# Can't not bind listen port 5140 to logstash ubuntu 18.04

**URL:** <https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428>\
**Category:** Logstash\
**Created:** [October 5, 2019, 3:32pm UTC](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428 "2019-10-05T15:32:06Z")\
**Posts on this page:** 6\
**Page:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 6, 2019, 2:53pm UTC](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428/24 "2019-10-06T14:53:16Z")

</div>

Also in my humble opinion separating the conf file into multiple conf files in the beginning or when you're trying to debug just makes it harder (example the actual line number with the error etc) ,  
Logstash under the covers concatenates them all anyways. Is there other input sections... what is the output section?

to format the code... past it in highlight it then click the `</>` button

Basically you still have syntax errors...

Example I just ran the following and it worked fine, all 1 conf file.

```
#01-inputs.conf
input {
  udp {
  type => "syslog"
  port => 5140
  }
}

# 05-syslog.conf
filter {
  if [type] == "syslog" {
  #Adjust to match the IP address of pfSense or OPNSense
    if [host] =~ /192.168.1.1/ {
      mutate {
        add_tag => ["pf", "Ready"]
      }
      if "Ready" not in [tags] {
        mutate {
          add_tag => ["syslog"]
        }
      }
    }
  }
  if [type] == "syslog" {
    mutate {
      remove_tag => "Ready"
    }
  }
}

# Output section
output {
  stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![Bubba\_Shakes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bubba_shakes/32/55276_2.png) [@Bubba\_Shakes](https://discuss.elastic.co/u/Bubba_Shakes)\
**Post date:** [October 6, 2019, 3:05pm UTC](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428/25 "2019-10-06T15:05:51Z")

</div>

Here is the guide I followed:

> **[a3ilson/pfelk](https://github.com/a3ilson/pfelk)**
>
> pfSense + ELK. Contribute to a3ilson/pfelk development by creating an account on GitHub.

In my /etc/logstash/conf.d I have the following:  
guyp@ubuntu:/etc/logstash/conf.d$ ls -l  
total 24  
-rw-r--r-- 1 root root 72 Oct 6 10:07 01-inputs.conf  
-rw-r--r-- 1 root root 452 Oct 6 10:08 05-syslog.conf  
-rw-r--r-- 1 root root 577 Oct 4 23:49 10-pf.conf  
-rw-r--r-- 1 root root 3475 Oct 4 23:49 11-firewall.conf  
-rw-r--r-- 1 root root 133 Oct 4 23:49 50-outputs.conf  
drwxr-xr-x 2 root root 4096 Oct 4 23:50 patterns

Thanks Stephen, how/what would I name the "1" config file in lieu of 01 and 05 for logstash? Or should I just correct the 01 and 05 config files and move on?

Also, is this version of Java compatible w/ logstash?

guyp@ubuntu:/etc/logstash/conf.d$ java -version  
java version "12.0.2" 2019-07-16  
Java(TM) SE Runtime Environment (build 12.0.2+10)  
Java HotSpot(TM) 64-Bit Server VM (build 12.0.2+10, mixed mode, sharing)

Made the changes and still failed.

guyp@ubuntu:/var/log/logstash$ tail logstash-plain.log  
[2019-10-06T10:10:04,803][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-10-06T10:10:09,881][INFO][logstash.runner] Logstash shut down.  
[2019-10-06T10:10:31,104][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.4.0"}  
[2019-10-06T10:10:32,905][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, ,, ] at line 40, column 28 (byte 609) after filter {\n if "pf" in [tags] {\n grok {\n match =\> ["message" ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in`compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2584:in`map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:153:in`initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:26:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:326:in`block in converge\_state'"]}  
[2019-10-06T10:10:33,181][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-10-06T10:10:38,061][INFO][logstash.runner] Logstash shut down.  
[2019-10-06T10:11:00,270][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.4.0"}  
