# Invalid FieldReference: \`\[\]\`

**URL:** <https://discuss.elastic.co/t/invalid-fieldreference/273834>\
**Category:** Logstash\
**Created:** [May 24, 2021, 2:18pm UTC](https://discuss.elastic.co/t/invalid-fieldreference/273834 "2021-05-24T14:18:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [May 24, 2021, 2:18pm UTC](https://discuss.elastic.co/t/invalid-fieldreference/273834/1 "2021-05-24T14:18:07Z")

</div>

Hi all,

i receive from logstash error this kind of error:  
:exception=\>#\<RuntimeError: Invalid FieldReference: `[]`

this pipeline transform a csv , in the line i've [] value a couple of field.  
for exaple the line can be:  
field1,field2,field3,field4  
value1,value2,[] ,"value4"

How can I handle this kind of value in the configuration?  
Tried some controls but all fails i'm going crazy.

KR

Roberto

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 24, 2021, 3:01pm UTC](https://discuss.elastic.co/t/invalid-fieldreference/273834/2 "2021-05-24T15:01:21Z")

</div>

The csv filter will [always call](https://github.com/logstash-plugins/logstash-filter-csv/blob/106bace4d0d4d2a4309a624262f4e0d3ea70244a/lib/logstash/filters/csv.rb#L156) event.set if you have told it to store that column, and event.set will always try to dereference the []. You could try using mutate+gsub to remove it before calling the csv filter.

---

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [May 25, 2021, 9:13am UTC](https://discuss.elastic.co/t/invalid-fieldreference/273834/3 "2021-05-25T09:13:46Z")

</div>

Hi Badger,

let's assume that I trim [] then i have a nil value ?  
Which is the best metod to control the nil values?

I wrote this :

```
filter {
mutate {
gsub => [
"field1", "[\[\]]", ""
]
}

```

}

```
filter{
	ruby {
  code => "
	if event.get('field1').nil?
		event.remove('[field1]')
	end
  "
	}
}
```

---

<div class="post-metadata">

**Author:** ![Roberto\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto_b/32/77615_2.png) [@Roberto\_B](https://discuss.elastic.co/u/Roberto_B)\
**Post date:** [May 25, 2021, 1:02pm UTC](https://discuss.elastic.co/t/invalid-fieldreference/273834/4 "2021-05-25T13:02:43Z")

</div>

The final solution , as mentioned by Badger remove all [] from the original message before the CSV parsing (substituting with a space) if you only trim it will not work:

```
filter {
       mutate {
                    gsub => ["message", "[\[\]]", " "]
                    }
 }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2021, 1:02pm UTC](https://discuss.elastic.co/t/invalid-fieldreference/273834/5 "2021-06-22T13:02:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
