# "event was filtered" message is showing "null" instead of the name of the matching filter.

**URL:** <https://discourse.sensu.io/t/event-was-filtered-message-is-showing-null-instead-of-the-name-of-the-matching-filter/754>\
**Category:** Sensu Classic (EOL)\
**Created:** [February 1, 2017, 8:41am UTC](https://discourse.sensu.io/t/event-was-filtered-message-is-showing-null-instead-of-the-name-of-the-matching-filter/754 "2017-02-01T08:41:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fhd](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@fhd](https://discourse.sensu.io/u/fhd)\
**Post date:** [February 1, 2017, 8:41am UTC](https://discourse.sensu.io/t/event-was-filtered-message-is-showing-null-instead-of-the-name-of-the-matching-filter/754/1 "2017-02-01T08:41:51Z")

</div>

As per #1467, on v0.27 the filtered events should show the name of the matching filter.  
Currently, I’m getting ‘null’. I wonder if I’m doing something wrong? Here are my filters:

{  
“filters”: {  
“filter\_1”: {  
“negate”: false,  
“attributes”: {  
“check”: {  
“name”: “checkname1”  
},  
“occurrences”: “eval: value != 1 && value % 5 != 0”  
}  
},  
“filter\_2”: {  
“negate”: false,  
“attributes”: {  
“check”: {  
“name”: “checkname2”  
},  
“occurrences”: “eval: value != 3 && value % 6 != 0”  
}  
}  
}  
}

And the relevant log output:  
{“timestamp”:“2017-02-01T09:22:00.375020+0100”,“level”:“info”,“message”:“event was filtered”,“handler”:{“type”:“pipe”,“command”:"/etc/sensu/handlers/myhandler.rb",“filters”:[“filter\_1”,“filter\_2”],“severities”:[“critical”,“unknown”,“ok”],“name”:“myhandler”},“event”:{“client”:{…},“check”:{“handlers”:[“webapi”],“command”:“sudo /etc/sensu/plugins/checkscript1.rb”,“interval”:60,“occurrences”:5,“alias”:“checkname1”,“subscribers”:[“all”],“name”:“checkname1”,“issued”:1485937320,“executed”:1485937320,“duration”:0.102,“output”:"",“status”:2,“type”:“standard”,“history”:[“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“0”,“2”],“total\_state\_change”:11},“occurrences”:1,“occurrences\_watermark”:1,“action”:“create”,“timestamp”:1485937320,“id”:“74d1367d-5b63-401f-a0d3-46f6e6be8da9”,“last\_ok”:1485937320,“last\_state\_change”:1485937320,“silenced”:false,“silenced\_by”:},“filter”:null}

Shouldn’t the “filter” value show the name of the matching filter?

---

<div class="post-metadata">

**Author:** ![Cameron\_Johnston2](https://avatars.discourse-cdn.com/v4/letter/c/f9ae1b/32.png) [@Cameron\_Johnston2](https://discourse.sensu.io/u/Cameron_Johnston2)\
**Post date:** [February 4, 2017, 11:51pm UTC](https://discourse.sensu.io/t/event-was-filtered-message-is-showing-null-instead-of-the-name-of-the-matching-filter/754/2 "2017-02-04T23:51:25Z")

</div>

Hi fhd,

Thanks for reporting this issue. I’ve reproduced this in my testing and it does seem that the feature isn’t working as intended. I’ve opened [Filter name is logged as null when event is filtered · Issue #1546 · sensu/sensu · GitHub](https://github.com/sensu/sensu/issues/1546) to track this.

> **···**
>
> On Wednesday, February 1, 2017 at 1:41:51 AM UTC-7, fhd wrote:
> 
> > As per #1467, on v0.27 the filtered events should show the name of the matching filter.  
> > Currently, I’m getting ‘null’. I wonder if I’m doing something wrong? Here are my filters:
> > 
> > {  
> > “filters”: {  
> > “filter\_1”: {  
> > “negate”: false,  
> > “attributes”: {  
> > “check”: {  
> > “name”: “checkname1”  
> > },  
> > “occurrences”: “eval: value != 1 && value % 5 != 0”  
> > }  
> > },  
> > “filter\_2”: {  
> > “negate”: false,  
> > “attributes”: {  
> > “check”: {  
> > “name”: “checkname2”  
> > },  
> > “occurrences”: “eval: value != 3 && value % 6 != 0”  
> > }  
> > }  
> > }  
> > }
> > 
> > And the relevant log output:  
> > {“timestamp”:“2017-02-01T09:22:00.375020+0100”,“level”:“info”,“message”:“event was filtered”,“handler”:{“type”:“pipe”,“command”:“/etc/sensu/handlers/myhandler.rb”,“filters”:[“filter\_1”,“filter\_2”],“severities”:[“critical”,“unknown”,“ok”],“name”:“myhandler”},“event”:{“client”:{…},“check”:{“handlers”:[“webapi”],“command”:“sudo /etc/sensu/plugins/checkscript1.rb”,“interval”:60,“occurrences”:5,“alias”:“checkname1”,“subscribers”:[“all”],“name”:“checkname1”,“issued”:1485937320,“executed”:1485937320,“duration”:0.102,“output”:“”,“status”:2,“type”:“standard”,“history”:[“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“2”,“0”,“2”],“total\_state\_change”:11},“occurrences”:1,“occurrences\_watermark”:1,“action”:“create”,“timestamp”:1485937320,“id”:“74d1367d-5b63-401f-a0d3-46f6e6be8da9”,“last\_ok”:1485937320,“last\_state\_change”:1485937320,“silenced”:false,“silenced\_by”:},“filter”:null}
> > 
> > Shouldn’t the “filter” value show the name of the matching filter?

---

<div class="post-metadata">

**Author:** ![fhd](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@fhd](https://discourse.sensu.io/u/fhd)\
**Post date:** [February 13, 2017, 9:20am UTC](https://discourse.sensu.io/t/event-was-filtered-message-is-showing-null-instead-of-the-name-of-the-matching-filter/754/3 "2017-02-13T09:20:39Z")

</div>

@Cameron Johnston

Great, thanks!

---

<div class="post-metadata">

**Author:** ![jspaleta](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/jspaleta/32/141_2.png) [@jspaleta](https://discourse.sensu.io/u/jspaleta)\
**Post date:** [November 22, 2018, 2:07am UTC](https://discourse.sensu.io/t/event-was-filtered-message-is-showing-null-instead-of-the-name-of-the-matching-filter/754/4 "2018-11-22T02:07:46Z")

</div>