[2019-10-06T10:11:02,582][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, ,, ] at line 40, column 28 (byte 609) after filter {\n if "pf" in [tags] {\n grok {\n match =\> ["message" ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in`compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2584:in`map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:153:in`initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:26:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:326:in`block in converge\_state'"]}  
[2019-10-06T10:11:02,874][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-10-06T10:11:07,946][INFO][logstash.runner] Logstash shut down.

Thanks

---

<div class="post-metadata">

**Author:** ![Bubba\_Shakes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bubba_shakes/32/55276_2.png) [@Bubba\_Shakes](https://discuss.elastic.co/u/Bubba_Shakes)\
**Post date:** [October 6, 2019, 4:01pm UTC](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428/27 "2019-10-06T16:01:01Z")

</div>

Looks like logstash is receiving messages from my FW:

guyp@ubuntu:/etc/logstash/conf.d$ sudo systemctl status logstash.service  
● logstash.service - logstash  
Loaded: loaded (/etc/systemd/system/logstash.service; enabled; vendor preset: enabled)  
Active: active (running) since Sun 2019-10-06 10:43:29 CDT; 16min ago  
Main PID: 69342 (java)  
Tasks: 31 (limit: 4649)  
CGroup: /system.slice/logstash.service  
└─69342 /usr/bin/java -Xms1g -Xmx1g -XX:+UseConcMarkSweepGC -XX:CMSInitiatingOccupancyFraction=75 -XX:+UseCMSInitiatingOccupancyOnly -Djava.awt.he

Oct 06 10:59:41 ubuntu logstash[69342]: {  
Oct 06 10:59:41 ubuntu logstash[69342]: "@timestamp" =\> 2019-10-06T15:59:40.919Z,  
Oct 06 10:59:41 ubuntu logstash[69342]: "message" =\> "\<134\>Oct 6 10:59:40 [xxxx.xxxx.com](http://xxxx.xxxx.com) filterlog: 76,,,0,xn0,match,pass,out,4,0x0  
Oct 06 10:59:41 ubuntu logstash[69342]: "@version" =\> "1",  
Oct 06 10:59:41 ubuntu logstash[69342]: "type" =\> "syslog",  
Oct 06 10:59:41 ubuntu logstash[69342]: "tags" =\> [  
Oct 06 10:59:41 ubuntu logstash[69342]: [0] "pf"  
Oct 06 10:59:41 ubuntu logstash[69342]: ],  
Oct 06 10:59:41 ubuntu logstash[69342]: "host" =\> "192.168.1.1"  
Oct 06 10:59:41 ubuntu logstash[69342]: }

---

<div class="post-metadata">

**Author:** ![Bubba\_Shakes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bubba_shakes/32/55276_2.png) [@Bubba\_Shakes](https://discuss.elastic.co/u/Bubba_Shakes)\
**Post date:** [October 6, 2019, 4:17pm UTC](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428/29 "2019-10-06T16:17:14Z")

</div>

This is the config file logstash is failing on:

**Update: Following this thread I was able to address my issue.**

> [@Having issues with my PF sense configs](https://discuss.elastic.co/t/having-issues-with-my-pf-sense-configs/202438):
>
> I'm having issues with getting my PF sense logs to parse properly. The current result is that everything is dropped and I am uncertain why. I am using the config files from this github: [https://github.com/a3ilson/pfelk](https://github.com/a3ilson/pfelk) I get this error: [2019-10-06T00:16:31,031][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.4.0"} [2019-10-06T00:16:32,625][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::C…

---

<div class="post-metadata">

**Author:** ![Bubba\_Shakes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bubba_shakes/32/55276_2.png) [@Bubba\_Shakes](https://discuss.elastic.co/u/Bubba_Shakes)\
**Post date:** [October 6, 2019, 5:41pm UTC](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428/30 "2019-10-06T17:41:20Z")

</div>

Thanks for all the feedback and assistance! This was a good learning experience for me!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2019, 5:41pm UTC](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428/31 "2019-11-03T17:41:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/cant-not-bind-listen-port-5140-to-logstash-ubuntu-18-04/202428.md?page=1)
