# Less than or equal not working logstash filter and crashing

**URL:** <https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729>\
**Category:** Logstash\
**Created:** [September 9, 2021, 4:29am UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729 "2021-09-09T04:29:37Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 9, 2021, 4:29am UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/1 "2021-09-09T04:29:37Z")

</div>

Hi Team,

I'm shipping logs from windows servers using filebeat. I have created a field which shows the reponse time in milliseconds.  
I have created a field "Create\_Indexing\_response\_time\_ms" using grok and it works perfectly when I run logstash and the field is getting created in ES  
However when I give the less than condition and mutate to create another field, I get the below error (pasted in the next reply)

```auto
input {
  beats {
    port => 5044
  }
}
filter
{
if [fields][logtype] == "Seal_Async_Logs"
{
grok {
   match => { "message" => ".*\[TIME]Indexing took: %{NUMBER:Create_Indexing_response_time_ms:int}"}
}
}
if [fields][logtype] == "Seal_Async_Logs" and [Create_Indexing_response_time_ms] < 2000 {
	mutate { add_field => { "Indexing_Time_taken" => "less than 2 seconds"}}
}
output {
  elasticsearch {
    hosts => ["http://10.150.59.17:9200"]
    index => "filebeat.test-%{+YYYY.MM}" 
  }
}

```

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 9, 2021, 4:30am UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/2 "2021-09-09T04:30:07Z")

</div>

[ERROR][logstash.javapipeline][main] Pipeline worker error, the pipeline will be stopped {:pipeline\_id=\>"main", :error=\>"", :exception=\>Java::JavaLang::NullPointerException, :backtrace=\>["org.logstash.config.ir.compiler.EventCondition$Compiler$UnexpectedTypeException.(EventCondition.java:679)", "org.logstash.config.ir.compiler.EventCondition$Compiler.compare(EventCondition.java:453)", "org.logstash.config.ir.compiler.EventCondition$Compiler.lambda$compareFieldToConstant$11(EventCondition.java:444)", "org.logstash.config.ir.compiler.Utils.filterEvents(Utils.java:47)", "org.logstash.generated.CompiledDataset3.compute(Unknown Source)", "org.logstash.generated.CompiledDataset2.compute(Unknown Source)", "org.logstash.generated.CompiledDataset4.compute(Unknown Source)", "org.logstash.config.ir.CompiledPipeline$CompiledU

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 9, 2021, 4:30am UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/3 "2021-09-09T04:30:47Z")

</div>

Please note that I have already converted the type to integer using the grok and I get the field as "Number" in elasticsearch

Kindly help pls

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 9, 2021, 3:29pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/4 "2021-09-09T15:29:08Z")

</div>

See the answer [here](https://discuss.elastic.co/t/comparing-number-in-conditionnal-event-treatement/217043/5).

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 13, 2021, 6:08am UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/5 "2021-09-13T06:08:12Z")

</div>

Thanks @Badger but I already have the field created and the type reflects as "Number" so ideally logstash should not throw the exception when trying for a greater than expression.

Am I doing anything wrong ? Is it because I converted the type to integer using Grok instead of Mutate ? kindly help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 13, 2021, 5:15pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/6 "2021-09-13T17:15:05Z")

</div>

As I said, you will get that exception with that stack trace if the field does not exist. If you get a \_grokparsefailure then logstash will crash.

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 14, 2021, 12:53pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/7 "2021-09-14T12:53:08Z")

</div>

Thanks @Badger I find its weird that Im getting the field in elasticsearch what I have defined in grok pattern and was able to get the expected results using KQL however Im not able to proceed with that field for any further actions in logstash due to \_grokparsefailure tag

this is how the field and message appears in each document

![grok1](https://us1.discourse-cdn.com/elastic/original/3X/8/8/880a0d12115346385be6eb631579efea0c06c99d.jpeg)

 ![grok2](https://us1.discourse-cdn.com/elastic/original/3X/e/3/e3d0a0ec202f93aae059757363c43ac5e9d9c85a.jpeg)

Pls help.

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 15, 2021, 2:37pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/8 "2021-09-15T14:37:31Z")

</div>

Anyone Any help on this would be great, thanks 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 15, 2021, 3:59pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/9 "2021-09-15T15:59:10Z")

</div>

That message will not match the grok pattern. There is no space between the colon and the number.

