# Connecting logstash on elastic with security enabled

**URL:** <https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636>\
**Category:** Logstash\
**Created:** [May 25, 2022, 7:01pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636 "2022-05-25T19:01:08Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dlazure](https://avatars.discourse-cdn.com/v4/letter/d/8797f3/32.png) [@dlazure](https://discuss.elastic.co/u/dlazure)\
**Post date:** [May 25, 2022, 7:01pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636/1 "2022-05-25T19:01:08Z")

</div>

Hi

I am trying to connect a plugin on elasticsearch with security enabled.

The plugin is having an unrecoverable error and is restarting

portion of logs of logstash

[2022-05-25T18:53:15,071][INFO][logstash.inputs.tcp][mikrotik-log][6941e412eeba6d7a7c03e32f344fbdf2555da759a46c27a7cb636d8cc746d53b] Starting tcp input listener {:address=\>"0.0.0.0:5514", :ssl\_enable=\>false}  
[2022-05-25T18:53:15,073][WARN][io.netty.channel.AbstractChannel][mikrotik-log][6941e412eeba6d7a7c03e32f344fbdf2555da759a46c27a7cb636d8cc746d53b] Force-closing a channel whose registration task was not accepted by an event loop: [id: 0x7881ae58]  
java.util.concurrent.RejectedExecutionException: event executor terminated  
at io.netty.util.concurrent.SingleThreadEventExecutor.reject(SingleThreadEventExecutor.java:926) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor.offerTask(SingleThreadEventExecutor.java:353) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor.addTask(SingleThreadEventExecutor.java:346) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor.execute(SingleThreadEventExecutor.java:828) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor.execute(SingleThreadEventExecutor.java:818) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.channel.AbstractChannel$AbstractUnsafe.register(AbstractChannel.java:483) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.channel.SingleThreadEventLoop.register(SingleThreadEventLoop.java:87) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.channel.SingleThreadEventLoop.register(SingleThreadEventLoop.java:81) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.channel.MultithreadEventLoopGroup.register(MultithreadEventLoopGroup.java:86) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.bootstrap.AbstractBootstrap.initAndRegister(AbstractBootstrap.java:323) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.bootstrap.AbstractBootstrap.doBind(AbstractBootstrap.java:272) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.bootstrap.AbstractBootstrap.bind(AbstractBootstrap.java:268) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.bootstrap.AbstractBootstrap.bind(AbstractBootstrap.java:253) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at org.logstash.tcp.InputLoop.run(InputLoop.java:86) [logstash-input-tcp-6.2.7.jar:?]  
at jdk.internal.reflect.GeneratedMethodAccessor43.invoke(Unknown Source) ~[?:?]  
at jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) ~[?:?]  
at java.lang.reflect.Method.invoke(Method.java:566) ~[?:?]  
at org.jruby.javasupport.JavaMethod.invokeDirectWithExceptionHandling(JavaMethod.java:441) [jruby.jar:?]  
at org.jruby.javasupport.JavaMethod.invokeDirect(JavaMethod.java:305) [jruby.jar:?]  
at org.jruby.java.invokers.InstanceMethodInvoker.call(InstanceMethodInvoker.java:32) [jruby.jar:?]  
at usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_input\_minus\_tcp\_minus\_6\_dot\_2\_dot\_7\_minus\_java.lib.logstash.inputs.tcp.RUBY$method$run$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-tcp-6.2.7-java/lib/logstash/inputs/tcp.rb:160) [jruby.jar:?]  
at usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$inputworker$0(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:410) [jruby.jar:?]  
at usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$inputworker$0$ **VARARGS** (/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:405) [jruby.jar:?]  
at org.jruby.internal.runtime.methods.CompiledIRMethod.call(CompiledIRMethod.java:80) [jruby.jar:?]  
at org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:70) [jruby.jar:?]  
at org.jruby.ir.targets.InvokeSite.invoke(InvokeSite.java:207) [jruby.jar:?]  
at usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$block$start\_input$1(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:401) [jruby.jar:?]  
at org.jruby.runtime.CompiledIRBlockBody.callDirect(CompiledIRBlockBody.java:138) [jruby.jar:?]  
at org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:58) [jruby.jar:?]  
at org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:52) [jruby.jar:?]  
at org.jruby.runtime.Block.call(Block.java:139) [jruby.jar:?]  
at org.jruby.RubyProc.call(RubyProc.java:318) [jruby.jar:?]  
at org.jruby.internal.runtime.RubyRunnable.run(RubyRunnable.java:105) [jruby.jar:?]  
at java.lang.Thread.run(Thread.java:829) [?:?]  
[2022-05-25T18:53:15,078][ERROR][logstash.javapipeline][mikrotik-log][6941e412eeba6d7a7c03e32f344fbdf2555da759a46c27a7cb636d8cc746d53b] A plugin had an unrecoverable error. Will restart this plugin.  
Pipeline\_id:mikrotik-log  
Plugin: \<LogStash::Inputs::Tcp port=\>5514, tags=\>["mikrotik-log"], id=\>"6941e412eeba6d7a7c03e32f344fbdf2555da759a46c27a7cb636d8cc746d53b", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Line id=\>"line\_6bd18bfc-f160-4af7-b189-df277732e185", enable\_metric=\>true, charset=\>"UTF-8", delimiter=\>"\n"\>, host=\>"0.0.0.0", mode=\>"server", proxy\_protocol=\>false, ssl\_enable=\>false, ssl\_verify=\>true, ssl\_key\_passphrase=\>, tcp\_keep\_alive=\>false, dns\_reverse\_lookup\_enabled=\>true\>  
Error: event executor terminated  
Exception: Java::JavaUtilConcurrent::RejectedExecutionException  
Stack: io.netty.util.concurrent.SingleThreadEventExecutor.reject(io/netty/util/concurrent/SingleThreadEventExecutor.java:926)  
io.netty.util.concurrent.SingleThreadEventExecutor.offerTask(io/netty/util/concurrent/SingleThreadEventExecutor.java:353)  
io.netty.util.concurrent.SingleThreadEventExecutor.addTask(io/netty/util/concurrent/SingleThreadEventExecutor.java:346)  
io.netty.util.concurrent.SingleThreadEventExecutor.execute(io/netty/util/concurrent/SingleThreadEventExecutor.java:828)  
io.netty.util.concurrent.SingleThreadEventExecutor.execute(io/netty/util/concurrent/SingleThreadEventExecutor.java:818)  
io.netty.channel.AbstractChannel$AbstractUnsafe.register(io/netty/channel/AbstractChannel.java:483)  
io.netty.channel.SingleThreadEventLoop.register(io/netty/channel/SingleThreadEventLoop.java:87)  
io.netty.channel.SingleThreadEventLoop.register(io/netty/channel/SingleThreadEventLoop.java:81)  
io.netty.channel.MultithreadEventLoopGroup.register(io/netty/channel/MultithreadEventLoopGroup.java:86)  
io.netty.bootstrap.AbstractBootstrap.initAndRegister(io/netty/bootstrap/AbstractBootstrap.java:323)  
io.netty.bootstrap.AbstractBootstrap.doBind(io/netty/bootstrap/AbstractBootstrap.java:272)  
io.netty.bootstrap.AbstractBootstrap.bind(io/netty/bootstrap/AbstractBootstrap.java:268)  
io.netty.bootstrap.AbstractBootstrap.bind(io/netty/bootstrap/AbstractBootstrap.java:253)  
org.logstash.tcp.InputLoop.run(org/logstash/tcp/InputLoop.java:86)  
jdk.internal.reflect.GeneratedMethodAccessor43.invoke(jdk/internal/reflect/GeneratedMethodAccessor43)  
jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(jdk/internal/reflect/DelegatingMethodAccessorImpl.java:43)  
java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:566)  
org.jruby.javasupport.JavaMethod.invokeDirectWithExceptionHandling(org/jruby/javasupport/JavaMethod.java:441)  
org.jruby.javasupport.JavaMethod.invokeDirect(org/jruby/javasupport/JavaMethod.java:305)  
usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_input\_minus\_tcp\_minus\_6\_dot\_2\_dot\_7\_minus\_java.lib.logstash.inputs.tcp.run(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-tcp-6.2.7-java/lib/logstash/inputs/tcp.rb:160)  
usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.inputworker(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:410)  
usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.start\_input(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:401)  
org.jruby.RubyProc.call(org/jruby/RubyProc.java:318)  
java.lang.Thread.run(java/lang/Thread.java:829)

this is my plugin :

root@elastic:/etc/logstash# cat /etc/logstash/conf.d/mikrotik-log.conf

# Input will be the tcp port specified, mikrotik config will be shown later.

input {  
tcp {  
port =\> 5514  
tags =\> ["mikrotik-log"]  
}  
udp {  
port =\> 5514  
tags =\> ["mikrotik-log"]  
}  
}

