field "`number_of_elements`" is only needed for getting the last element of a field named "`patternmatch4`", you can just use the `[-1]` index in Ruby instead.

That way, you only need:

```auto
ruby {
    code => 'event.set("gross_profit", event.get("patternmatch4")[-1])'
}

```

If you really need the `number_of_elements` field (which actually contains the total number - 1 to match the index of the last element of the array) , here it is another example that might serve as inspiration to work with your patterns array:

```auto
ruby{
  code => '
    number_of_elements = event.get("patternmatch4").length - 1
    event.set("number_of_elements", number_of_elements)
    event.set("gross_profit", event.get("patternmatch4")[number_of_elements])
  '
}

```

---

<div class="post-metadata">

**Author:** ![Md\_Iburahimsha\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/md_iburahimsha_s/32/47142_2.png) [@Md\_Iburahimsha\_S](https://discuss.elastic.co/u/Md_Iburahimsha_S)\
**Post date:** [May 19, 2020, 3:10pm UTC](https://discuss.elastic.co/t/using-a-variable-like-an-index-of-an-array-in-logstash-pipeline/233304/5 "2020-05-19T15:10:30Z")

</div>

> [@andres-perez](#):
>
> ruby{ code =\> ' number\_of\_elements = event.get("patternmatch4").length - 1 event.set("number\_of\_elements", number\_of\_elements) event.set("gross\_profit", event.get("patternmatch4")[number\_of\_elements]) ' }

Awesome ! Thank you so much. Both are working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2020, 3:25pm UTC](https://discuss.elastic.co/t/using-a-variable-like-an-index-of-an-array-in-logstash-pipeline/233304/6 "2020-06-16T15:25:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
