# Ruby exception occurred: undefined method \`split' for nil:NilClass

**URL:** <https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352>\
**Category:** Logstash\
**Created:** [June 25, 2019, 1:47pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352 "2019-06-25T13:47:57Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![monika](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monika/32/99606_2.png) [@monika](https://discuss.elastic.co/u/monika)\
**Post date:** [June 25, 2019, 1:47pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/1 "2019-06-25T13:47:57Z")

</div>

This is my config for logstash (filter file )

filter {  
if "ETL\_log\_enriched" in [tags] {  
grok {  
match =\> {  
"message" =\> "%{TIMESTAMP\_ISO8601:log\_timestamp} (%{LOGLEVEL:loglevel}|%{WORD:loglevel}) (?[^]]+)- %{GREEDYDATA:msgbody}"  
}  
}  
mutate  
{  
add\_field =\> ["event\_read\_time", "%{@timestamp}"]  
}  
date {  
match =\> ["log\_timestamp", "yyyy-MM-dd HH:mm:ss"]  
}  
grok {  
match =\> {  
"msgbody" =\> "(?\<log\_category\>\w+(?=--\>))"  
}  
}  
grok{  
match =\> {  
"msgbody" =\> "(?\<log\_value\>(?\<=--\>)(.+))"  
}  
}  
grok{  
match =\> {  
"msgbody" =\> "(?\<Loggable\_Message\>(?\<=ETL -)(.+))"  
}  
}

```
    if [log_category] == "KPI" or [log_category] == "EXCEPTION" {
        ruby {
            code => "
                log_value=event.get('log_value')
                entities=log_value.split('||',5)
                event.set('appName',entities[0])
                event.set('repoName',entities[1])
                event.set('resource_name',entities[2])
                event.set('resource_type',entities[3])
                kpi_list_string=entities[4]
                kpi_list_string[0]=''
                kpi_list_string[kpi_list_string.length-1]=''
                kpi_list=kpi_list_string.split('||')
                kpi_list.each do |kv_pair|
                    key=kv_pair.split(':',2)[0]
                    value=kv_pair.split(':',2)[1]
                    is_integer=value.match(/\A[+-]?\d+?(\.\d+)?\Z/) == nil ? false : true
                    if(is_integer==true)
                        value = value.to_i
                    end
                    event.set(key,value)
                end
            "
        }

    } 
    else if [log_category] == "STATUS"{
        ruby {
            code => "
                log_value=event.get('log_value')
                entities=log_value.split('||',4)
                event.set('appName',entities[0])
                event.set('repoName',entities[1])
                event.set('resource_name',entities[2])
                event.set('resource_status',entities[3])
            "
        }
    else if [loglevel] == "KPI" or [loglevel] == "ERROR" or [loglevel] == "INFO" {
    if [Loggable_Message] != "" {
        ruby {
            code => "
                Loggable_Message=event.get('Loggable_Message')
                entities=Loggable_Message.split('||',3)
                event.set('appName',entities[1])
                event.set('repoName',entities[0])
                kpi_list_string=entities[2]
                kpi_list_string[0]=''
                kpi_list_string[kpi_list_string.length-1]=''
                kpi_list=kpi_list_string.split('||')
                kpi_list.each do |kv_pair|
                    key=kv_pair.split(':',2)[0]
                    value=kv_pair.split(':',2)[1]
                    is_integer=value.match(/\A[+-]?\d+?(\.\d+)?\Z/) == nil ? false : true
                    if(is_integer==true)
                        value = value.to_i
                    end
                    event.set(key,value)
                end
            "
           }
       }
    }
    mutate {
        remove_field => ["log_value","msgbody","Loggable_Message]
    }

}

```

}

Input (logs)  
2019-06-24 14:54:20 INFO etl - KPI--\>Spark ETL Pipeline For Unstructured Repo||PANGAEA||classification/PANGAEA/056050050048056056046065069065071078065080:PANGAEA.json||STORE||(timeTakenToStoreInS3:85)  
2019-06-24 14:54:20 KPI ETL - effr||Spark ETL Pipeline For Unstructured Repo||ResourceType:PIPE||pipeName:storeClassification||run\_time:96||containerS3Key:pangaea/2019-03-06/PANGAEA.880228/

I am getting Ruby exception occurred: undefined method `split' for nil:NilClass.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2019, 2:27pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/2 "2019-06-25T14:27:07Z")

</div>

I get compilation errors for that configuration. Please post the configuration that actually gets a ruby error. Select the configuration and click on \</\> in the toolbar above the edit pane so that it is block quoted, and verify in the preview pane that what is displayed matches your configuration.

