# How to write NULL value for a field

**URL:** <https://discuss.elastic.co/t/how-to-write-null-value-for-a-field/53885>\
**Category:** Logstash\
**Created:** [June 24, 2016, 12:06pm UTC](https://discuss.elastic.co/t/how-to-write-null-value-for-a-field/53885 "2016-06-24T12:06:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![trondhindenes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trondhindenes/32/10534_2.png) [@trondhindenes](https://discuss.elastic.co/u/trondhindenes)\
**Post date:** [June 24, 2016, 12:06pm UTC](https://discuss.elastic.co/t/how-to-write-null-value-for-a-field/53885/1 "2016-06-24T12:06:07Z")

</div>

We're ingesting some logfiles where the system writes a "-" for fields without value. I'd like to replace this with a proper NULL in order to keep data as clean as possible.

I've tried mutations with the following values:  
[null]  
nil

But these only show up as strings in my log.

So: How do I properly set a field value to NULL in logstash?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2016, 8:14pm UTC](https://discuss.elastic.co/t/how-to-write-null-value-for-a-field/53885/2 "2016-06-29T20:14:32Z")

</div>

The Logstash configuration language has no notion of null. You'll have to use a ruby filter. Something like

```nohighlight
ruby {
  code => "event['name-of-field'] = nil if event['name-of-field'] == '-'"
}

```

should work

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:50am UTC](https://discuss.elastic.co/t/how-to-write-null-value-for-a-field/53885/3 "2017-07-06T04:50:19Z")

</div>


