# \[ERROR\]\[logstash.agent\] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \\"and\\", \\"or\\", \\"xor\\", \\"nand\\",

**URL:** <https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599>\
**Category:** Logstash\
**Created:** [January 6, 2023, 7:22am UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599 "2023-01-06T07:22:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![SP003](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sp003/32/112159_2.png) [@SP003](https://discuss.elastic.co/u/SP003)\
**Post date:** [January 6, 2023, 7:22am UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599/1 "2023-01-06T07:22:36Z")

</div>

Hello experts,

I am setting up filebeat, logstash for my log monitoring work. (Linux system)

Getting below error on filebeat.  
--\> systemctl status filebeat - getting error  
--\> systemctl status logstash - Running fine.

**Error :**

```auto
[2023-01-05T08:10:42,132][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"and\", \"or\", \"xor\", \"nand\", \"{\" at line 23, column 9 (byte 649) after filter\n{\n if [id] == \"Filebeat_AnalyticsMonitoringGrafanaLog\"\n {\n grok {\n match => { \"message\" => \"%{TIMESTAMP_ISO8601:logTime} %{LOGLEVEL:logLevel} %{GREEDYDATA:message}\" }\n }\n }\n else if [id] == \"Filebeat_AnalyticsMonitoringInfluxDBLog\"\n {\n grok {\n match => { \"message\" => \"%{MONTH} %{NUMBER} %{TIME} %{HOSTNAME:host} influxd-systemd-start.sh\\[%{NUMBER}\\]: ts=%{TIMESTAMP_ISO8601:logTime} lvl=%{LOGLEVEL:logLevel} %{GREEDYDATA:message} \" }\n }\n }\n else if [id] == \"Filebeat_AnalyticsMonitoringKomdoLog\"\n \n ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:210:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:48:in `initialize'", "org/jruby/RubyClass.java:911:in `new'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:50:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:381:in `block in converge_state'"]}
[2023-01-05T08:10:42,189][INFO][logstash.runner] Logstash shut down.
[2023-01-05T08:10:42,198][FATAL][org.logstash.Logstash] Logstash stopped processing because of an error: (SystemExit) exit
org.jruby.exceptions.SystemExit: (SystemExit) exit
        at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:790) ~[jruby.jar:?]
        at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:753) ~[jruby.jar:?]

```

Logstash configuration : (logs.conf)  
Here I am configuring grok pattern for multiple sources of logs using nested if, and filtering based on log id defined in filebeat.yml.

```auto
input {
  beats {
    port => 5044
  }
}
 
filter
{
    if [id] == "Filebeat_AnalyticsMonitoringGrafanaLog"
    {
        grok {
                match => { "message" => "%{TIMESTAMP_ISO8601:logTime} %{LOGLEVEL:logLevel} %{GREEDYDATA:message}" }
             }
    }
    else if [id] == "Filebeat_AnalyticsMonitoringInfluxDBLog"
    {
       grok {
               match => { "message" => "%{MONTH} %{NUMBER} %{TIME} %{HOSTNAME:host} influxd-systemd-start.sh\[%{NUMBER}\]: ts=%{TIMESTAMP_ISO8601:logTime} lvl=%{LOGLEVEL:logLevel} %{GREEDYDATA:message} " }
            }
    }
    else if [id] == "Filebeat_AnalyticsMonitoringKomdoLog"
     {
        grok {
                match => { "message" => "%{TIMESTAMP_ISO8601:logTime} - Komodo - %{LOGLEVEL:logLevel} - \[%{WORD:class}\] - %{GREEDYDATA:message}" }
             }
   }
    date{
        match => ["logtime", "yyyy-MM-dd HH:mm:ss", "ISO8601"]
        timezone => "Europe/Dublin"
        target => "@timestamp"
    }
}
 
output {
  elasticsearch {
      hosts => ["localhost:9200"]
      index => "logs-%{+YYYY.MM.dd}"
  }
}

**Filebeat.yml** 

```

`########################### Filebeat Configuration #############################`

`# ============================== Filebeat inputs ===============================`

