# \[ERROR\] 2019-01-08 10:18:42.313 \[main\] Logstash - java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

**URL:** <https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302>\
**Category:** Logstash\
**Created:** [January 8, 2019, 5:02am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302 "2019-01-08T05:02:16Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [January 8, 2019, 5:02am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/1 "2019-01-08T05:02:16Z")

</div>

I have an error at first i have run the config for beasts but now just for checking it's shows an error like this(in windows)  
what can i do did i make any mistake  
correct me

C:\ELK\logstash-6.5.3\bin\>logstash -e 'input { stdin {} } output { stdout {} }'  
ERROR: Unknown command '{'

See: 'bin/logstash --help'  
[ERROR] 2019-01-08 10:18:42.313 [main] Logstash - java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![Tayyab](https://avatars.discourse-cdn.com/v4/letter/t/e79b87/32.png) [@Tayyab](https://discuss.elastic.co/u/Tayyab)\
**Post date:** [January 8, 2019, 6:03am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/2 "2019-01-08T06:03:39Z")

</div>

I am facing the same issue.

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [January 8, 2019, 9:59am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/3 "2019-01-08T09:59:22Z")

</div>

Hello @tayyab, @Dv_Thiyanesh,

try this,

logstash -e 'input{stdin{}}output{stdout{}}'

It will work fine.

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [January 9, 2019, 11:07am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/4 "2019-01-09T11:07:04Z")

</div>

> [@balumurari1](#):
>
> logstash -e 'input{stdin{}}output{stdout{}}'

yaa it works thank you!

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [January 9, 2019, 11:13am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/5 "2019-01-09T11:13:50Z")

</div>

cheers..!! mark it as solution, so that it helps others

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [January 9, 2019, 11:20am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/6 "2019-01-09T11:20:35Z")

</div>

Done...And i am new to elastic so i need some good tutorials for filebeat to elasticsearch in windows  
can you Have send Me  
can you give some instructions  
where to learn

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [January 9, 2019, 11:26am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/7 "2019-01-09T11:26:25Z")

</div>

ok, in which scenarios you were using elasticsearch, so that i can help you to share knowledge.

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [January 9, 2019, 11:36am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/8 "2019-01-09T11:36:40Z")

</div>

I want to take logs from windows using winlogbeat and send that shipped logs to logstash using grok filter i need to take needed fields and send that that to elastic search

i have done it's working with this config file(I cannot understand what the filter is doing)  
how i can change filter to select specific fields,can u help me out?

input {  
beats {  
port =\> 5044  
}  
}

filter {  
if [system][process] {  
if [system][process][cmdline] {  
grok {  
match =\> {  
"[system][process][cmdline]" =\> "^%{PATH:[system][process][cmdline\_path]}"  
}  
remove\_field =\> "[system][process][cmdline]"  
}  
}  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [January 10, 2019, 7:40am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/9 "2019-01-10T07:40:31Z")

</div>

Today when i running this it's shows error

C:\ELK\logstash-6.5.3\bin\>logstash -e 'input{stdin{}}output{stdout{}}'  
Sending Logstash logs to C:/ELK/logstash-6.5.3/logs which is now configured via log4j2.properties  
[2019-01-10T13:09:08,506][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-01-10T13:09:08,545][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.5.3"}  
[2019-01-10T13:09:10,088][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 1, column 1 (byte 1) after ", :backtrace=\>["C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/compiler.rb:49:in`compile\_graph'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:149:in`initialize'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/pipeline.rb:90:in`initialize'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/pipeline\_action/create.rb:42:in `block in execute'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/agent.rb:92:in`block in exclusive'", "org/jruby/ext/thread/Mutex.java:148:in `synchronize'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/agent.rb:92:in`exclusive'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/pipeline\_action/create.rb:38:in `execute'", "C:/ELK/logstash-6.5.3/logstash-core/lib/logstash/agent.rb:317:in`block in converge\_state'"]}  
[2019-01-10T13:09:10,691][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![JKCode](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@JKCode](https://discuss.elastic.co/u/JKCode)\
**Post date:** [February 5, 2019, 4:51am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/10 "2019-02-05T04:51:51Z")

</div>

Hi All

I am facing the same issue while trying to start LS 6.5.0 on Windows 10 after a considerably long break in usage.  
I have checked /pipeline\_action/create.rb file to see if I could locate the missing #, but things seem fine.  
Logstash logs sincedb file also deleted, but error persists.  
Any help is much appreciated.

Edit:  
Attempted again, this time created a basic conf file as below:

> input{  
> stdin{}  
> }  
> output{  
> stdout{}  
> }

.. and it works!

Would still like some help to identify what's causing the error with the command line -e flag for better understanding!

Thanks!

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [February 6, 2019, 5:12am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/11 "2019-02-06T05:12:35Z")

</div>

i can't get you, could you can explain once again?

---

<div class="post-metadata">

**Author:** ![Dv\_Thiyanesh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dv_thiyanesh/32/53965_2.png) [@Dv\_Thiyanesh](https://discuss.elastic.co/u/Dv_Thiyanesh)\
**Post date:** [February 6, 2019, 6:00am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/12 "2019-02-06T06:00:25Z")

</div>

After doing this i have restarted logstash:

'''C:\ELK\logstash-6.5.3\bin\>logstash -f demo-winlog-pipeline.conf  
Sending Logstash logs to C:/ELK/logstash-6.5.3/logs which is now configured via log4j2.properties  
[2019-02-06T11:11:27,417][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-02-06T11:11:27,652][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.5.3"}  
[2019-02-06T11:11:37,022][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2019-02-06T11:11:39,096][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2019-02-06T11:11:41,744][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-02-06T11:11:41,926][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2019-02-06T11:11:41,934][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2019-02-06T11:11:42,004][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2019-02-06T11:11:49,785][INFO][logstash.inputs.beats] Beats inputs: Starting input listener {:address=\>"0.0.0.0:5044"}  
[2019-02-06T11:11:49,819][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x39a1e568 run\>"}  
[2019-02-06T11:11:50,566][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-02-06T11:11:54,077][INFO][org.logstash.beats.Server] Starting server on port: 5044  
[2019-02-06T11:11:55,387][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}'''

And the Result will be same not dropping events:  
 ![Screenshot_2019-02-06%20Discover%20-%20Kibana](https://us1.discourse-cdn.com/elastic/original/3X/8/8/882c40004ae6773ea0576cc56e5794a991d4f025.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2019, 6:00am UTC](https://discuss.elastic.co/t/error-2019-01-08-1042-313-main-logstash-java-lang-illegalstateexception-logstash-stopped-processing-because-of-an-error-systemexit-exit/163302/13 "2019-03-06T06:00:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
