# Dead Letter Queue problem

**URL:** <https://discuss.elastic.co/t/dead-letter-queue-problem/130281>\
**Category:** Logstash\
**Created:** [May 2, 2018, 3:06pm UTC](https://discuss.elastic.co/t/dead-letter-queue-problem/130281 "2018-05-02T15:06:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kernelpanic](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Post date:** [May 2, 2018, 3:06pm UTC](https://discuss.elastic.co/t/dead-letter-queue-problem/130281/1 "2018-05-02T15:06:00Z")

</div>

Hello, I've attempted to add the dead letter queue to my configuration but when I restart logstash it fails to come back up, I've no doubt its something I'm doing wrong, hereis my relevant config:

```
###-INPUT-###
dead_letter_queue {
    path => "/usr/local/logstash/data/dead_letter_queue/" 
    type => deadletter
  }

###-FILTER-###

if [type] == "deadletter" {
   filter {
     mutate {
      remove_field => ["src_ip"] 
     }
   }
  }

###-OUTPUT-###

else if [type] == "deadletter" {
   elasticsearch {
    hosts => ["192.168.56.226:9200", "192.168.52.251:9200", "192.168.52.252:9200"]
    index => ["syslogcisco-%{+YYYY.MM.dd}"]
   }
  }

```

When I attempt to restart logstash I get the following error in the logstash log:

`:backtrace=>["/usr/local/logstash/logstash-core/lib/logstash/pipeline.rb:60:in`initialize'", "/usr/local/logstash/logstash-core/lib/logstash/pipeline.rb:165:in `initialize'", "/usr/local/logstash/logstash-core/lib/logstash/agent.rb:296:in`create\_pipeline'", "/usr/local/logstash/logstash-core/lib/logstash/agent.rb:95:in `register_pipeline'", "/usr/local/logstash/logstash-core/lib/logstash/runner.rb:313:in`execute'", "/usr/local/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:67:in `run'", "/usr/local/logstash/logstash-core/lib/logstash/runner.rb:204:in`run'", "/usr/local/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:132:in `run'", "/usr/local/logstash/lib/bootstrap/environment.rb:71:in`(root)'"]}`

I can get logstash to start properly only when I comment out the deadletter filter section.

Any help appreciated.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [May 3, 2018, 12:20am UTC](https://discuss.elastic.co/t/dead-letter-queue-problem/130281/2 "2018-05-03T00:20:27Z")

</div>

Can you copy the _whole_ error message? The [line in the backtrace](https://github.com/elastic/logstash/blob/5.6/logstash-core/lib/logstash/pipeline.rb#L60) indicates that the config failed to parse, and it should give a more helpful reason.

---

<div class="post-metadata">

**Author:** ![kernelpanic](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Post date:** [May 3, 2018, 9:11am UTC](https://discuss.elastic.co/t/dead-letter-queue-problem/130281/3 "2018-05-03T09:11:01Z")

</div>

Thanks for getting back to me, its quite a large error message and exceeds the 7000 character limit on this forum; the best I could think of doing was to upload a screenshot of the error to this post.

 ![logstash-error](https://us1.discourse-cdn.com/elastic/original/3X/c/d/cd782a788c30452ae35a5ed82336b68236e44d27.jpg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 9:11am UTC](https://discuss.elastic.co/t/dead-letter-queue-problem/130281/4 "2018-05-31T09:11:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
