# Error in Logstash gork filter

**URL:** https://discuss.elastic.co/t/error-in-logstash-gork-filter/159304
**Category:** Logstash
**Created:** [December 4, 2018, 7:37am UTC](https://discuss.elastic.co/t/error-in-logstash-gork-filter/159304 "2018-12-04T07:37:28Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)
#### Post date: [December 4, 2018, 7:37am UTC](https://discuss.elastic.co/t/error-in-logstash-gork-filter/159304/1 "2018-12-04T07:37:28Z")

</div>

Hi,

I tried to structure the syserr log, and i'm getting some error. Please anyone guide me how to proceed.

Log file sample

[1/8/18 14:08:22:395 IST] 0000007a SystemErr R com.ibm.ws.persistence.WsJpaProductDerivation:java.lang.ClassNotFoundException: com.ibm.ws.persistence.WsJpaProductDerivation  
[1/8/18 14:08:22:453 IST] 0000007a SystemErr R 18 jpa-unit-rdbms WARN [server.startup : 2] openjpa.Runtime - Could not create the optional validation provider. Reason returned: "A default ValidatorFactory could not be created."  
[1/8/18 14:08:22:848 IST] 0000007a SystemErr R 413 jpa-unit-rdbms INFO [server.startup : 2] openjpa.jdbc.JDBC - Using dictionary class "org.apache.openjpa.jdbc.sql.OracleDictionary" (Oracle Oracle Database 12c Enterprise Edition Release 12.1.0.2.0 - 64bit Production  
With the Partitioning, OLAP, Advanced Analytics and Real Application Testing options ,Oracle JDBC driver 12.1.0.2.0).  
[1/8/18 14:08:22:854 IST] 0000007a SystemErr R 419 jpa-unit-rdbms INFO [server.startup : 2] openjpa.jdbc.JDBC - Connected to Oracle version 12.12 using JDBC driver Oracle JDBC driver version 12.1.0.2.0.  
[1/8/18 14:08:22:899 IST] 0000007a SystemErr R 464 jpa-unit-rdbms INFO [server.startup : 2] openjpa.Runtime - Starting OpenJPA 2.4.0  
[1/8/18 14:08:28:771 IST] 00000079 SystemErr R Some product derivations are being skipped. For information about product derivation status, run:  
java org.apache.openjpa.lib.conf.ProductDerivations  
[1/8/18 14:08:28:771 IST] 00000079 SystemErr R com.ibm.ws.persistence.WsJpaProductDerivation:java.lang.ClassNotFoundException: com.ibm.ws.persistence.WsJpaProductDerivation  
[1/8/18 14:08:28:830 IST] 00000079 SystemErr R 26 PushPU-oracle INFO [server.startup : 1] openjpa.Runtime - Starting OpenJPA 2.4.1  
[1/8/18 14:08:28:849 IST] 00000079 SystemErr R 45 PushPU-oracle INFO [server.startup : 1] openjpa.jdbc.JDBC - Using dictionary class "org.apache.openjpa.jdbc.sql.OracleDictionary".  
[1/8/18 14:08:28:864 IST] 00000079 SystemErr R 60 PushPU-oracle INFO [server.startup : 1] openjpa.jdbc.JDBC - Connected to Oracle version 12.12 using JDBC driver Oracle JDBC driver version 12.1.0.2.0.  
[1/8/18 14:08:42:921 IST] 0000007a SystemErr R Some product derivations are being skipped. For information about product derivation status, run:  
java org.apache.openjpa.lib.conf.ProductDerivations  
[1/8/18 14:08:42:921 IST] 0000007a SystemErr R com.ibm.ws.persistence.WsJpaProductDerivation:java.lang.ClassNotFoundException: com.ibm.ws.persistence.WsJpaProductDerivation  
[1/8/18 14:08:42:947 IST] 0000007a SystemErr R 9 WorklightManagementPU-oracle WARN [server.startup : 2] openjpa.Runtime - Could not create the optional validation provider. Reason returned: "A default ValidatorFactory could not be created."  
[1/8/18 14:08:42:956 IST] 0000007a SystemErr R 1 WorklightManagementPU-oracle WARN [server.startup : 2] openjpa.Runtime - Could not create the optional validation provider. Reason returned: "A default ValidatorFactory could not be created."  
[1/8/18 14:08:43:636 IST] 0000007a SystemErr R 681 WorklightManagementPU-oracle INFO [server.startup : 2] openjpa.Runtime - Starting OpenJPA 2.4.1  
[1/8/18 14:08:43:646 IST] 0000007a SystemErr R 691 WorklightManagementPU-oracle INFO [server.startup : 2] openjpa.jdbc.JDBC - Using dictionary class "org.apache.openjpa.jdbc.sql.OracleDictionary".  
[1/8/18 14:08:43:657 IST] 0000007a SystemErr R 702 WorklightManagementPU-oracle INFO [server.startup : 2] openjpa.jdbc.JDBC - Connected to Oracle version 12.12 using JDBC driver Oracle JDBC driver version 12.1.0.2.0.  
[1/8/18 14:10:18:440 IST] 00000078 SystemErr R log4j:WARN No appenders could be found for logger (org.apache.cxf.common.logging.LogUtils).  
[1/8/18 14:10:18:440 IST] 00000078 SystemErr R log4j:WARN Please initialize the log4j system properly.  
[1/8/18 14:10:18:440 IST] 00000078 SystemErr R log4j:WARN See [http://logging.apache.org/log4j/1.2/faq.html#noconfig](http://logging.apache.org/log4j/1.2/faq.html#noconfig) for more info.  
[1/8/18 14:10:22:802 IST] 00000135 SystemErr R 99864 WorklightManagementPU-oracle INFO [Default : 2] openjpa.Runtime - Starting OpenJPA 2.4.1  
[1/8/18 14:10:22:804 IST] 00000135 SystemErr R 99866 WorklightManagementPU-oracle INFO [Default : 2] openjpa.jdbc.JDBC - Using dictionary class "org.apache.openjpa.jdbc.sql.OracleDictionary".  
[1/8/18 14:10:22:808 IST] 00000135 SystemErr R 99870 WorklightManagementPU-oracle INFO [Default : 2] openjpa.jdbc.JDBC - Connected to Oracle version 12.12 using JDBC driver Oracle JDBC driver version 12.1.0.2.0.  
[1/17/18 17:32:30:066 IST] 0000016f SystemErr R java.lang.IllegalArgumentException: Illegal status value : 0  
[1/17/18 17:32:30:066 IST] 0000016f SystemErr R at org.apache.cxf.jaxrs.impl.ResponseBuilderImpl.status(ResponseBuilderImpl.java:78)  
[1/17/18 17:32:30:067 IST] 0000016f SystemErr R at javax.ws.rs.core.Response.status(Response.java:613)  
[1/17/18 17:32:30:068 IST] 0000016f SystemErr R at sun.reflect.GeneratedMethodAccessor215.invoke(Unknown Source)  
[1/17/18 17:32:30:068 IST] 0000016f SystemErr R at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:55)  
[1/17/18 17:32:30:068 IST] 0000016f SystemErr R at java.lang.reflect.Method.invoke(Method.java:508)  
[1/17/18 17:32:30:068 IST] 0000016f SystemErr R at org.springframework.web.method.support.InvocableHandlerMethod.doInvoke(InvocableHandlerMethod.java:221)

