# Undefined method \`accept' for nil:NilClass

**URL:** <https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226>\
**Category:** Logstash\
**Created:** [November 1, 2023, 5:48pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226 "2023-11-01T17:48:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jsamuel](https://avatars.discourse-cdn.com/v4/letter/j/ac8455/32.png) [@jsamuel](https://discuss.elastic.co/u/jsamuel)\
**Post date:** [November 1, 2023, 5:48pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226/1 "2023-11-01T17:48:38Z")

</div>

At present, we are operating several instances of Elasticsearch, encompassing both 5.x and 6.x versions, and are in the process of assessing the viability of OpenSearch. However, it is imperative to maintain the current configurations of Filebeat and Logstash unaltered. In alignment with this requirement, we have deployed version 7.16.2 of Logstash. Subsequent to this update, we have observed a proliferation of errors, specifically `undefined method 'accept' for nil:NilClass`, which were not encountered in preceding versions. The root cause of this anomaly is currently ambiguous and the methodology to rectify it remains elusive. Moreover, the issue manifests in the cessation of log reception from the application servers over time, necessitating a manual restart to reinitiate the log transmission pipeline.

Please advise.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2023, 5:48pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226/2 "2023-11-01T17:48:38Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 1, 2023, 7:20pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226/3 "2023-11-01T19:20:22Z")

</div>

Hello,

Opensearch is not supported here, but if you think that your issue is in any Logstash filter you need to share both the configuration you are using, the error you are getting and also a sample of your data so the issue can be replicated.

It is not clear where this error is happening, you need to provide more context about it.

---

<div class="post-metadata">

**Author:** ![jsamuel](https://avatars.discourse-cdn.com/v4/letter/j/ac8455/32.png) [@jsamuel](https://discuss.elastic.co/u/jsamuel)\
**Post date:** [November 2, 2023, 12:50pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226/4 "2023-11-02T12:50:49Z")

</div>

This is the same filters that is used on all the versions in our environments:

```auto

filter {
  mutate {
    remove_tag => ["beats_input_codec_plain_applied","beats_input_raw_event"]
  }
}

# Certain fields are known to be strings but occasionally get interpreted as integers, this will convert their type appropriately.
filter {
  mutate {
    convert => {
        '[body][hid]' => 'string'
        '[body][id]' => 'string'
    }
  }
}

# If we find DOBs in MM/DD/YYYY format, rewrite them to
# YYYY-MM-DD and save the original
filter {
    ruby {
      code => "
        require 'date'
        dobstr = event.get('[body][dob]')
        if dobstr
          begin
          dob = Date.strptime(dobstr, '%m/%d/%Y')
          dobISO = dob.strftime('%Y-%m-%d')
          event.set('[body][dob]', dobISO)
          event.set('[originalDOB]', dobstr)
          rescue
          end
        end
      "
    }
}

filter {
  grok {
    match => ["message", "%{TIMESTAMP_ISO8601:timestamp} %{IP:source} %{WORD:method} %{URIPATH:uripath} (?:-|%{NOTSPACE:uriquery}) %{POSINT:port} (?:-|%{NOTSPACE:username}) %{IP:clientip} %{NOTSPACE:useragent} %{URI:url} %{NUMBER:status}"]
    tag_on_failure => []
  }
}

filter {
  grok {
    match => ["message", "%{IPORHOST:clientip} (?:-|(%{WORD}.%{WORD})) %{USER:ident} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{QS:referrer} %{QS:agent}"]
    tag_on_failure => []
  }
}

# TS-13526 When err.response.body is a string it is converted to an object with a single field named source that contains the value. This matches the shape of object logged by services that log user-agent as an object.
filter {
  ruby {
    code => "
      agent = event.get('[user-agent]')
      if agent && agent.is_a?(String)
        event.set('[user-agent]', {'source' => agent})
      end
    "
  }
}

# TS-13568 When err.response.body is a string it is converted to an object with a single field named @text that contains the value.
filter {
  ruby {
    code => "
      body = event.get('[err][response][body]')
      if body && body.is_a?(String)
        event.set('[err][response][body]', {'@text' => body})
      end
    "
  }
}

# TS-13647 When err.request.body is a string it is converted to an object with a single field named @text that contains the value.
filter {
  ruby {
    code => "
      body = event.get('[err][request][body]')
      if body && body.is_a?(String)
        event.set('[err][request][body]', {'@text' => body})
      end
    "
  }
}

# TS-13586 When body.result is a string it is converted to an object with a single field named @text that contains the value.
filter {
  ruby {
    code => "
      bodyResult = event.get('[body][result]')
      if bodyResult && bodyResult.is_a?(String)
        event.set('[body][result]', {'@text' => bodyResult})
      end
    "
  }
}

# TS-13583 body.availability is converted to an object with a single field named @json that contains the JSON representation of the original value.
filter {
  ruby {
    code => "
      require 'json'
      bodyAvailability = event.get('[body][availability]')
      if bodyAvailability
        event.set('[body][availability]', {'@json' => JSON.generate(bodyAvailability)})
      end
    "
  }
}