# the tag mikrotik-log is added by the input

filter {  
if "mikrotik-log" in [tags] {  
grok {  
id =\> "mikrotik-log-pipeline"  
patterns\_dir =\> "/etc/logstash/custom-patterns/"  
tag\_on\_failure =\> "\_grokparsefailure\_mikrotik\_log"  
match =\> [  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{GREEDYDATA:item} %{DATA:action} by %{DATA:user}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) user %{DATA:user} %{GREEDYDATA:action} from %{IP:host} via %{DATA:method}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{GREEDYDATA:action} for user %{DATA:user} from %{IP:host} via %{DATA:method}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{GREEDYDATA:action} for user: %{DATA:user}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{GREEDYDATA:action} (Identity Protection): %{IP:local\_address}%{GREEDYDATA}%{IP:remote\_address}%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{GREEDYDATA:action}%{IP:local\_address}[%{GREEDYDATA}]-%{IP:remote\_address}[%{GREEDYDATA}] spi:%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{MIKROTIK\_ACQUIRED\_IP:action} %{IP:acquired\_ip} address for %{IP:remote\_address}[%{GREEDYDATA}]$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{GREEDYDATA:action}%{IP:local\_address}[%{GREEDYDATA}]\<=\>%{IP:remote\_address}[%{GREEDYDATA}] spi=%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{GREEDYDATA:action} %{IP:released\_ip} $",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{MIKROTIK\_FAILED\_PROPOSAL:action}%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{IP:remote\_address} %{MIKROTIK\_FAILED\_PROPOSAL:action}%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{MIKROTIK\_PEER\_NOT\_COMPLIANT:action}%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) the %{MIKROTIK\_PACKET\_RETRANSMISSION:action} by %{IP:remote\_address}[%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{DATA:interface} link %{GREEDYDATA:link\_state}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{MIKROTIK\_TRAFFIC\_FLOW:action} by %{DATA:user}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{DATA:address\_pool} %{MIKROTIK\_ACQUIRED\_IP:action} %{IP:acquired\_ip} to %{DATA:mac\_address}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{DATA:address\_pool} %{MIKROTIK\_RELEASED\_IP:action} %{IP:released\_ip} from %{DATA:mac\_address} $",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{DATA:mac\_address}@%{DATA:ap\_ssid}: %{DATA:action}, signal strength %{INT:signal\_strength}%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{DATA:mac\_address}@%{DATA:ap\_ssid}: %{DATA:action}, %{MIKROTIK\_DISCO\_REASON:disconnect\_reason}%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{DATA:mac\_address}@%{DATA:ap\_ssid}: %{MIKROTIK\_WIFI\_STATE:wifi\_state} $",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{DATA:chain}: in:%{DATA:in\_interface} out:%{GREEDYDATA:out\_interface}, src-mac %{DATA:mac\_address}, proto %{DATA:protocol}, %{IP:local\_address}:%{INT:src\_port}-\>%{IP:remote\_address}:%{INT:dst\_port}, len %{INT:length}%{GREEDYDATA}$",  
"message", "(%{MIKROTIK\_TOPIC:topic1}(,%{MIKROTIK\_TOPIC:topic2}(,%{MIKROTIK\_TOPIC:topic3}?)?)?) %{DATA:chain}: in:%{DATA:in\_interface} out:%{GREEDYDATA:out\_interface}, src-mac %{DATA:mac\_address}, proto %{DATA:protocol} (%GREEDYDATA}), %{IP:local\_address}-\>%{IP:remote\_address}, len %{INT:length}%{GREEDYDATA}$"  
]  
}  
if "\_grokparsefailure\_mikrotik\_log" not in [tags] {  
mutate {  
remove\_field =\> ["message"]  
}  
}  
}  
}

# output to all elasticsearch hosts

output {  
if "mikrotik-log" in [tags] {  
elasticsearch {  
ssl =\> true  
ssl\_certificate\_verification =\> false  
user =\> "elastic"  
password =\> "password"  
id =\> "mikrotik-log-output"  
hosts =\> ["[https://192.168.15.38:9200](https://192.168.15.38:9200)"]  
index =\> "mikrotik-log-%{+YYYY.MM.ww}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 25, 2022, 7:42pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636/2 "2022-05-25T19:42:57Z")

</div>

What logstash version? I wonder if you are hitting [this](https://github.com/elastic/logstash/issues/11908) issue.

