# \[ERROR\]\[logstash.agent\] "Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"input\\", \\"filter\\", \\"output\\" at line 1, column 1 (byte 1)"

**URL:** <https://discuss.elastic.co/t/error-logstash-agent-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/269515>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [April 7, 2021, 7:21pm UTC](https://discuss.elastic.co/t/error-logstash-agent-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/269515 "2021-04-07T19:21:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eng.Lucy](https://avatars.discourse-cdn.com/v4/letter/e/7cd45c/32.png) [@Eng.Lucy](https://discuss.elastic.co/u/Eng.Lucy)\
**Post date:** [April 7, 2021, 7:21pm UTC](https://discuss.elastic.co/t/error-logstash-agent-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/269515/1 "2021-04-07T19:21:11Z")

</div>

I run logstash in a Docker container and occurs a error:  
``[ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "input", "filter", "output" at line 1, column 1 (byte 1)", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:184:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:69:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:389:in `block in converge\_state'"]}

```
My conf file is:
   input{
          http_poller{
            urls => {
              users => {
                method => get
                url => "https://randomuser.me/api"
                headers => {
                  Accept => "application/json"
                }
              }
            }
            request_timeout => 60
            schedule => {every => "20s"}
            codec => "json"
          }
        }

    filter{
      split{
        field => "results"
      }
    }

    output{
      elasticsearch{
        hosts => "elasticsearch:9200"
        index => "testeapi"
      }
      stdout{ }
    }

```

I used a docker-compose to create the containers for Elasticsearch, Logstash and Kibana. The docker-compose.yml is:

```
version: '3.2'
services:
  elasticsearch:
    build:
      context: elasticsearch/
      args:
        ELK_VERSION: $ELK_VERSION
    volumes:
      - type: bind
        source: ./elasticsearch/config/elasticsearch.yml
        target: /usr/share/elasticsearch/config/elasticsearch.yml
        read_only: true
      - type: volume
        source: elasticsearch
        target: /usr/share/elasticsearch/data
    ports:
      - "9200:9200"
      - "9300:9300"
    environment:
      ES_JAVA_OPTS: "-Xmx256m -Xms256m"
      ELASTIC_PASSWORD: changeme
      # Use single node discovery in order to disable production mode and avoid bootstrap checks.
      # see: https://www.elastic.co/guide/en/elasticsearch/reference/current/bootstrap-checks.html
      discovery.type: single-node
    networks:
      - elk

  logstash:
    build:
      context: logstash/
      args:
        ELK_VERSION: $ELK_VERSION
    volumes:
      - type: bind
        source: ./logstash/config/logstash.yml
        target: /usr/share/logstash/config/logstash.yml
        read_only: true
      - type: bind
        source: ./logstash/pipeline
        target: /usr/share/logstash/pipeline
        read_only: true
    ports:
      - "5044:5044"
      - "5000:5000/tcp"
      - "5000:5000/udp"
      - "9600:9600"
    environment:
      LS_JAVA_OPTS: "-Xmx256m -Xms256m"
    networks:
      - elk
    depends_on:
      - elasticsearch

  kibana:
    build:
      context: kibana/
      args:
        ELK_VERSION: $ELK_VERSION
    volumes:
      - type: bind
        source: ./kibana/config/kibana.yml
        target: /usr/share/kibana/config/kibana.yml
        read_only: true
    ports:
      - "5601:5601"
    networks:
      - elk
    depends_on:
      - elasticsearch
networks:
  elk:
    driver: bridge
volumes:
  elasticsearch:

```

I need i need your help to find my error.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 7, 2021, 8:04pm UTC](https://discuss.elastic.co/t/error-logstash-agent-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/269515/2 "2021-04-07T20:04:35Z")

</div>

> [@Eng.Lucy](#):
>
> I need i need your help to find my error.

How are you setting path.config and what is its value?

It could be your configuration file has a byte-order-mark as the first byte.

If you are pointing path.config at a directory then logstash will concatenate every file in the directory. If the first file (alphabetically) is not a configuration file it could cause this error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 5, 2021, 8:04pm UTC](https://discuss.elastic.co/t/error-logstash-agent-expected-one-of-t-r-n-input-filter-output-at-line-1-column-1-byte-1/269515/3 "2021-05-05T20:04:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
