# Constantly repeating error: A plugin had an unrecoverable error. Will restart this plugin

**URL:** <https://discuss.elastic.co/t/constantly-repeating-error-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/107104>\
**Category:** Logstash\
**Created:** [November 9, 2017, 8:56pm UTC](https://discuss.elastic.co/t/constantly-repeating-error-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/107104 "2017-11-09T20:56:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ajstark123](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@ajstark123](https://discuss.elastic.co/u/ajstark123)\
**Post date:** [November 9, 2017, 8:56pm UTC](https://discuss.elastic.co/t/constantly-repeating-error-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/107104/1 "2017-11-09T20:56:24Z")

</div>

We are getting the following error in the logs. We run fine for about 40 minutes then we start to get the following errors. It is unclear as to what went wrong.

> [2017-11-09T15:03:38,289][INFO][logstash.pipeline] Pipeline main started  
> [2017-11-09T15:03:38,345][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
> [2017-11-09T15:42:50,736][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.  
> Plugin: \<LogStash::Inputs::Tcp port=\>514, type=\>"syslog", id=\>"aa04873f48b834660f5dcfdc573533b3f3af07db-1", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Line id=\>"line\_e209eaa8-91f2-4462-821b-c16509daed64", enable\_metric=\>true, charset=\>"UTF-8", delimiter=\>"\n"\>, host=\>"0.0.0.0", data\_timeout=\>-1, mode=\>"server", proxy\_protocol=\>false, ssl\_enable=\>false, ssl\_verify=\>true, ssl\_key\_passphrase=\>\>  
> Error: problem when accepting

logstash.yml

> # The # character at the beginning of a line indicates a comment. Use
> 
> # comments to describe your configuration.
> 
> input {  
> #file {  
> # path =\> "/opt/pki/syslog/messages"  
> #}  
> # beats {  
> # port =\> "5044"  
> # }  
> tcp {  
> port =\> "514"  
> type =\> syslog  
> }
> 
> }
> 
> # The filter part of this file is commented out to indicate that it is
> 
> # optional.
> 
> filter {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]
> 
> ```
> # need it for alert queuering
> add_field => ["datacenter", "cnj"]
> add_field => ["env", "dev"]
> add_field => ["family", "pki"]
> add_field => ["app", "monitoring"]
> add_field => ["service", "loggy"]
> add_field => ["component", "logstash_1"]
> }
> date {
> match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
> }
> 
> if [syslog_hostname]{
> # the following fields are needed for hashing
> fingerprint {
> source => "syslog_hostname"
> target => "message_key_fingerprint"
> method => "MURMUR3"
> key => "Log analytics"
> }
> mutate {
> copy => { "message_key_fingerprint" => "message_key_int" }
> }
> mutate {
> convert => { "message_key_int" => "integer" }
> }
> mutate {
> copy => { "message_key_int" => "message_key" }
> }
> ruby {
> code => "event.set('message_key', event.get('message_key_int') % 10000 )"
> }
> mutate {
> convert => { "message_key" => "string" }
> }
> mutate {
> remove_field => ["message", "message_key_int", "message_key_fingerprint"]
> }
> 
> ```
> 
> }  
> }  
> output {  
> # stdout { codec =\> rubydebug }  
> # elasticsearch {  
> # hosts =\> ["[monatee-loggy-master-cnj.dev.bnymellon.net:80](http://monatee-loggy-master-cnj.dev.bnymellon.net:80)"]  
> # index =\> "monatee\_loggy\_cnj-%{+YYYY.MM.dd}"  
> #}
> 
> ```
> kafka {
> bootstrap_servers => "rsomtapae182.bnymellon.net:9092,rsomtapae183.bnymellon.net:9092,rsomtapae184.bnymellon.net:9092"
> client_id => "r00j55n0c"
> topic_id => "monatee_loggy"
> jaas_path => "/opt/pki/logstash_1/config_kafka/kafka_client_jaas_logstash.conf"
> security_protocol => "SASL_PLAINTEXT"
> sasl_kerberos_service_name => "kafka"
> sasl_mechanism => "plain"
> # compression_type => "snappy"
> }
> 
> ```
> 
> }

---

<div class="post-metadata">

**Author:** ![ajstark123](https://avatars.discourse-cdn.com/v4/letter/a/73ab20/32.png) [@ajstark123](https://discuss.elastic.co/u/ajstark123)\
**Post date:** [November 10, 2017, 1:32pm UTC](https://discuss.elastic.co/t/constantly-repeating-error-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/107104/2 "2017-11-10T13:32:00Z")

</div>

the log message is being generated every second and producing huge log files.

---

<div class="post-metadata">

**Author:** ![Cristina\_Alvarez](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@Cristina\_Alvarez](https://discuss.elastic.co/u/Cristina_Alvarez)\
**Post date:** [November 16, 2017, 10:58am UTC](https://discuss.elastic.co/t/constantly-repeating-error-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/107104/3 "2017-11-16T10:58:01Z")

</div>

I am getting the same error. Did you find how to fix it, Albert?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2017, 10:58am UTC](https://discuss.elastic.co/t/constantly-repeating-error-a-plugin-had-an-unrecoverable-error-will-restart-this-plugin/107104/4 "2017-12-14T10:58:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