---

<div class="post-metadata">

### Author: ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)
#### Post date: [December 4, 2018, 7:37am UTC](https://discuss.elastic.co/t/error-in-logstash-gork-filter/159304/2 "2018-12-04T07:37:41Z")

</div>

My config File --

input {  
file{  
path =\> "/path/of/my/log/file/SystemErr.log"  
start\_position =\> "beginning"  
}  
}

filter {  
grok {  
match =\>  
{  
"message" =\> "%{SYSLOG5424SD:time} %{NOTSPACE:id1} %{WORD:errortype}\s\s\s\s %{WORD:id2}\s%{WORD:check}"  
}  
}

if [check] == " " {  
grok  
{  
match =\>  
{  
"message" =\> "%{WORD:id3} %{URIHOST}(%{JAVACLASS}:%{NUMBER:errorclass}) "  
}  
}  
}

if [check] == "java.\*" {  
grok  
{  
match =\>  
{  
"message" =\> "%{URIHOST}:%{CISCO\_REASON}:%{Number:statusvalue} "  
}  
}   
}

if [check] == "log4j:\*" {  
grok  
{  
match =\>  
{  
"message" =\> "log4j:WARN %{CISCO\_REASON} (%{URIHOST}). "  
}  
}   
}  
}

output {  
stdout {}  
elasticsearch{  
hosts =\> "x.x.x.x"  
index =\> "system\_error\_log\_x"  
}

