# Aggregate filter, error when same task\_id in two separate aggregate filters

**URL:** <https://discuss.elastic.co/t/aggregate-filter-error-when-same-task-id-in-two-separate-aggregate-filters/264151>\
**Category:** Logstash\
**Created:** [February 12, 2021, 3:41pm UTC](https://discuss.elastic.co/t/aggregate-filter-error-when-same-task-id-in-two-separate-aggregate-filters/264151 "2021-02-12T15:41:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [February 12, 2021, 3:41pm UTC](https://discuss.elastic.co/t/aggregate-filter-error-when-same-task-id-in-two-separate-aggregate-filters/264151/1 "2021-02-12T15:41:16Z")

</div>

Hi,  
I'm running a Logstash 7.9.2 Docker container inside a Kubernetes cluster and I'm seeing the following error message in Logstash when I attempt to use the same task\_id in two separate aggregate filters:

> [ERROR] 2021-02-12 15:28:57.351 [Converge PipelineAction::Reload] agent - Failed to execute action {:id=\>:"sandbox-qa", :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Reload, action\_result: false", :backtrace=\>nil}

These are the aggregate plugins:

```
if "interfaces" in [name] {
    aggregate {
        task_id => "%{device}-%{interface-name}"
        push_previous_map_as_event => true
        code => "
            event.to_hash.each { |k,v|
                unless map[k]
                    map[k] = v
                end
            }
            event.cancel
        "
    }
} 

if [in-octets] and [out-octets] {
    aggregate {
        task_id => "%{device}-%{interface-name}"
        inactivity_timeout => 120
        timeout_timestamp_field => "@timestamp"
        push_map_as_event_on_timeout => true
        code => "
            event.to_hash.each { |k,v|
                unless map[k]
                    map[k] = v
                end
            }
            event.cancel
        "
    }
}

```

If I change the first task\_id to something different, then the errors go away and the pipeline runs.

In other words, changing the first task\_id to "%{interface-name}" allows the pipeline to run.

Am I allowed to have the same task\_id in two separate aggregate plugins running inside the same pipeline?

Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2021, 8:09pm UTC](https://discuss.elastic.co/t/aggregate-filter-error-when-same-task-id-in-two-separate-aggregate-filters/264151/2 "2021-02-12T20:09:03Z")

</div>

> [@mohsin106](#):
>
> Am I allowed to have the same task\_id in two separate aggregate plugins running inside the same pipeline?

Yes.

I suggest you set log.level to debug and see if you get a more informative error message.

---

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [February 12, 2021, 8:26pm UTC](https://discuss.elastic.co/t/aggregate-filter-error-when-same-task-id-in-two-separate-aggregate-filters/264151/3 "2021-02-12T20:26:31Z")

</div>

Hi @Badger , these are the log lines before and after the [ERROR] event. I don't see any hints in the logs that can point me in the right direction.

