# Using Arithmetic in pipeline.yml Processor

**URL:** <https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 16, 2023, 11:34am UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725 "2023-02-16T11:34:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![fbaer](https://avatars.discourse-cdn.com/v4/letter/f/34f0e0/32.png) [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Post date:** [February 16, 2023, 11:34am UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725/1 "2023-02-16T11:34:02Z")

</div>

Hello,  
I'm appointed to update or rewriting an old ELK project. In the old version we used Logstash and its corresponding 'filebeat.cfg' file. I was rebuilding an IngestPipeline in a 'pipeline.yml'. In Losgtash we had filters and in pipeline i got processors. They are kinda similar and i was able to adjust almost everything but i've encountered one problem.

With filebeat filters we had the filter "ruby" available, in processors i don't.

This would be the ruby call from the old project:

```auto
 ruby {
            code => 'event.set("[monitor][heap][pct]", event.get("[monitor][heap][pct]").to_f * 0.01)'
            id => "MONITOR_RUBY_SCALE_HEAP_PCT"
        }

```

The main thing i want to solve here is this arithmetical operation. I got the field monitor.heap.pct which is mapped as float inside 'fields.yml' and now i just want to divide it by 100 resp. multiply it with 0.01.

This is a list of my available processors:

```auto
"processors": [
          {
            "type": "append"
          },
          {
            "type": "attachment"
          },
          {
            "type": "bytes"
          },
          {
            "type": "circle"
          },
          {
            "type": "community_id"
          },
          {
            "type": "convert"
          },
          {
            "type": "csv"
          },
          {
            "type": "date"
          },
          {
            "type": "date_index_name"
          },
          {
            "type": "dissect"
          },
          {
            "type": "dot_expander"
          },
          {
            "type": "drop"
          },
          {
            "type": "enrich"
          },
          {
            "type": "fail"
          },
          {
            "type": "fingerprint"
          },
          {
            "type": "foreach"
          },
          {
            "type": "geoip"
          },
          {
            "type": "grok"
          },
          {
            "type": "gsub"
          },
          {
            "type": "html_strip"
          },
          {
            "type": "inference"
          },
          {
            "type": "join"
          },
          {
            "type": "json"
          },
          {
            "type": "kv"
          },
          {
            "type": "lowercase"
          },
          {
            "type": "network_direction"
          },
          {
            "type": "pipeline"
          },
          {
            "type": "registered_domain"
          },
          {
            "type": "remove"
          },
          {
            "type": "rename"
          },
          {
            "type": "script"
          },
          {
            "type": "set"
          },
          {
            "type": "set_security_user"
          },
          {
            "type": "sort"
          },
          {
            "type": "split"
          },
          {
            "type": "trim"
          },
          {
            "type": "uppercase"
          },
          {
            "type": "uri_parts"
          },
          {
            "type": "urldecode"
          },
          {
            "type": "user_agent"
          }

```

Is there any way to achieve this?

Kind regards  
Florian

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 17, 2023, 6:48pm UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725/2 "2023-02-17T18:48:48Z")

</div>

"[Script](https://www.elastic.co/guide/en/elasticsearch/reference/7.16/script-processor.html)" would be the one to try. It will default to the painless language and should be able to do the trick.

---

<div class="post-metadata">

**Author:** ![fbaer](https://avatars.discourse-cdn.com/v4/letter/f/34f0e0/32.png) [@fbaer](https://discuss.elastic.co/u/fbaer)\
**Post date:** [February 20, 2023, 9:46am UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725/3 "2023-02-20T09:46:04Z")

</div>

This kinda solves it:

```auto
  - convert:
      if: ctx.pac != null && ctx.pac.log != null && ctx.pac.log.tags != null && ctx.pac.log.tags.contains('MONITOR')
      field: pac.log.system.monitor.cpu.pct
      type: float

  - script:
      if: ctx.pac != null && ctx.pac.log != null && ctx.pac.log.tags != null && ctx.pac.log.tags.contains('MONITOR')
      description: formatting pct for dashboards
      lang: painless
      source: ctx.pac.log.system.monitor.cpu.pct = ctx.pac.log.system.monitor.cpu.pct / 100

```

But why do i have to convert the fields type with the 'convert' processor at all when i configured my field as 'float' within fields.yml?  
If i don't i get a script\_exception caused by a runtime\_error because a type conversion exception because he assumes ctx.pac.log.system.monitor.cpu.pct is a 'String'. And i assume a cast for my field would do it also, but i would like not to use any of this because it's configured as 'float'.

Kind Regards

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [February 20, 2023, 6:11pm UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725/4 "2023-02-20T18:11:52Z")

</div>

Nice, glad you got it working. I'm not sure why you have to convert it to a float, but the index is logically distinct from the painless scripting language. I wouldn't worry about the resource usage of converting to the float for now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2023, 8:11pm UTC](https://discuss.elastic.co/t/using-arithmetic-in-pipeline-yml-processor/325725/5 "2023-03-20T20:11:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