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 15, 2021, 4:56pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/10 "2021-09-15T16:56:48Z")

</div>

I changed the pattern without space and tried refreshing the index pattern

Again, the field appears with the expected value however I still get the \_grokparsefailre in the tag and due to this, im unable to use a mutate function using the same field

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 15, 2021, 5:12pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/11 "2021-09-15T17:12:58Z")

</div>

What is the setting for path.config (either on the command line or in logstash.yml)?

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 15, 2021, 5:34pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/12 "2021-09-15T17:34:30Z")

</div>

Thanks for quick reply.

I haven't done any changes to logstash.yml. Guess im using the default settings  
PFB

 ![logyml](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d13815b601446e3ed5364104611aee504c7d6756.jpeg)

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 15, 2021, 5:43pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/13 "2021-09-15T17:43:52Z")

</div>

I have placed the conf file in pipelines.yml file and run logstash as a service

below is how the conf is placed in pipelines.yml

```auto
# Available options:
#
# # name of the pipeline
   - pipeline.id: SEALlogs
     path.config: "/ELK/logstash-oss-7.10.2-windows-x86_64/logstash-7.10.2/conf.d/test.conf"

```

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 15, 2021, 5:45pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/14 "2021-09-15T17:45:16Z")

</div>

Is there anything that I need to add in path.config in logstash.yml ? pls help

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 15, 2021, 6:07pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/15 "2021-09-15T18:07:36Z")

</div>

What exactly is the error message that you get with that configuration?

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 15, 2021, 6:11pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/16 "2021-09-15T18:11:04Z")

</div>

[ERROR][logstash.javapipeline][main] Pipeline worker error, the pipeline will be stopped {:pipeline\_id=\>"main", :error=\>"", :exception=\>Java::JavaLang::NullPointerException, :backtrace=\>["org.logstash.config.ir.compiler.EventCondition$Compiler$UnexpectedTypeException.(EventCondition.java:679)", "org.logstash.config.ir.compiler.EventCondition$Compiler.compare(EventCondition.java:453)", "org.logstash.config.ir.compiler.EventCondition$Compiler.lambda$compareFieldToConstant$11(EventCondition.java:444)", "org.logstash.config.ir.compiler.Utils.filterEvents(Utils.java:47)", "org.logstash.generated.CompiledDataset3.compute(Unknown Source)", "org.logstash.generated.CompiledDataset2.compute(Unknown Source)", "org.logstash.generated.CompiledDataset4.compute(Unknown Source)",

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 15, 2021, 6:27pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/17 "2021-09-15T18:27:53Z")

</div>

OK, so you have configured a pipeline called SEALlogs and are getting the error for a pipeline called main. You are not running the configuration you think you are.

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 16, 2021, 8:48am UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/18 "2021-09-16T08:48:46Z")

</div>

I have corrected that and the I modified the grok pattern to field name in lower case and was able to get rid of the \_grokparsefailure

Also I used to mutate convert to change type to string to number however when I try the

```auto
if [indexing] < 2000 {
mutate { add_field => { "timetaken" => "2secs" } }
}

```

Im getting the same pipeline error

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 16, 2021, 8:53am UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/19 "2021-09-16T08:53:45Z")

</div>

here is the complete filter im using

```auto
filter
{
if [fields][logtype] == "Seal_Async_Logs"
{
grok {
   match => { "message" => ".*\[TIME]Indexing took:%{WORD:indexing}"}
}
}
if [fields][logtype] == "Seal_Async_Logs" {
mutate {
   convert => { "indexing" => "integer" }
}
}
if [indexing] < 2000 {
mutate { add_field => { "timetaken" => "2secs" } }
}
}

```

and below is the actual log

2021-09-16 09:59:27,799 INFO [ro.star.seal.session.archive.impl.DocumentServiceBean] (default task-22) [TIME]Indexing took:63 ms

---

<div class="post-metadata">

**Author:** ![Shaiju\_Sam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaiju_sam/32/86283_2.png) [@Shaiju\_Sam](https://discuss.elastic.co/u/Shaiju_Sam)\
**Post date:** [September 16, 2021, 3:25pm UTC](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729/20 "2021-09-16T15:25:23Z")

</div>

The issue is not with grok anymore. I am getting the field created in ES as expected without \_grokparsefailure

The problem is now not being able to add field when I give \< or \> symbol however it works when I give ==

Can someone pls help if anything else to be done before giving these expressions ?

[Next page](https://discuss.elastic.co/t/less-than-or-equal-not-working-logstash-filter-and-crashing/283729.md?page=2)