> [DEBUG] 2021-02-12 20:17:10.205 [[qa-hub-json-interfaces]-pipeline-manager] grok - Adding pattern {"BACULA\_LOG\_FATAL\_CONN"=\>"Fatal error: bsock.c:133 Unable to connect to (Client: %{BACULA\_HOST:client}|Storage daemon) on %{HOSTNAME}:%{POSINT}. ERR=(?%{GREEDYDATA})"}  
> [DEBUG] 2021-02-12 20:17:10.205 [[qa-hub-json-interfaces]-pipeline-manager] grok - Adding pattern {"BACULA\_LOG\_NO\_CONNECT"=\>"Warning: bsock.c:127 Could not connect to (Client: %{BACULA\_HOST:client}|Storage daemon) on %{HOSTNAME}:%{POSINT}. ERR=(?%{GREEDYDATA})"}  
> [DEBUG] 2021-02-12 20:17:10.205 [[qa-hub-json-interfaces]-pipeline-manager] grok - Adding pattern {"BACULA\_LOG\_NO\_AUTH"=\>"Fatal error: Unable to authenticate with File daemon at %{HOSTNAME}. Possible causes:"}  
> [DEBUG] 2021-02-12 20:17:10.205 [[qa-hub-json-interfaces]-pipeline-manager] grok - Adding pattern {"BACULA\_LOG\_NOSUIT"=\>"No prior or suitable Full backup found in catalog. Doing FULL backup."}  
> [DEBUG] 2021-02-12 20:17:10.205 [[lab-backbone-json-interfaces]-pipeline-manager] aggregate - Aggregate register call {:code=\>"\n # Handle description change\n if map['description'] == nil\n desc = event.get('description');\n if desc != ''\n map['description'] = desc;\n else\n map['description'] = 'undefined';\n end\n end\n "}  
> [DEBUG] 2021-02-12 20:17:10.206 [[qa-hub-json-interfaces]-pipeline-manager] grok - Adding pattern {"BACULA\_LOG\_NOPRIOR"=\>"No prior Full backup Job record found."}  
> **[ERROR] 2021-02-12 20:17:10.206 [Converge PipelineAction::Create] agent - Failed to execute action {:id=\>:"sandbox-qa", :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}**  
> [DEBUG] 2021-02-12 20:17:10.206 [[qa-hub-json-interfaces]-pipeline-manager] grok - Adding pattern {"BACULA\_LOG\_JOB"=\>"(Error: )?Bacula %{BACULA\_HOST} %{BACULA\_VERSION} \(%{BACULA\_VERSION}\):"}  
> [DEBUG] 2021-02-12 20:17:10.207 [[lab-backbone-json-interfaces]-pipeline-manager] aggregate - Aggregate timeout for '%{device}-%{interface-name}' pattern: seconds  
> [DEBUG] 2021-02-12 20:17:10.207 [[qa-hub-json-interfaces]-pipeline-manager] grok - Adding pattern {"BACULA\_LOGLINE"=\>"%{BACULA\_TIMESTAMP:bts} %{BACULA\_HOST:hostname} JobId %{INT:jobid}: (%{BACULA\_LOG\_MAX\_CAPACITY}|%{BACULA\_LOG\_END\_VOLUME}|%{BACULA\_LOG\_NEW\_VOLUME}|%{BACULA\_LOG\_NEW\_LABEL}|%{BACULA\_LOG\_WROTE\_LABEL}|%{BACULA\_LOG\_NEW\_MOUNT}|%{BACULA\_LOG\_NOOPEN}|%{BACULA\_LOG\_NOOPENDIR}|%{BACULA\_LOG\_NOSTAT}|%{BACULA\_LOG\_NOJOBS}|%{BACULA\_LOG\_ALL\_RECORDS\_PRUNED}|%{BACULA\_LOG\_BEGIN\_PRUNE\_JOBS}|%{BACULA\_LOG\_BEGIN\_PRUNE\_FILES}|%{BACULA\_LOG\_PRUNED\_JOBS}|%{BACULA\_LOG\_PRUNED\_FILES}|%{BACULA\_LOG\_ENDPRUNE}|%{BACULA\_LOG\_STARTJOB}|%{BACULA\_LOG\_STARTRESTORE}|%{BACULA\_LOG\_USEDEVICE}|%{BACULA\_LOG\_DIFF\_FS}|%{BACULA\_LOG\_JOBEND}|%{BACULA\_LOG\_NOPRUNE\_JOBS}|%{BACULA\_LOG\_NOPRUNE\_FILES}|%{BACULA\_LOG\_VOLUME\_PREVWRITTEN}|%{BACULA\_LOG\_READYAPPEND}|%{BACULA\_LOG\_CANCELLING}|%{BACULA\_LOG\_MARKCANCEL}|%{BACULA\_LOG\_CLIENT\_RBJ}|%{BACULA\_LOG\_VSS}|%{BACULA\_LOG\_MAXSTART}|%{BACULA\_LOG\_DUPLICATE}|%{BACULA\_LOG\_NOJOBSTAT}|%{BACULA\_LOG\_FATAL\_CONN}|%{BACULA\_LOG\_NO\_CONNECT}|%{BACULA\_LOG\_NO\_AUTH}|%{BACULA\_LOG\_NOSUIT}|%{BACULA\_LOG\_JOB}|%{BACULA\_LOG\_NOPRIOR})"}  
> [WARN] 2021-02-12 20:17:10.208 [[lab-backbone-json-interfaces]-pipeline-manager] javapipeline - 'pipeline.ordered' is enabled and is likely less efficient, consider disabling if preserving event order is not necessary

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2021, 9:10pm UTC](https://discuss.elastic.co/t/aggregate-filter-error-when-same-task-id-in-two-separate-aggregate-filters/264151/4 "2021-02-12T21:10:06Z")

</div>

Those messages are all for other pipelines. Are there any other messages for `sandbox-qa`?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2021, 9:10pm UTC](https://discuss.elastic.co/t/aggregate-filter-error-when-same-task-id-in-two-separate-aggregate-filters/264151/5 "2021-03-12T21:10:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