---

<div class="post-metadata">

**Author:** ![dlazure](https://avatars.discourse-cdn.com/v4/letter/d/8797f3/32.png) [@dlazure](https://discuss.elastic.co/u/dlazure)\
**Post date:** [May 26, 2022, 2:51pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636/4 "2022-05-26T14:51:55Z")

</div>

Using bundled JDK: /usr/share/logstash/jdk  
logstash 8.2.1

i don't think it applies

---

<div class="post-metadata">

**Author:** ![dlazure](https://avatars.discourse-cdn.com/v4/letter/d/8797f3/32.png) [@dlazure](https://discuss.elastic.co/u/dlazure)\
**Post date:** [May 26, 2022, 3:35pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636/6 "2022-05-26T15:35:49Z")

</div>

Error: event executor terminated  
Exception: Java::JavaUtilConcurrent::RejectedExecutionException  
Stack: io.netty.util.concurrent.SingleThreadEventExecutor.reject(io/netty/util/concurrent/SingleThreadEventExecutor.java:926)  
io.netty.util.concurrent.SingleThreadEventExecutor.offerTask(io/netty/util/concurrent/SingleThreadEventExecutor.java:353)  
io.netty.util.concurrent.SingleThreadEventExecutor.addTask(io/netty/util/concurrent/SingleThreadEventExecutor.java:346)  
io.netty.util.concurrent.SingleThreadEventExecutor.execute(io/netty/util/concurrent/SingleThreadEventExecutor.java:828)  
io.netty.util.concurrent.SingleThreadEventExecutor.execute(io/netty/util/concurrent/SingleThreadEventExecutor.java:818)  
io.netty.channel.AbstractChannel$AbstractUnsafe.register(io/netty/channel/AbstractChannel.java:483)  
io.netty.channel.SingleThreadEventLoop.register(io/netty/channel/SingleThreadEventLoop.java:87)  
io.netty.channel.SingleThreadEventLoop.register(io/netty/channel/SingleThreadEventLoop.java:81)  
io.netty.channel.MultithreadEventLoopGroup.register(io/netty/channel/MultithreadEventLoopGroup.java:86)  
io.netty.bootstrap.AbstractBootstrap.initAndRegister(io/netty/bootstrap/AbstractBootstrap.java:323)  
io.netty.bootstrap.AbstractBootstrap.doBind(io/netty/bootstrap/AbstractBootstrap.java:272)  
io.netty.bootstrap.AbstractBootstrap.bind(io/netty/bootstrap/AbstractBootstrap.java:268)  
io.netty.bootstrap.AbstractBootstrap.bind(io/netty/bootstrap/AbstractBootstrap.java:253)  
org.logstash.tcp.InputLoop.run(org/logstash/tcp/InputLoop.java:86)  
jdk.internal.reflect.GeneratedMethodAccessor51.invoke(jdk/internal/reflect/GeneratedMethodAccessor51)  
jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(jdk/internal/reflect/DelegatingMethodAccessorImpl.java:43)  
java.lang.reflect.Method.invoke(java/lang/reflect/Method.java:566)  
org.jruby.javasupport.JavaMethod.invokeDirectWithExceptionHandling(org/jruby/javasupport/JavaMethod.java:441)  
org.jruby.javasupport.JavaMethod.invokeDirect(org/jruby/javasupport/JavaMethod.java:305)  
usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_input\_minus\_tcp\_minus\_6\_dot\_2\_dot\_7\_minus\_java.lib.logstash.inputs.tcp.run(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-tcp-6.2.7-java/lib/logstash/inputs/tcp.rb:160)  
usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.inputworker(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:410)  
usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.start\_input(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:401)  
org.jruby.RubyProc.call(org/jruby/RubyProc.java:318)  
java.lang.Thread.run(java/lang/Thread.java:829)  
[2022-05-26T15:32:55,877][INFO][logstash.inputs.udp][main][6fa280cdb3cc1a04284d9ea4c612d859185dd3aa5773099f9004ef074616f367] Starting UDP listener {:address=\>"0.0.0.0:5514"}  
[2022-05-26T15:32:55,878][ERROR][logstash.inputs.udp][main][6fa280cdb3cc1a04284d9ea4c612d859185dd3aa5773099f9004ef074616f367] UDP listener died {:exception=\>#\<Errno::EADDRINUSE: Address already in use - bind(2) for "0.0.0.0" port 5514\>, :backtrace=\>["org/jruby/ext/socket/RubyUDPSocket.java:200:in `bind'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-udp-3.5.0/lib/logstash/inputs/udp.rb:129:in `udp\_listener'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-udp-3.5.0/lib/logstash/inputs/udp.rb:81:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:410:in `inputworker'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:401:in `block in start\_input'"]}  
[2022-05-26T15:32:56,193][WARN][logstash.outputs.Elasticsearch][mikrotik-log][mikrotik-log-output] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"mikrotik-log-2022.05.21", :routing=\>nil}, {"host"=\>{"ip"=\>"192.168.2.32"}, "tags"=\>["mikrotik-log", "\_grokparsefailure\_mikrotik\_log"], "event"=\>{"original"=\>"firewall,info FWLOG input: in:bridge out:(unknown 0), src-mac d0:57:94:f4:50:40, proto ICMP (type 0, code 0), 8.8.8.8-\>192.168.2.32, len 56"}, "@version"=\>"1", "@timestamp"=\>2022-05-26T15:32:56.072065Z, "message"=\>"firewall,info FWLOG input: in:bridge out:(unknown 0), src-mac d0:57:94:f4:50:40, proto ICMP (type 0, code 0), 8.8.8.8-\>192.168.2.32, len 56"}], :response=\>{"index"=\>{"\_index"=\>"mikrotik-log-2022.05.21", "\_id"=\>"XMX\_AIEBviXzFmki2eoA", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [host] of type [keyword] in document with id 'XMX\_AIEBviXzFmki2eoA'. Preview of field's value: '{ip=192.168.2.32}'", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:9"}}}}}  