---

<div class="post-metadata">

**Author:** ![monika](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monika/32/99606_2.png) [@monika](https://discuss.elastic.co/u/monika)\
**Post date:** [June 25, 2019, 2:31pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/3 "2019-06-25T14:31:22Z")

</div>

```
filter {
if "ETL_log_enriched" in [tags] {
    grok {
    match => {
    "message" => "%{TIMESTAMP_ISO8601:log_timestamp} (%{LOGLEVEL:loglevel}|%{WORD:loglevel}) (?<classname>[^\]]+)- %{GREEDYDATA:msgbody}"
        }
    }
    mutate
    {
        add_field => ["event_read_time", "%{@timestamp}"]
    }
    date {
            match => ["log_timestamp", "yyyy-MM-dd HH:mm:ss"]
            }
    grok {
    match => {
    "msgbody" => "(?<log_category>\w+(?=-->))"
        }
    }
    grok{
        match => {
        "msgbody" => "(?<log_value>(?<=-->)(.+))"
        }
    }
    grok{
        match => {  
        "msgbody" => "(?<Loggable_Message>(?<=ETL -)(.+))"
        }
    }

    if [log_category] == "KPI" or [log_category] == "EXCEPTION" {
        ruby {
            code => "
                log_value=event.get('log_value')
                entities=log_value.split('||',5)
                event.set('appName',entities[0])
                event.set('repoName',entities[1])
                event.set('resource_name',entities[2])
                event.set('resource_type',entities[3])
                kpi_list_string=entities[4]
                kpi_list_string[0]=''
                kpi_list_string[kpi_list_string.length-1]=''
                kpi_list=kpi_list_string.split('||')
                kpi_list.each do |kv_pair|
                    key=kv_pair.split(':',2)[0]
                    value=kv_pair.split(':',2)[1]
                    is_integer=value.match(/\A[+-]?\d+?(\.\d+)?\Z/) == nil ? false : true
                    if(is_integer==true)
                        value = value.to_i
                    end
                    event.set(key,value)
                end
            "
        }

    } 
    else if [log_category] == "STATUS"{
        ruby {
            code => "
                log_value=event.get('log_value')
                entities=log_value.split('||',4)
                event.set('appName',entities[0])
                event.set('repoName',entities[1])
                event.set('resource_name',entities[2])
                event.set('resource_status',entities[3])
            "
        }
}
    else if [loglevel] == "KPI" or [loglevel] == "ERROR" or [loglevel] == "INFO" {
    if [Loggable_Message] != "" {
        ruby {
            code => "
                Loggable_Message=event.get('Loggable_Message')
                entities=Loggable_Message.split('||',3)
                event.set('appName',entities[1])
                event.set('repoName',entities[0])
                kpi_list_string=entities[2]
                kpi_list=kpi_list_string.split('||')
                kpi_list.each do |kv_pair|
                    key=kv_pair.split(':',2)[0]
                    value=kv_pair.split(':',2)[1]
                    is_integer=value.match(/\A[+-]?\d+?(\.\d+)?\Z/) == nil ? false : true
                    if(is_integer==true)
                        value = value.to_i
                    end
                    event.set(key,value)
                end
            "
           }
       }
    }
    mutate {
        remove_field => ["log_value","msgbody","Loggable_Message"]
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [June 25, 2019, 2:56pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/4 "2019-06-25T14:56:08Z")

</div>

I've encountered NilClass errors when the field doesn't have contents. It seems without content, it doesn't "type" it, so it can't use the method.

---

<div class="post-metadata">

**Author:** ![monika](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monika/32/99606_2.png) [@monika](https://discuss.elastic.co/u/monika)\
**Post date:** [June 25, 2019, 2:59pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/5 "2019-06-25T14:59:50Z")

</div>

@rugenl how can we check if a field has value or not ?

i.e if [Loggable\_Message] != ""

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2019, 3:35pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/6 "2019-06-25T15:35:46Z")

</div>

The first message gets a \_grokparsefailure, but not a \_rubyexception. The second one gets both a \_grokparsefailure and a \_rubyexception. It has [loglevel] == "KPI" so the ruby filter does a split on [Loggable\_Message], but that field does not exist.

I would always check that fetched fields exist in the ruby filter

```
        code => "
            Loggable_Message=event.get('Loggable_Message')
            if Loggable_Message
                entities=Loggable_Message.split('||',3)
                 [...]
            end
        "

```

If you want to test it in the filter section then the way to do that is

```
if [Loggable_Message] {

```

Your test does not work since nil is not equal to "".

Lastly, object names that start with a capital letter, like Loggable\_Message are used for constants in ruby. It will likely produce warnings and confuse other people if you use that.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2019, 4:08pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/8 "2019-06-25T16:08:19Z")

</div>

OK, so you are doing a positive lookbehind assertion in order to grab whatever follows "ETL -". That would work if you were matching against [message], but [msgbody] has already had that stripped off.

Also, a positive lookbehind is rather obscure. It would be simpler to do

```
grok { match => { "message" => "ETL - %{GREEDYDATA:loggableMessage}" } }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2019, 10:15pm UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/11 "2019-06-25T22:15:41Z")

</div>

> [@monika](#):
>
> What do think abt this config file now

Does it do what you want? If not, what do you want to change?

---

<div class="post-metadata">

**Author:** ![monika](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monika/32/99606_2.png) [@monika](https://discuss.elastic.co/u/monika)\
**Post date:** [June 26, 2019, 9:12am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/13 "2019-06-26T09:12:56Z")

</div>

I am getting \_grokparsefailure

26 09:04:14 ip-10-95-36-47 logstash: [2] "\_grokparsefailure"

---

<div class="post-metadata">

**Author:** ![monika](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monika/32/99606_2.png) [@monika](https://discuss.elastic.co/u/monika)\
**Post date:** [June 26, 2019, 11:16am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/14 "2019-06-26T11:16:16Z")

</div>

Thanks Guys!!!

Now it is working fine

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 11:16am UTC](https://discuss.elastic.co/t/ruby-exception-occurred-undefined-method-split-for-nil-nilclass/187352/15 "2019-07-24T11:16:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
