# Wrong ruby code

**URL:** https://discuss.elastic.co/t/wrong-ruby-code/103546
**Category:** Logstash
**Created:** [October 11, 2017, 12:47pm UTC](https://discuss.elastic.co/t/wrong-ruby-code/103546 "2017-10-11T12:47:27Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ssasporta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ssasporta/32/13695_2.png) [@ssasporta](https://discuss.elastic.co/u/ssasporta)
#### Post date: [October 11, 2017, 12:47pm UTC](https://discuss.elastic.co/t/wrong-ruby-code/103546/1 "2017-10-11T12:47:27Z")

</div>

```
ruby {
                      # isolate the server name from the "source" field
                      # adding the field 'inputserver'
                      code => 'event.set("inputserver", event.get("source.split('/', -1)[4]"))'
                }

```

My logstash failing during initialization.

What is wrong with my ruby deceleration?

I am trying to split the source filed, which contains a 'path' , get the fourth parameter in the array, and put it in new field named inputserver.

The error in the logstash log is:

#event.set("inputserver", event.get("source").downcase)\n code =\> 'servername=@source.split('", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:50:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:145:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:286:in `create_pipeline'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:95:in`register\_pipeline'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:274:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:67:in`run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:185:in `run'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:132:in`run'", "/usr/share/logstash/lib/bootstrap/environment.rb:71:in `(root)'"]}  
[2017-10-11T15:33:06,102][DEBUG][logstash.agent] starting agent

Thanks  
Sharon.

---

<div class="post-metadata">

### Author: ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)
#### Post date: [October 11, 2017, 12:56pm UTC](https://discuss.elastic.co/t/wrong-ruby-code/103546/2 "2017-10-11T12:56:46Z")

</div>

The error is because of wrong enclosing quotes. The first single quote in _split_ actually terminates the whole code in the parser since it also opens with a single quote. To be safe, either use double quotes for the whole code block enclosure and single quotes inside the code or vice-versa.

Also:

1. Your function chaining is wrong, you should think of the whole _event.get('fieldname')_ as a single variable (so the split function should be applied to it instead of the fieldname inside the get).
2. The _-1_ part in the split is not needed for the desired result you describe, and the index should be _3_ instead of _4_ since index starts at _0_.

The correct syntax would be

```auto
ruby {
    # isolate the server name from the "source" field
    # adding the field 'inputserver'
    code => "event.set('inputserver', event.get('source').split('/')[3])"
}
```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 8, 2017, 12:56pm UTC](https://discuss.elastic.co/t/wrong-ruby-code/103546/3 "2017-11-08T12:56:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