```

since we have microservices, there are many servers that has the same filebeat configuration

```auto
- type: log
  tags: ["catapultapps"]  
  paths:
    - /catapult/apps/*/current/log/*.log
  json.keys_under_root: true
  json.add_error_key: false
  json.message_key: log
  fields:
    index_name: catapultapps  

```

Below is one sample of the error:

```auto
[2023-11-02T00:00:25,302][INFO][org.logstash.beats.BeatsHandler][main][b735a5d7382cd510fb08d026e77b3c72851aeff150c96ea727a0bc0962ca0134] [local: 10.108.12.16:5044, remote: 10.108.28.32:38018] Handling exception: org.logstash.FieldReference$IllegalSyntaxException: Invalid FieldReference: `vendors[]` (caused by: org.logstash.FieldReference$IllegalSyntaxException: Invalid FieldReference: `vendors[]`)
[2023-11-02T00:00:25,302][WARN][io.netty.channel.DefaultChannelPipeline][main][b735a5d7382cd510fb08d026e77b3c72851aeff150c96ea727a0bc0962ca0134] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
org.logstash.FieldReference$IllegalSyntaxException: Invalid FieldReference: `vendors[]`

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 2, 2023, 1:23pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226/5 "2023-11-02T13:23:53Z")

</div>

> [@jsamuel](#):
>
> ```auto
> [2023-11-02T00:00:25,302][INFO][org.logstash.beats.BeatsHandler][main][b735a5d7382cd510fb08d026e77b3c72851aeff150c96ea727a0bc0962ca0134] [local: 10.108.12.16:5044, remote: 10.108.28.32:38018] Handling exception: org.logstash.FieldReference$IllegalSyntaxException: Invalid FieldReference: `vendors[]` (caused by: org.logstash.FieldReference$IllegalSyntaxException: Invalid FieldReference: `vendors[]`)
> [2023-11-02T00:00:25,302][WARN][io.netty.channel.DefaultChannelPipeline][main][b735a5d7382cd510fb08d026e77b3c72851aeff150c96ea727a0bc0962ca0134] An exceptionCaught() event was fired, and it reached at the tail of the pipeline. It usually means the last handler in the pipeline did not handle the exception.
> org.logstash.FieldReference$IllegalSyntaxException: Invalid FieldReference: `vendors[]`
> 
> ```

This is a common issue, if I'm not wrong this was changed [here](https://github.com/elastic/logstash/pull/9543).

On Logstash 7 this was mentioned as a [breaking change](https://www.elastic.co/guide/en/logstash/current/breaking-7.0.html#field-ref-strict), saying that this is not configurable anymore and only the mode `strict` works, and on Logstash 8 another [breaking change](https://www.elastic.co/guide/en/logstash/current/breaking-8.0.html#bc-field-ref-parser) says that the setting was removed, since it only had one option.

I'm not sure if there is anything you can do on Logstash side to solve this, this field named is not valid for Logstash, it needs to be fixed in the source.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2023, 1:24pm UTC](https://discuss.elastic.co/t/undefined-method-accept-for-nil-nilclass/346226/6 "2023-11-30T13:24:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
