# Logstash / Protobuf plugin, removing oneOf fields that aren't set (are null)

**URL:** <https://discuss.elastic.co/t/logstash-protobuf-plugin-removing-oneof-fields-that-arent-set-are-null/271994>\
**Category:** Logstash\
**Created:** [May 3, 2021, 1:48pm UTC](https://discuss.elastic.co/t/logstash-protobuf-plugin-removing-oneof-fields-that-arent-set-are-null/271994 "2021-05-03T13:48:43Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![SCollins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/scollins/32/77761_2.png) [@SCollins](https://discuss.elastic.co/u/SCollins)\
**Post date:** [May 3, 2021, 1:48pm UTC](https://discuss.elastic.co/t/logstash-protobuf-plugin-removing-oneof-fields-that-arent-set-are-null/271994/1 "2021-05-03T13:48:43Z")

</div>

I'm using the logstash protobuf plugin as a mechanism to read protobuf from kafka, convert it from protobuf and write it to elasticsearch. The problem we are having is, the oneOf fields, despite being null/not set in the incoming protobuf payload, the plugin seems to set the field and assign value, for floats, a default value of 0.0. This highly undesired. We would like to the ingestion to not include any oneOf fields that are null/not set.

I've tried a few different things such as, in the pipeline .config:

```auto
    if event.get('myField_oneof').nil? 
              event.remove('myField') 
    end

```

That doesn't work, it's always nil for some reason.

Neither does this:

```auto
    if event.get('myField').nil? 
              event.remove('myField') 
    end

```

By the time this ruby code is ran, the value is already set to 0.0.

Any ideas?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2021, 1:49pm UTC](https://discuss.elastic.co/t/logstash-protobuf-plugin-removing-oneof-fields-that-arent-set-are-null/271994/2 "2021-05-31T13:49:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
