# Event is not created for null value records

**URL:** <https://discuss.elastic.co/t/event-is-not-created-for-null-value-records/112423>\
**Category:** Logstash\
**Created:** [December 19, 2017, 11:42am UTC](https://discuss.elastic.co/t/event-is-not-created-for-null-value-records/112423 "2017-12-19T11:42:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [December 19, 2017, 11:42am UTC](https://discuss.elastic.co/t/event-is-not-created-for-null-value-records/112423/1 "2017-12-19T11:42:06Z")

</div>

Hi All

I have a json file, which is in this below format, for all the records date2 is always null.  
But in future this date2 can have the value.

Since currently date2 is having null value, because of this date2 event itself is not created.

Although i can see events with name,date1 and status but not with date2

How can i make sure date2 event is created with null values?

```
"testing" : {
						"name" : "Formal Test",
						"date1" : "05/22/2017 00:00:00 PDT",
						"date2" : null,
						"status" : "active"
					},
```

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [December 19, 2017, 6:56pm UTC](https://discuss.elastic.co/t/event-is-not-created-for-null-value-records/112423/2 "2017-12-19T18:56:44Z")

</div>

Does anyone face this problem?

Is this not supported, the documentation is not clear

> **[Dealing with Null Values | Elasticsearch: The Definitive Guide \[2.x\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/guide/current/_dealing_with_null_values.html)**

See, section : When null Means null

> When choosing a suitable null\_value, ensure the following:
> 
> It matches the field’s type. You can’t use a string null\_value in a field of type date.  
> It is different from the normal values that the field may contain, to avoid confusing real values with null values.

Eventhough i am trying to convert the null string to "", it is not working, since event itself is not getting created so there is no use of applying filter

---

<div class="post-metadata">

**Author:** ![rkhapre](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rkhapre/32/48333_2.png) [@rkhapre](https://discuss.elastic.co/u/rkhapre)\
**Post date:** [December 21, 2017, 6:32am UTC](https://discuss.elastic.co/t/event-is-not-created-for-null-value-records/112423/3 "2017-12-21T06:32:32Z")

</div>

Hi All

Anyone have idea on this subject?

---

<div class="post-metadata">

**Author:** ![arisbanach](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@arisbanach](https://discuss.elastic.co/u/arisbanach)\
**Post date:** [December 27, 2017, 2:52pm UTC](https://discuss.elastic.co/t/event-is-not-created-for-null-value-records/112423/4 "2017-12-27T14:52:14Z")

</div>

I could be wrong but I think from my own testing I've found that if a field that is either an object or a date then it can't be null or empty. My workaround is to check `if ![field]` and then remove it or set some non-null value.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2018, 2:52pm UTC](https://discuss.elastic.co/t/event-is-not-created-for-null-value-records/112423/5 "2018-01-24T14:52:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