}

Error in Logstash terminal

Sending Logstash logs to /app/install/logstash-6.4.2/logs which is now configured via log4j2.properties  
[2018-12-04T12:57:44,934][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-12-04T12:57:45,754][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.4.2"}  
[2018-12-04T12:57:52,267][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2018-12-04T12:57:52,804][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://x.x.x.x:9200/](http://x.x.x.x:9200/)]}}  
[2018-12-04T12:57:52,815][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://x.x.x.x:9200/](http://x.x.x.x:9200/), :path=\>"/"}  
[2018-12-04T12:57:53,059][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://x.x.x.x:9200/](http://x.x.x.x:9200/)"}  
[2018-12-04T12:57:53,127][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-12-04T12:57:53,131][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-12-04T12:57:53,170][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//x.x.x.x](https://x.x.x.x)"]}  
[2018-12-04T12:57:53,194][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-12-04T12:57:53,233][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-12-04T12:57:53,521][ERROR][logstash.pipeline] Error registering plugin {:pipeline\_id=\>"main", :plugin=\>"#\<LogStash::FilterDelegator:0x6f7a1952 @metric\_events\_out=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: out value:0, @metric\_events\_in=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: in value:0, @metric\_events\_time=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: duration\_in\_millis value:0, @id="9c030f9b6ff707c026be39d193338171a60b2c9f46176b22ee2cc685c628100a", @klass=LogStash::Filters::Grok, @metric\_events=#LogStash::Instrument::NamespacedMetric:0x3c33faa0, @filter=\<LogStash::Filters::Grok match=\>{"message"=\>"%{URIHOST}:%{CISCO\_REASON}:%{Number:statusvalue} "}, id=\>"9c030f9b6ff707c026be39d193338171a60b2c9f46176b22ee2cc685c628100a", enable\_metric=\>true, periodic\_flush=\>false, patterns\_files\_glob=\>"\*", break\_on\_match=\>true, named\_captures\_only=\>true, keep\_empty\_captures=\>false, tag\_on\_failure=\>["\_grokparsefailure"], timeout\_millis=\>30000, tag\_on\_timeout=\>"\_groktimeout"\>\>", :error=\>"pattern %{Number:statusvalue} not defined", :thread=\>"#\<Thread:0x727640eb run\>"}  
[2018-12-04T12:57:53,944][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<Grok::PatternError: pattern %{Number:statusvalue} not defined\>, :backtrace=\>["/app/install/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:123:in `block in compile'", "org/jruby/RubyKernel.java:1292:in`loop'", "/app/install/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:93:in `compile'", "/app/install/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.3/lib/logstash/filters/grok.rb:281:in`block in register'", "org/jruby/RubyArray.java:1734:in `each'", "/app/install/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.3/lib/logstash/filters/grok.rb:275:in`block in register'", "org/jruby/RubyHash.java:1343:in `each'", "/app/install/logstash-6.4.2/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.3/lib/logstash/filters/grok.rb:270:in`register'", "/app/install/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:242:in `register_plugin'", "/app/install/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:253:in`block in register\_plugins'", "org/jruby/RubyArray.java:1734:in `each'", "/app/install/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:253:in`register\_plugins'", "/app/install/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:595:in `maybe_setup_out_plugins'", "/app/install/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:263:in`start\_workers'", "/app/install/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:200:in `run'", "/app/install/logstash-6.4.2/logstash-core/lib/logstash/pipeline.rb:160:in`block in start'"], :thread=\>"#\<Thread:0x727640eb run\>"}  
[2018-12-04T12:57:53,968][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}  
[user@server bin]$

Please let me know i'm doing it in a right way (or) Guide me how to read the above log

---

<div class="post-metadata">

### Author: ![Sripal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sripal/32/36704_2.png) [@Sripal](https://discuss.elastic.co/u/Sripal)
#### Post date: [December 4, 2018, 7:39am UTC](https://discuss.elastic.co/t/error-in-logstash-gork-filter/159304/3 "2018-12-04T07:39:01Z")

</div>

Appreciate your response 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 1, 2019, 7:39am UTC](https://discuss.elastic.co/t/error-in-logstash-gork-filter/159304/4 "2019-01-01T07:39:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
