# Error in logstash.conf

**URL:** <https://discuss.elastic.co/t/error-in-logstash-conf/141281>\
**Category:** Logstash\
**Created:** [July 24, 2018, 3:07am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281 "2018-07-24T03:07:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yih\_Ashley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yih_ashley/32/33658_2.png) [@Yih\_Ashley](https://discuss.elastic.co/u/Yih_Ashley)\
**Post date:** [July 24, 2018, 3:07am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281/1 "2018-07-24T03:07:34Z")

</div>

Hello, I have a problem when running my logstash. Below is my configuration in logstash.conf

input {  
file {  
path =\> ["/var/log/nsm/eve.json"]  
codec =\> json  
type =\> "SuricataIDPS"  
}

}

filter {  
if [type] == "SuricataIDPS" {  
date {  
match =\> ["timestamp", "ISO8601"]  
}  
ruby {  
code =\> "  
if event.get('[event\_type]') == 'fileinfo'  
event.set('[fileinfo][type]', event.get('[fileinfo][magic]').to\_s.split(',')[0])  
end  
"  
}  
}

if [src\_ip] {  
geoip {  
source =\> "src\_ip"  
target =\> "geoip"  
#database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
if ![geoip.ip] {  
if [dest\_ip] {  
geoip {  
source =\> "dest\_ip"  
target =\> "geoip"  
#database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
}  
}  
}  
}

output {  
elasticsearch { hosts =\> localhost }  
}

The error is occured as:  
[2018-07-25T01:37:12,638][ERROR][logstash.pipeline] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {:pipeline\_id=\>"main", "exception"=\>"undefined method `tr' for -118.244:Float", "backtrace"=>["/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:344:in`convert\_float'", "org/jruby/RubyMethod.java:115:in `call'", "/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in`block in convert'", "org/jruby/RubyArray.java:2486:in `map'", "/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in`block in convert'", "org/jruby/RubyHash.java:1343:in `each'", "/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:299:in`convert'", "/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:252:in `filter'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/filters/base.rb:145:in`do\_filter'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/filters/base.rb:164:in `block in multi_filter'", "org/jruby/RubyArray.java:1734:in`each'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/filters/base.rb:161:in `multi_filter'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/filter_delegator.rb:47:in`multi\_filter'", "(eval):352:in `block in initialize'", "org/jruby/RubyArray.java:1734:in`each'", "(eval):348:in `block in initialize'", "(eval):366:in`block in initialize'", "org/jruby/RubyArray.java:1734:in `each'", "(eval):363:in`block in initialize'", "(eval):382:in `block in initialize'", "org/jruby/RubyArray.java:1734:in`each'", "(eval):377:in `block in initialize'", "(eval):172:in`block in filter\_func'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/pipeline.rb:445:in `filter_batch'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/pipeline.rb:424:in`worker\_loop'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/pipeline.rb:386:in `block in start_workers'"], :thread=>"#<Thread:0xd1823a0 sleep>"} [2018-07-25T01:37:12,758][FATAL][logstash.runner] An unexpected error occurred! {:error=>#<NoMethodError: undefined method`tr' for -118.244:Float\>, :backtrace=\>["/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:344:in `convert_float'", "org/jruby/RubyMethod.java:115:in`call'", "/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in `block in convert'", "org/jruby/RubyArray.java:2486:in`map'", "/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:309:in `block in convert'", "org/jruby/RubyHash.java:1343:in`each'", "/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:299:in `convert'", "/home/ashley/logstash-6.2.4/vendor/bundle/jruby/2.3.0/gems/logstash-filter-mutate-3.3.1/lib/logstash/filters/mutate.rb:252:in`filter'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/filters/base.rb:145:in `do_filter'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/filters/base.rb:164:in`block in multi\_filter'", "org/jruby/RubyArray.java:1734:in `each'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/filters/base.rb:161:in`multi\_filter'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/filter\_delegator.rb:47:in `multi_filter'", "(eval):352:in`block in initialize'", "org/jruby/RubyArray.java:1734:in `each'", "(eval):348:in`block in initialize'", "(eval):366:in `block in initialize'", "org/jruby/RubyArray.java:1734:in`each'", "(eval):363:in `block in initialize'", "(eval):382:in`block in initialize'", "org/jruby/RubyArray.java:1734:in `each'", "(eval):377:in`block in initialize'", "(eval):172:in `block in filter_func'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/pipeline.rb:445:in`filter\_batch'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/pipeline.rb:424:in `worker_loop'", "/home/ashley/logstash-6.2.4/logstash-core/lib/logstash/pipeline.rb:386:in`block in start\_workers'"]}  
[2018-07-25T01:37:12,893][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: org.jruby.exceptions.RaiseException: (SystemExit) exit

Can everyone helps? Thanks.

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [July 24, 2018, 7:17am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281/2 "2018-07-24T07:17:12Z")

</div>

Hi Ashley,

Please format your post so that it is easier to read.

Could you try removing the mutate block and see if this still gives you the same errors?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 24, 2018, 9:35am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281/3 "2018-07-24T09:35:46Z")

</div>

I answered a question like this a week or two ago.

You're trying to convert a field value already containing a float into a float value.

---

<div class="post-metadata">

**Author:** ![Charaf\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charaf_ahmed/32/30467_2.png) [@Charaf\_Ahmed](https://discuss.elastic.co/u/Charaf_Ahmed)\
**Post date:** [July 24, 2018, 9:38am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281/4 "2018-07-24T09:38:10Z")

</div>

Should it not also specify the port at the output level ?

---

<div class="post-metadata">

**Author:** ![Yih\_Ashley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yih_ashley/32/33658_2.png) [@Yih\_Ashley](https://discuss.elastic.co/u/Yih_Ashley)\
**Post date:** [July 25, 2018, 2:14am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281/5 "2018-07-25T02:14:26Z")

</div>

Thanks a lot...Logstash is already running.....

---

<div class="post-metadata">

**Author:** ![Yih\_Ashley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yih_ashley/32/33658_2.png) [@Yih\_Ashley](https://discuss.elastic.co/u/Yih_Ashley)\
**Post date:** [July 25, 2018, 2:15am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281/6 "2018-07-25T02:15:15Z")

</div>

Thanks a lot...Thanks for your explanation....

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [August 4, 2018, 10:54am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281/7 "2018-08-04T10:54:13Z")

</div>

@Yih_Ashley as you are processing Suricata data, you might want to also have a look at...

> **[koiossian/synesis\_lite\_suricata](https://github.com/koiossian/synesis_lite_suricata)**
>
> synesis\_lite\_suricata - Suricata IDS/IPS log analytics using the Elastic Stack.

It uses filebeat to tail the eve.json file and send the data to Logstash for processing before it is sent to Elasticsearch and can be visualized in Kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2018, 10:54am UTC](https://discuss.elastic.co/t/error-in-logstash-conf/141281/8 "2018-09-01T10:54:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
