# \[Logstash\] \<Java::JavaUtil::ArrayList:31 \[nil\]\> on json with \[null\]

**URL:** <https://discuss.elastic.co/t/logstash-java-31-nil-on-json-with-null/282382>\
**Category:** Logstash\
**Created:** [August 24, 2021, 4:05pm UTC](https://discuss.elastic.co/t/logstash-java-31-nil-on-json-with-null/282382 "2021-08-24T16:05:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![zenkovac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zenkovac/32/93645_2.png) [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Post date:** [August 24, 2021, 4:05pm UTC](https://discuss.elastic.co/t/logstash-java-31-nil-on-json-with-null/282382/1 "2021-08-24T16:05:03Z")

</div>

hi, i'm experiencing an error when processing a json log which has a [null] value on a field.

■The log is the following (tested as valid json):

```auto
{"message":{"errorMessage":"INTERNAL_SERVER_ERROR","errorDetail":{"message":"Request failed with status code 500","name":"Error","stack":"xxx","config":{"url":"xxx","method":"post","data":"xxx","headers":{"Accept":"application/json, text/plain, */*","Content-Type":"application/json;charset=utf-8","User-Agent":"xxx","Content-Length":123},"field1":[null],"field2":[null],"requestStartedAt":1629355057329}}},"level":"error","version":"123","timestamp":"2021-08-19T06:37:41.658Z"}

```

■my filebeat config looks like this:

```auto
- type: log
  paths:
    - /tmp/file.log
  fields_under_root: true
  json.keys_under_root: true
  json.add_error_key: true
  enabled: true

output.logstash:
  hosts: ["127.0.0.1:5044"]

```

■my logstash config which i reduced to the minimum to debug

```auto
input {
    beats {
        port => 5044
    }
}
output {
    file {
        path => "/tmp/output.log"
        codec => rubydebug
  }
}

```

■content of /tmp/output.log

```auto
{
     "timestamp" => "2021-08-19T06:37:41.658Z",
          "tags" => [
        [0] "beats_input_codec_plain_applied"
    ],
       "version" => "123",
    "@timestamp" => 2021-08-24T15:02:22.594Z,
      "@version" => "1",
         "level" => "error",
       "message" => "{\"errorMessage\"=>\"INTERNAL_SERVER_ERROR\", \"errorDetail\"=>{\"config\"=>{\"field2\"=><Java::JavaUtil::ArrayList:31 [nil]>, \"requestStartedAt\"=>1629355057329, \"url\"=>\"xxx\", \"method\"=>\"post\", \"data\"=>\"xxx\", \"headers\"=>{\"User-Agent\"=>\"xxx\", \"Content-Length\"=>123, \"Accept\"=>\"application/json, text/plain, */*\", \"Content-Type\"=>\"application/json;charset=utf-8\"}, \"field1\"=><Java::JavaUtil::ArrayList:31 [nil]>}, \"message\"=>\"Request failed with status code 500\", \"name\"=>\"Error\", \"stack\"=>\"xxx\"}}"
}

```

As you can see i'm getting the [null] value translated to \<Java::JavaUtil::ArrayList:31 [nil]\>.  
I validated that the java error is being introduced by logstash.  
Using stack 7.8.0

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 24, 2021, 5:11pm UTC](https://discuss.elastic.co/t/logstash-java-31-nil-on-json-with-null/282382/2 "2021-08-24T17:11:40Z")

</div>

Definitely looks like a bug to me. With 7.14.0, if you use

```auto
processors:
  - decode_json_fields:
      fields: ["message"]
      process_array: true
      target: ""

```

then you get an array containing nil, as expected

```
       "foo" => [
    [0] nil
],
   "message" => "{ \"foo\": [null] }",

```

If you remove the target option, so that [message] is overwritten, then you get

```
   "message" => "{\"foo\"=><Java::JavaUtil::ArrayList:31 [nil]>}",
```

---

<div class="post-metadata">

**Author:** ![zenkovac](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zenkovac/32/93645_2.png) [@zenkovac](https://discuss.elastic.co/u/zenkovac)\
**Post date:** [August 24, 2021, 6:14pm UTC](https://discuss.elastic.co/t/logstash-java-31-nil-on-json-with-null/282382/3 "2021-08-24T18:14:51Z")

</div>

Thanks badger, I reported it in github:

> <https://github.com/elastic/logstash/issues/13165>
>
> hi, i'm experiencing an error when processing a json log which has a \[null\] valu…e on a field.
> 
> ■The log is the following (tested as valid json):
> {"message":{"errorMessage":"INTERNAL\_SERVER\_ERROR","errorDetail":{"message":"Request failed with status code 500","name":"Error","stack":"xxx","config":{"url":"xxx","method":"post","data":"xxx","headers":{"Accept":"application/json, text/plain, \*/\*","Content-Type":"application/json;charset=utf-8","User-Agent":"xxx","Content-Length":123},"field1":\[null\],"field2":\[null\],"requestStartedAt":1629355057329}}},"level":"error","version":"123","timestamp":"2021-08-19T06:37:41.658Z"}
> 
> ■my filebeat config looks like this:
> \- type: log
> paths:
> - /tmp/file.log
> fields\_under\_root: true
> json.keys\_under\_root: true
> json.add\_error\_key: true
> enabled: true
> 
> output.logstash:
> hosts: \["127.0.0.1:5044"\]
> 
> ■my logstash config which i reduced to the minimum to debug
> input {
> beats {
> port =\> 5044
> }
> }
> output {
> file {
> path =\> "/tmp/output.log"
> codec =\> rubydebug
> }
> }
> ■content of /tmp/output.log
> {
> "timestamp" =\> "2021-08-19T06:37:41.658Z",
> "tags" =\> \[
> \[0\] "beats\_input\_codec\_plain\_applied"
> \],
> "version" =\> "123",
> "@timestamp" =\> 2021-08-24T15:02:22.594Z,
> "@version" =\> "1",
> "level" =\> "error",
> "message" =\> "{\\"errorMessage\\"=\>\\"INTERNAL\_SERVER\_ERROR\\", \\"errorDetail\\"=\>{\\"config\\"=\>{\\"field2\\"=\>\<Java::JavaUtil::ArrayList:31 \[nil\]\>, \\"requestStartedAt\\"=\>1629355057329, \\"url\\"=\>\\"xxx\\", \\"method\\"=\>\\"post\\", \\"data\\"=\>\\"xxx\\", \\"headers\\"=\>{\\"User-Agent\\"=\>\\"xxx\\", \\"Content-Length\\"=\>123, \\"Accept\\"=\>\\"application/json, text/plain, \*/\*\\", \\"Content-Type\\"=\>\\"application/json;charset=utf-8\\"}, \\"field1\\"=\>\<Java::JavaUtil::ArrayList:31 \[nil\]\>}, \\"message\\"=\>\\"Request failed with status code 500\\", \\"name\\"=\>\\"Error\\", \\"stack\\"=\>\\"xxx\\"}}"
> }
> 
> As you can see i'm getting the \[null\] value translated to \<Java::JavaUtil::ArrayList:31 \[nil\]\>.
> I validated that the java error is being introduced by logstash.
> Using stack 7.8.0

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2021, 6:15pm UTC](https://discuss.elastic.co/t/logstash-java-31-nil-on-json-with-null/282382/4 "2021-09-21T18:15:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
