# Nil Class error crashing pipeline

**URL:** <https://discuss.elastic.co/t/nil-class-error-crashing-pipeline/43684>\
**Category:** Logstash\
**Created:** [March 7, 2016, 5:31pm UTC](https://discuss.elastic.co/t/nil-class-error-crashing-pipeline/43684 "2016-03-07T17:31:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bwgriffith](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bwgriffith/32/7695_2.png) [@bwgriffith](https://discuss.elastic.co/u/bwgriffith)\
**Post date:** [March 7, 2016, 5:31pm UTC](https://discuss.elastic.co/t/nil-class-error-crashing-pipeline/43684/1 "2016-03-07T17:31:40Z")

</div>

I started getting this error today with some new code I put into logstash. I'm having trouble tracking it down. Would appreciate any help on where to start.

The error:  
NoMethodError: undefined method `strip' for nil:NilClass  
filter at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-xml-2.0.2/lib/logstash/filters/xml.rb:94  
multi\_filter at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.0-java/lib/logstash/filters/base.rb:151  
each at org/jruby/RubyArray.java:1613  
multi\_filter at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.0-java/lib/logstash/filters/base.rb:148  
cond\_func\_71 at (eval):2134  
each at org/jruby/RubyArray.java:1613  
cond\_func\_71 at (eval):2129  
filter\_func at (eval):820  
filterworker at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.0-java/lib/logstash/pipeline.rb:243  
start\_filters at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.1.0-java/lib/logstash/pipeline.rb:177

```
if "activity" in [tags] {

    # adjust timezone
    date{
        match => ["requesttime_epoch", "ISO8601", "UNIX_MS"]
        timezone => "America/New_York"
        #locale => "en"
        target => requesttime
        remove_field => ["requesttime_epoch"]
    }

    date{
        match => ["responsetime_epoch", "ISO8601", "UNIX_MS"]
        timezone => "America/New_York"
        #locale => "en"
        target => responsetime
        remove_field => ["responsetime_epoch"]
    }

      # xml parsing - XPATH to be implemented
    xml{
        # Parse XML field
        source => "request"
        target => "parsed"
        add_tag => ["xml_parsed"]
        xpath => [
        "namespace-uri(/*)", "MessageNamespace",
        "concat(//Context/Id, substring('', 1 div not(//Context/Id/text())))", "MessageContextID",
        "concat(/*[local-name()='Request']/Parameter/Session/UserHeaderAgent, substring('', 1 div not(/*[local-name()='Request']/Parameter/Session/UserHeaderAgent/text())))", "UserHeaderAgent",
        "concat(/*[local-name()='Request']/Parameter/Session/Id, substring('', 1 div not(/*[local-name()='Request']/Parameter/Session/Id/text())))", "SessionID",
        "concat(/*[local-name()='Request']/Parameter/Session/IpAddress, substring('', 1 div not(/*[local-name()='Request']/Parameter/Session/IpAddress/text())))", "IpAddress",
        "concat(//Context/Source, substring('', 1 div not(//Context/Source/text())))", "RequestSource"
        ]
        store_xml => false
      }

    grok{
        match => {"MessageNamespace" => "^(?:[^\/]*\/){3}(?<OperationFqn>(?<OperationCategory>\S+?)\/(?<OperationName>\w+)\/(?<OperationVersion>[\d\/]+?))\/{0,1}$"}

    }

      # Geo IP
    if [IpAddress]{
        geoip {
            source => "IpAddress"
            database => "/opt/logstash/vendor/geoip/GeoLiteCity.dat"
            target => "geoip"
            # add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
            # add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
        }
      }

    ruby {
        code => "event['index_day'] = event['responsetime'].time.localtime.strftime('%Y.%m.%d')"

    }

```

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2016, 6:21pm UTC](https://discuss.elastic.co/t/nil-class-error-crashing-pipeline/43684/2 "2016-03-07T18:21:30Z")

</div>

The `request` field wasn't set for this event. Starting with version 2.1.1 of the xml filter you'll get a decent error message instead of the stack trace above (see [PR #21](https://github.com/logstash-plugins/logstash-filter-xml/pull/21)).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:08am UTC](https://discuss.elastic.co/t/nil-class-error-crashing-pipeline/43684/3 "2017-07-06T05:08:09Z")

</div>


