# Dead Letter Queue can't be enabled

**URL:** <https://discuss.elastic.co/t/dead-letter-queue-cant-be-enabled/121447>\
**Category:** Logstash\
**Created:** [February 26, 2018, 7:51am UTC](https://discuss.elastic.co/t/dead-letter-queue-cant-be-enabled/121447 "2018-02-26T07:51:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![manya12](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@manya12](https://discuss.elastic.co/u/manya12)\
**Post date:** [February 26, 2018, 7:51am UTC](https://discuss.elastic.co/t/dead-letter-queue-cant-be-enabled/121447/1 "2018-02-26T07:51:44Z")

</div>

Hi Team,  
I am trying to use dead letter queue feature and want to create a new index for dlq input events.  
Here are my configurations:  
in logstash.yml:  
path.data: /usr/share/logstash/data  
dead\_letter\_queue.enable: true  
dead\_letter\_queue.max\_bytes: 1024mb

in pipelines.yml:

- pipeline.id: main  
pipeline.workers: 3  
dead\_letter\_queue.enable: true  
dead\_letter\_queue.max\_bytes: 1024mb  
path.config: "/usr/share/logstash/pipeline/logstash.conf"
- pipeline.id: test  
dead\_letter\_queue.enable: false  
path.config: "/usr/share/logstash/pipeline/deadletter.conf"

I have my main configuration file logstash.conf at location /usr/share/logstash/pipeline/ which has inputs from beats, kafka and s3.  
While my deadletter.conf is also at /usr/share/logstash/pipeline/ and it's configuration has:  
input {  
dead\_letter\_queue {  
path =\> "/usr/share/logstash/data/dead\_letter\_queue"  
commit\_offsets =\> true  
pipeline\_id =\> "test"  
}  
}

output {  
elasticsearch {  
hosts =\> "elasticsearch"  
manage\_template =\> false  
index =\> "deadletterlog-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Now when i am running logstash through docker, i am getting the error:  
[2018-02-26T07:40:13,825][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://elasticsearch:9200/](http://elasticsearch:9200/), :path=\>"/"}  
[2018-02-26T07:40:13,862][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://elasticsearch:9200/](http://elasticsearch:9200/)"}  
[2018-02-26T07:40:13,874][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["//elasticsearch"]}  
[2018-02-26T07:40:13,878][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"test", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>500, :thread=\>"#\<Thread:0x1bf1f716@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:290 run\>"}  
[2018-02-26T07:40:13,921][ERROR][logstash.pipeline] Error registering plugin {:pipeline\_id=\>"test", :plugin=\>"\<LogStash::Inputs::DeadLetterQueue path=\>"/usr/share/logstash/data/dead\_letter\_queue", commit\_offsets=\>true, pipeline\_id=\>"test", id=\>"a3d25d3edc326dca05c593696922858580e88e8db65dcadcf89381251ae59511", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_e4bc4a24-8034-4bbf-b80a-438f50a5f5d6", enable\_metric=\>true, charset=\>"UTF-8"\>\>", :error=\>"/usr/share/logstash/data/dead\_letter\_queue/test", :thread=\>"#\<Thread:0x1bf1f716@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:290 run\>"}  
[2018-02-26T07:40:14,878][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline\_id=\>"test", :exception=\>java.nio.file.NoSuchFileException: /usr/share/logstash/data/dead\_letter\_queue/test, :backtrace=\>["sun.nio.fs.UnixException.translateToIOException(sun/nio/fs/UnixException.java:86)", "sun.nio.fs.UnixException.asIOException(sun/nio/fs/UnixException.java:111)", "sun.nio.fs.LinuxWatchService$Poller.implRegister(sun/nio/fs/LinuxWatchService.java:246)", "sun.nio.fs.AbstractPoller.processRequests(sun/nio/fs/AbstractPoller.java:260)", "sun.nio.fs.LinuxWatchService$Poller.run(sun/nio/fs/LinuxWatchService.java:329)", "java.lang.Thread.run(java/lang/Thread.java:748)"], :thread=\>"#\<Thread:0x1bf1f716@/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:290 run\>"}  
[2018-02-26T07:40:14,891][ERROR][logstash.agent] Failed to execute action {:id=\>:test, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: LogStash::PipelineAction::Create/pipeline\_id:test, action\_result: false", :backtrace=\>nil}

Can anyone help me with the error. Any help and guidance will be appreciated.  
Thanks in Advance!

---

<div class="post-metadata">

**Author:** ![RobBavey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/robbavey/32/20421_2.png) [@RobBavey](https://discuss.elastic.co/u/RobBavey)\
**Post date:** [March 1, 2018, 11:41pm UTC](https://discuss.elastic.co/t/dead-letter-queue-cant-be-enabled/121447/2 "2018-03-01T23:41:17Z")

</div>

Hi @manya12,

I suspect the issue you are having here is the `pipeline_id` defined in the `dead_letter_queue` input - the pipeline\_id here should be the name of the pipeline you want to read from, not the pipeline running the dead\_letter\_queue plugin. In your case this appears to be the pipeline with id `main`, so try setting the `pipeline_id` to `main`

Hope this helps!

Rob

---

<div class="post-metadata">

**Author:** ![manya12](https://avatars.discourse-cdn.com/v4/letter/m/e480ec/32.png) [@manya12](https://discuss.elastic.co/u/manya12)\
**Post date:** [March 5, 2018, 12:12pm UTC](https://discuss.elastic.co/t/dead-letter-queue-cant-be-enabled/121447/3 "2018-03-05T12:12:34Z")

</div>

@RobBavey  
Thanks alot. It worked for me.🙂  
One more thing i need to ask.  
Now when i have dead letter queue enabled and my input from dead letter queue is sending output to new index, my logs in it do not contains metadata and error why the log has been into inputted to dead letter queue.  
Is there any other configuration i need to do for that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2018, 12:12pm UTC](https://discuss.elastic.co/t/dead-letter-queue-cant-be-enabled/121447/4 "2018-04-02T12:12:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