[2022-05-26T15:32:56,658][INFO][logstash.inputs.tcp][main][7b978a9212db2c2fa046be3b99dd1b3379b8dca6a5e322b275192852c8e4495a] Starting tcp input listener {:address=\>"0.0.0.0:5514", :ssl\_enable=\>false}  
[2022-05-26T15:32:56,658][WARN][io.netty.channel.AbstractChannel][main][7b978a9212db2c2fa046be3b99dd1b3379b8dca6a5e322b275192852c8e4495a] Force-closing a channel whose registration task was not accepted by an event loop: [id: 0x01fe5d8e]  
java.util.concurrent.RejectedExecutionException: event executor terminated  
at io.netty.util.concurrent.SingleThreadEventExecutor.reject(SingleThreadEventExecutor.java:926) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor.offerTask(SingleThreadEventExecutor.java:353) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor.addTask(SingleThreadEventExecutor.java:346) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor.execute(SingleThreadEventExecutor.java:828) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.util.concurrent.SingleThreadEventExecutor.execute(SingleThreadEventExecutor.java:818) ~[netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.channel.AbstractChannel$AbstractUnsafe.register(AbstractChannel.java:483) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.channel.SingleThreadEventLoop.register(SingleThreadEventLoop.java:87) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.channel.SingleThreadEventLoop.register(SingleThreadEventLoop.java:81) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.channel.MultithreadEventLoopGroup.register(MultithreadEventLoopGroup.java:86) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.bootstrap.AbstractBootstrap.initAndRegister(AbstractBootstrap.java:323) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.bootstrap.AbstractBootstrap.doBind(AbstractBootstrap.java:272) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.bootstrap.AbstractBootstrap.bind(AbstractBootstrap.java:268) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at io.netty.bootstrap.AbstractBootstrap.bind(AbstractBootstrap.java:253) [netty-all-4.1.65.Final.jar:4.1.65.Final]  
at org.logstash.tcp.InputLoop.run(InputLoop.java:86) [logstash-input-tcp-6.2.7.jar:?]  
at jdk.internal.reflect.GeneratedMethodAccessor51.invoke(Unknown Source) ~[?:?]  
at jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) ~[?:?]  
at java.lang.reflect.Method.invoke(Method.java:566) ~[?:?]  
at org.jruby.javasupport.JavaMethod.invokeDirectWithExceptionHandling(JavaMethod.java:441) [jruby.jar:?]  
at org.jruby.javasupport.JavaMethod.invokeDirect(JavaMethod.java:305) [jruby.jar:?]  
at org.jruby.java.invokers.InstanceMethodInvoker.call(InstanceMethodInvoker.java:32) [jruby.jar:?]  
at usr.share.logstash.vendor.bundle.jruby.$2\_dot\_5\_dot\_0.gems.logstash\_minus\_input\_minus\_tcp\_minus\_6\_dot\_2\_dot\_7\_minus\_java.lib.logstash.inputs.tcp.RUBY$method$run$0(/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-input-tcp-6.2.7-java/lib/logstash/inputs/tcp.rb:160) [jruby.jar:?]  
at usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$inputworker$0(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:410) [jruby.jar:?]  
at usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$method$inputworker$0$ **VARARGS** (/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:405) [jruby.jar:?]  
at org.jruby.internal.runtime.methods.CompiledIRMethod.call(CompiledIRMethod.java:80) [jruby.jar:?]  
at org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:70) [jruby.jar:?]  
at org.jruby.ir.targets.InvokeSite.invoke(InvokeSite.java:207) [jruby.jar:?]  
at usr.share.logstash.logstash\_minus\_core.lib.logstash.java\_pipeline.RUBY$block$start\_input$1(/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:401) [jruby.jar:?]  
at org.jruby.runtime.CompiledIRBlockBody.callDirect(CompiledIRBlockBody.java:138) [jruby.jar:?]  
at org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:58) [jruby.jar:?]  
at org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:52) [jruby.jar:?]  
at org.jruby.runtime.Block.call(Block.java:139) [jruby.jar:?]  
at org.jruby.RubyProc.call(RubyProc.java:318) [jruby.jar:?]  
at org.jruby.internal.runtime.RubyRunnable.run(RubyRunnable.java:105) [jruby.jar:?]  
at java.lang.Thread.run(Thread.java:829) [?:?]  
[2022-05-26T15:32:56,659][ERROR][logstash.javapipeline][main][7b978a9212db2c2fa046be3b99dd1b3379b8dca6a5e322b275192852c8e4495a] A plugin had an unrecoverable error. Will restart this plugin.

