# Ruby exception occurred: undefined method '\[\]' for nil:NilClass when filtering csv

**URL:** <https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass-when-filtering-csv/231893>\
**Category:** Logstash\
**Created:** [May 10, 2020, 5:09pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass-when-filtering-csv/231893 "2020-05-10T17:09:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![eeijlar](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Post date:** [May 10, 2020, 5:09pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass-when-filtering-csv/231893/1 "2020-05-10T17:09:31Z")

</div>

I can't figure out why this filter is throwing this error:

`Ruby exception occurred: undefined method [] for nil:NilClass`

I have added a check anytime ruby could have thrown an exception:

```
filter {
        ruby { code => 'event.set("[@metadata][fields]", 1 + event.get("message").count(","))' }
            if [tags] !~ "_rubyexception" {
                if [@metadata][fields] == 29 {
                csv {
                    separator => ","
                    columns => [ "ACTION","DISCRIMINATOR","CHECKPOINT_ID","INSTALLATION_ID","NUMERIC_VALUE","STRING_VALUE","COMPONENT_NAME","TRANSACTION_ID","STATISTIC_DURATION","STATISTIC_NAME","ASSOCIATED_NAME","SINGLE_LATENCY",
                                    "AVERAGE_LATENCY","MAX_LATENCY","MIN_LATENCY","TPS","MAX_LATENCY_TRANSACTION_ID","CREATED_ON_DATE","TOTAL_TRANSACTIONS","PROCESS_NAME","SLA1","SLA2","EXCEPTION_COUNT","CATEGORY","P95","P99","P999",
                                    "P9999","P99999" ]
                    }
                }

                if [@metadata][fields] == 24 {
                    csv {
                        separator => ","
                        columns => [ "ACTION","DISCRIMINATOR","CHECKPOINT_ID","INSTALLATION_ID","NUMERIC_VALUE","STRING_VALUE","COMPONENT_NAME","TRANSACTION_ID","STATISTIC_DURATION","STATISTIC_NAME","ASSOCIATED_NAME","SINGLE_LATENCY",
                                        "AVERAGE_LATENCY","MAX_LATENCY","MIN_LATENCY","TPS","MAX_LATENCY_TRANSACTION_ID","CREATED_ON_DATE","TOTAL_TRANSACTIONS","PROCESS_NAME","SLA1","SLA2","EXCEPTION_COUNT","CATEGORY" ]
                    }
                }

                if [tags] !~ "_csvparsefailure" {
                        ruby { code => "event.set('FW_DATE',Time.at(event.get('CREATED_ON_DATE')[0..9].to_i).strftime('%Y.%m.%d'))" }
                        if [tags] !~ "_rubyexception" {
                            mutate {
                                remove_field => ["ACTION","DISCRIMINATOR","CHECKPOINT_ID","STRING_VALUE","P95","P99","P999","P9999","P99999"]
                                gsub => [
                                    "ASSOCIATED_NAME", "\"", "",
                                    "COMPONENT_NAME", "\"", "",
                                    "STATISTIC_NAME", "\"", "",
                                    "INSTALLATION_ID", "\"", "",
                                    "PROCESS_NAME", "[\",]", "",
                                    "PROCESS_NAME", "^[0-9]*", ""
                                ]
                                convert => {
                                    "CREATED_ON_DATE" => "integer"
                                    "NUMERIC_VALUE" => "integer"
                                    "STATISTIC_DURATION" => "integer"
                                    "SINGLE_LATENCY" => "integer"
                                    "AVERAGE_LATENCY" => "integer"
                                    "MAX_LATENCY" => "integer"
                                    "MIN_LATENCY" => "integer"
                                    "TPS" => "integer"
                                    "TOTAL_TRANSACTIONS" => "integer"
                                    "SLA1" => "integer"
                                    "SLA2" => "integer"
                                    "EXCEPTION_COUNT" => "integer"
                                }
                                replace => {
                                    "INSTALLATION_ID" => "%{[host][name]}"
                                }
                            }
                            date {
                                match => ["CREATED_ON_DATE", "UNIX_MS"]
                                target => "@timestamp"
                            }
                        }
                }
            }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 10, 2020, 5:46pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass-when-filtering-csv/231893/2 "2020-05-10T17:46:03Z")

</div>

> [@eeijlar](#):
>
> if [tags] !~ "\_rubyexception"

The normal way to test this is

```
if "_rubyexception" not in [tags]

```

The only way I can see you getting `"[undefined method ‘[]’ for nil:NilClass"` from that configuration is if the event does not have a CREATED\_ON\_DATE field.

---

<div class="post-metadata">

**Author:** ![eeijlar](https://avatars.discourse-cdn.com/v4/letter/e/96bed5/32.png) [@eeijlar](https://discuss.elastic.co/u/eeijlar)\
**Post date:** [May 10, 2020, 7:43pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass-when-filtering-csv/231893/3 "2020-05-10T19:43:28Z")

</div>

Thank you that worked perfectly!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2020, 7:54pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-for-nil-nilclass-when-filtering-csv/231893/4 "2020-06-07T19:54:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
