# How to remove event with "'\<nil\>'" value on an IP type field

**URL:** <https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273>\
**Category:** Logstash\
**Created:** [May 9, 2022, 4:41pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273 "2022-05-09T16:41:58Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thuunder7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thuunder7/32/97482_2.png) [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Post date:** [May 9, 2022, 4:41pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273/1 "2022-05-09T16:41:59Z")

</div>

Hello,

I am trying to drop events every time the field [dns.resolved\_ip] is ''. I have tried multiple approachs but without successs.

> "reason"=\>"failed to parse field [dns.resolved\_ip] of type [ip] in document with id 'G5mrqYABOI1CdVDindTb'. Preview of field's value: ''", "caused\_by"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"'' is not an IP string literal."

Two filters i tried to use:

```auto
filter {
    if [agent][type] == "packetbeat" {
        if ![dns][resolved_ip] {
           drop{}
        }
    }
}

```

and i also have tried:

```auto
filter {
    if [agent][type] == "packetbeat" {
        if [dns][resolved_ip] == "<nil>" { #i also tried with "'<nil>'"
           drop{}
        }
    }
}

```

Do you have any guesses?  
Thank you,

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [May 9, 2022, 5:32pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273/2 "2022-05-09T17:32:25Z")

</div>

`Preview of field's value: ''"` says the value is `''` not `<nil>`.

Try just `if [dns][resolved_ip] == ""` to match that value.

---

<div class="post-metadata">

**Author:** ![Thuunder7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thuunder7/32/97482_2.png) [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Post date:** [May 9, 2022, 5:47pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273/3 "2022-05-09T17:47:30Z")

</div>

I don't know why but i probably deleted the correct logstash log.

```auto
Preview of field's value: '<nil>'", "caused_by"=>{"type"=>"illegal_argument_exception", "reason"=>"'<nil>' is not an IP string literal."

```

The above log is the correct one.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [May 9, 2022, 6:08pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273/4 "2022-05-09T18:08:42Z")

</div>

What you have is correct.

Maybe the `if [agent][type] == "packetbeat"` condition isn't being met?

```auto
input {
  generator {
    lines => ['{ "msg": "<nil>" }']
    count => 1
    codec => json
  }
}
filter {
  if [msg] == "<nil>" {
    mutate { add_tag => "condition met" }
  }

}
output {
  stdout { codec => "json_lines" }
}

```

**Output**

```auto
{
    "msg": "<nil>",
    "@timestamp": "2022-05-09T18:07:02.875Z",
    "tags": [
        "condition met"
    ]
}

```

---

<div class="post-metadata">

**Author:** ![Thuunder7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thuunder7/32/97482_2.png) [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Post date:** [May 9, 2022, 6:29pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273/5 "2022-05-09T18:29:49Z")

</div>

The condition `if [agent][type] == "packetbeat"` is being met, since i have a remove\_fields and it is working. I can see the documents being indexed on elastic without the fields i removed.  
Like this:

```auto
filter {
    if [agent][type] == "packetbeat" {
        if [dns][resolved_ip] == "<nil>" {
          drop {}
        }
        mutate {
           remove_field => ["[dns][additionals_count]", "[dns][opt][udp_size]"]
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2022, 7:11pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273/6 "2022-05-09T19:11:02Z")

</div>

> [@Thuunder7](#):
>
> ```auto
> if [dns][resolved_ip] == "<nil>" {
> drop {}
> }
> 
> ```

The packetbeat [documentation](https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields-ecs.html) says dns.resolved\_ip is an array. Does it work if you use this?

```
    if [dns][resolved_ip][0] == "<nil>" {

```

---

<div class="post-metadata">

**Author:** ![Thuunder7](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thuunder7/32/97482_2.png) [@Thuunder7](https://discuss.elastic.co/u/Thuunder7)\
**Post date:** [May 9, 2022, 7:45pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273/7 "2022-05-09T19:45:23Z")

</div>

Your solution seems to work! (from the time interval that i am checking the logs, they didn't appear again)  
Thank you very much for both of your answers.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 6, 2022, 7:46pm UTC](https://discuss.elastic.co/t/how-to-remove-event-with-nil-value-on-an-ip-type-field/304273/8 "2022-06-06T19:46:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