---

<div class="post-metadata">

**Author:** ![dlazure](https://avatars.discourse-cdn.com/v4/letter/d/8797f3/32.png) [@dlazure](https://discuss.elastic.co/u/dlazure)\
**Post date:** [May 26, 2022, 3:52pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636/7 "2022-05-26T15:52:47Z")

</div>

removing the main pipelines from pipelines.yml fixed the crashing issue.

now getting this

[2022-05-26T15:51:47,500][WARN][logstash.outputs.Elasticsearch][mikrotik-log][mikrotik-log-output] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"mikrotik-log-2022.05.21", :routing=\>nil}, {"tags"=\>["mikrotik-log"], "item"=\>"log action", "action"=\>"changed", "@version"=\>"1", "topic2"=\>"info", "user"=\>"admin", "event"=\>{"original"=\>"system,info log action changed by admin"}, "host"=\>{"ip"=\>"192.168.2.32"}, "topic1"=\>"system", "@timestamp"=\>2022-05-26T15:51:47.240245Z}], :response=\>{"index"=\>{"\_index"=\>"mikrotik-log-2022.05.21", "\_id"=\>"ssURAYEBviXzFmkiHO0d", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [host] of type [keyword] in document with id 'ssURAYEBviXzFmkiHO0d'. Preview of field's value: '{ip=192.168.2.32}'", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:181"}}}}}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 26, 2022, 4:55pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636/8 "2022-05-26T16:55:02Z")

</div>

See [this](https://discuss.elastic.co/t/getting-illegal-state-exception-error-while-pushing-logs-to-elasticsearch/290029/2) answer. Once you have indexed an document in which [host] is a string, any event in which [host] is an object will be rejected.

---

<div class="post-metadata">

**Author:** ![dlazure](https://avatars.discourse-cdn.com/v4/letter/d/8797f3/32.png) [@dlazure](https://discuss.elastic.co/u/dlazure)\
**Post date:** [May 26, 2022, 5:32pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636/9 "2022-05-26T17:32:46Z")

</div>

I modified [host] to object and it works

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 23, 2022, 5:33pm UTC](https://discuss.elastic.co/t/connecting-logstash-on-elastic-with-security-enabled/305636/10 "2022-06-23T17:33:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
