# Mutate+copy of @timestamp gets NullPointerException

**URL:** <https://discuss.elastic.co/t/mutate-copy-of-timestamp-gets-nullpointerexception/135033>\
**Category:** Logstash\
**Created:** [June 7, 2018, 5:20pm UTC](https://discuss.elastic.co/t/mutate-copy-of-timestamp-gets-nullpointerexception/135033 "2018-06-07T17:20:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2018, 5:20pm UTC](https://discuss.elastic.co/t/mutate-copy-of-timestamp-gets-nullpointerexception/135033/1 "2018-06-07T17:20:18Z")

</div>

In 6.2.4, when I try to do a mutate+copy of @timestamp it blows up with a NullPointerException. Is there another way to do this?

```
input { generator { message => '2018/05/11 12:34:56' count => 1 } }
filter {
    date { match => ["message", "yyyy/MM/dd HH:mm:ss"] }
    mutate { copy => { "@timestamp" => "foo" } }
}
output { stdout { codec => rubydebug } }

```

The top of the stack trace looks like this:

```auto
Exception in thread "Ruby-0-Thread-14@[main]>worker0: /usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:385" java.lang.NullPointerException
        at org.logstash.ext.JrubyTimestampExtLibrary$RubyTimestamp.ruby_to_iso8601(JrubyTimestampExtLibrary.java:112)
        at org.logstash.ext.JrubyTimestampExtLibrary$RubyTimestamp.ruby_inspect(JrubyTimestampExtLibrary.java:106)
        at org.logstash.ext.JrubyTimestampExtLibrary$RubyTimestamp$INVOKER$i$0$0$ruby_inspect.call(JrubyTimestampExtLibrary$RubyTimestamp$INVOKER$i$0$0$ruby_inspect.gen)
        at org.jruby.runtime.callsite.CachingCallSite.cacheAndCall(CachingCallSite.java:318)

```

Replacing the rubydebug output with an elasticsearch output gets you "An unknown error occurred sending a bulk request to Elasticsearch" instead.

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [June 13, 2018, 10:54pm UTC](https://discuss.elastic.co/t/mutate-copy-of-timestamp-gets-nullpointerexception/135033/2 "2018-06-13T22:54:25Z")

</div>

It looks like this was a bug.  
[https://github.com/elastic/logstash/issues/8888](https://github.com/elastic/logstash/issues/8888) and fix: [https://github.com/elastic/logstash/pull/9405](https://github.com/elastic/logstash/pull/9405)

I reproduced this on 6.2.4 and verified it is indeed fixed in 6.3.0 (released today)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2018, 10:54pm UTC](https://discuss.elastic.co/t/mutate-copy-of-timestamp-gets-nullpointerexception/135033/3 "2018-07-11T22:54:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
