# Null error with greater-than comparison on an integer field

**URL:** <https://discuss.elastic.co/t/null-error-with-greater-than-comparison-on-an-integer-field/194313>\
**Category:** Logstash\
**Created:** [August 7, 2019, 6:54pm UTC](https://discuss.elastic.co/t/null-error-with-greater-than-comparison-on-an-integer-field/194313 "2019-08-07T18:54:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![datawrangler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datawrangler/32/50256_2.png) [@datawrangler](https://discuss.elastic.co/u/datawrangler)\
**Post date:** [August 7, 2019, 6:54pm UTC](https://discuss.elastic.co/t/null-error-with-greater-than-comparison-on-an-integer-field/194313/1 "2019-08-07T18:54:50Z")

</div>

Hello All,  
I am getting an error which suggests that my if-statement is trying to do a \> (greater-than) expression comparison against a null value. When I comment out the if-statement everything works as expected.  
Here is the

```
filter {
 if [netflow][fw_ext_event] != '' {

   mutate { convert => {"[netflow][fw_ext_event]" => "integer" }}

   ######## This does not work######
   #if [netflow][fw_ext_event] > 2000 {
   # mutate { add_field => { "netflow.fw_ext_event_name" => "flowDeleted"} }
   #}
   ########

   if [netflow][fw_ext_event] == 1001 {
   #} else if [netflow][fw_ext_event] == 1001 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedByIngressACL"} }
   } else if [netflow][fw_ext_event] == 1002 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedByEgressACL"} }
   } else if [netflow][fw_ext_event] == 1003 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedICMP"} }
   } else if [netflow][fw_ext_event] == 1004 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedNonSYNPacket"} }
   }

 }
}

```

Here is the error message:  
java.lang.NullPointerException: null

```
[ERROR][org.logstash.execution.WorkerLoop] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash.
java.lang.NullPointerException: null

```

netflow.fw\_ext\_event is an integer, but I still convert it to an integer as a test to validate that I am not doing a greater-than comparison against a text field.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3fa6f8d0b82dcb3d24cc6f1e16e171948f445b3c.png)

Can anyone please provide some insight into why I am getting the null error?  
Thank you!!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 7, 2019, 8:45pm UTC](https://discuss.elastic.co/t/null-error-with-greater-than-comparison-on-an-integer-field/194313/2 "2019-08-07T20:45:24Z")

</div>

I think the problem is that the field [netflow][fw\_ext\_event] does not exist. I notice that when you add the name you use a period in the name and do not add a field to the netflow object. Should you be referring to netflow.fw\_ext\_event?

```
if [netflow][fw_ext_event] != '' {

```

If the field does not exist then the left hand side is nil, which is not equal to an empty string. The normal way to test for existence is just

```
if [netflow][fw_ext_event] {
```

---

<div class="post-metadata">

**Author:** ![datawrangler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datawrangler/32/50256_2.png) [@datawrangler](https://discuss.elastic.co/u/datawrangler)\
**Post date:** [August 9, 2019, 1:53pm UTC](https://discuss.elastic.co/t/null-error-with-greater-than-comparison-on-an-integer-field/194313/3 "2019-08-09T13:53:03Z")

</div>

Thank you. That worked, here is my full filter, for reference:

```
if [netflow][fw_ext_event] {

   if [netflow][fw_ext_event] >= 2000 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "flowDeleted"} }
   } else if [netflow][fw_ext_event] == 1001 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedByIngressACL"} }
   } else if [netflow][fw_ext_event] == 1002 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedByEgressACL"} }
   } else if [netflow][fw_ext_event] == 1003 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedICMP"} }
   } else if [netflow][fw_ext_event] == 1004 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedNonSYNPacket"} }
   }

}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 9, 2019, 2:25pm UTC](https://discuss.elastic.co/t/null-error-with-greater-than-comparison-on-an-integer-field/194313/4 "2019-08-09T14:25:15Z")

</div>

You might consider replacing the four == tests with a [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter. With four tests if else is OK, but if it gets bigger I would definitely consider using translate.

---

<div class="post-metadata">

**Author:** ![datawrangler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datawrangler/32/50256_2.png) [@datawrangler](https://discuss.elastic.co/u/datawrangler)\
**Post date:** [August 15, 2019, 6:21pm UTC](https://discuss.elastic.co/t/null-error-with-greater-than-comparison-on-an-integer-field/194313/5 "2019-08-15T18:21:06Z")

</div>

I replaced this:

```
if [netflow][fw_ext_event] {
   if [netflow][fw_ext_event] >= 2000 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "flowDeleted"} }
   } else if [netflow][fw_ext_event] == 1001 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedByIngressACL"} }
   } else if [netflow][fw_ext_event] == 1002 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedByEgressACL"} }
   } else if [netflow][fw_ext_event] == 1003 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedICMP"} }
   } else if [netflow][fw_ext_event] == 1004 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "deniedNonSYNPacket"} }
   }
 }

```

With this:

```
if [netflow][fw_ext_event] {
   if [netflow][fw_ext_event] >= 2000 {
     mutate { add_field => { "netflow.fw_ext_event_name" => "flowDeleted"} }
   } else {
      translate {
         #field => "netflow.fw_ext_event"
         field => "[netflow][fw_ext_event]"
         #destination => "netflow.fw_ext_event_name"
         destination => "[netflow][fw_ext_event_name]"
         dictionary => {
               #"0" => "undefined(0)"
               "1001" => "deniedByIngressACL"
               "1002" => "deniedByEgressACL"
               "1003" => "deniedICMP"
               "1004" => "deniedNonSYNPacket"
             }
         #fallback => "UNKNOWN(%{[netflow][fw_ext_event]})"
      }
   }
}

```

Thank you for your guidance! Cheers!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2019, 6:21pm UTC](https://discuss.elastic.co/t/null-error-with-greater-than-comparison-on-an-integer-field/194313/6 "2019-09-12T18:21:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