`filebeat.inputs:`

`# Grafana Log Settings`

`- ` `type` `: log`

` ` `multiline.` `type` `: pattern`

`# Pattern for Grafana log StackTrace`

` ` `multiline.negate: ` `false`

` ` `multiline.match: after`

` ` `id` `: Filebeat_AnalyticsMonitoringGrafanaLog`

` ` `enabled: ` `true`

` ` `paths:`

`# Log location:`

` ` `- ` `"/var/log/grafana/*.log"`

` `

` ` `# InfluxDB Log Settings`

`- ` `type` `: log`

` ` `multiline.` `type` `: pattern`

`# Pattern for Grafana log StackTrace`

` ` `multiline.negate: ` `false`

` ` `multiline.match: after`

` ` `id` `: Filebeat_AnalyticsMonitoringInfluxDBLog`

` ` `enabled: ` `true`

` ` `paths:`

`# Log location:`

` ` `- ` `"/var/log/influxdb/*.log"`

` ` `# komodo Log Settings`

`- ` `type` `: log`

` ` `multiline.` `type` `: pattern`

`# Pattern for komodo log StackTrace`

` ` `multiline.negate: ` `false`

` ` `multiline.match: after`

` ` `id` `: Filebeat_AnalyticsMonitoringKomdoLog`

` ` `enabled: ` `true`

` ` `paths:`

`# Log location:`

` ` `- ` `"/opt/komodo/log/*.log"`

` ` `# ======================= Elasticsearch template setting =======================`

` `

`setup.template.settings:`

` ` `index.number_of_shards: 1`

` `

`# ================================== Outputs ===================================`

`# ------------------------------ Logstash Output -------------------------------`

`output.logstash:`

` ` `# The Logstash hosts`

` ` `hosts: [` `"logstash"` `]`

` `

` ` `# Optional SSL. By default is off.`

` ` `# List of root certificates for HTTPS server verifications`

` ` `#ssl.certificate_authorities: ["/etc/pki/root/ca.pem"]`

` `

` ` `# Certificate for SSL client authentication`

` ` `#ssl.certificate: "/etc/pki/client/cert.pem"`

` `

` ` `# Client Certificate Key`

` ` `#ssl.key: "/etc/pki/client/cert.key"`

` `

`# ================================= Processors =================================`

`processors:`

` ` `- add_host_metadata:`

` ` `when.not.contains.tags: forwarded`

` ` `- add_cloud_metadata: ~`

` ` `- add_docker_metadata: ~`

` ` `- add_kubernetes_metadata: ~`

---

<div class="post-metadata">

**Author:** ![anon90868141](https://avatars.discourse-cdn.com/v4/letter/a/7ab992/32.png) [@anon90868141](https://discuss.elastic.co/u/anon90868141)\
**Post date:** [January 6, 2023, 7:51am UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599/2 "2023-01-06T07:51:02Z")

</div>

> [@SP003](#):
>
> ```auto
> else if [id] == "Filebeat_AnalyticsMonitoringKomdoLog"
>      
> 
> ```

you're missing an opening bracket, should be

```auto
    else if [id] == "Filebeat_AnalyticsMonitoringKomdoLog"
    { 
        grok {

```

---

<div class="post-metadata">

**Author:** ![SP003](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sp003/32/112159_2.png) [@SP003](https://discuss.elastic.co/u/SP003)\
**Post date:** [January 6, 2023, 8:08am UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599/3 "2023-01-06T08:08:09Z")

</div>

Thank you @Ossenfeld for your response. But that's a by-mistake missed in my post. But after that, I am getting the same configuration error.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 6, 2023, 10:25am UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599/4 "2023-01-06T10:25:54Z")

</div>

Hi,

> [@SP003](#):
>
> --\> systemctl status filebeat - getting error  
> --\> systemctl status logstash - Running fine.

Systemd status are not really worth looking for if your logs are full of errors and logstash is constantly restarting.

When starting logstash from fresh do you observe any errors in /var/log/logstash/logstash-plain.log ?

And for your filebeat configuration since it's yml could you edit your post and make it inside a preformatted code text ? The way it is now makes it quite hard to read/debug.

Where are the filebeat errors ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 6, 2023, 5:05pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599/5 "2023-01-06T17:05:48Z")

</div>

> [@SP003](#):
>
> But after that, I am getting the same configuration error.

That's hard to believe. You are saying you still get exactly this?

> "Expected one of [\t\r\n], "#", "and", "or", "xor", "nand", "{" at line 23, column 9 (byte 649)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 10, 2023, 1:52pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599/7 "2023-01-10T13:52:52Z")

</div>

Your .conf is fine, LS has started on my host without any problems.

```auto
[2023-01-10T14:51:18,641][INFO][logstash.javapipeline][main] Pipeline Java execution initialization time {"seconds"=>0.85}
[2023-01-10T14:51:18,656][INFO][logstash.inputs.beats][main] Starting input listener {:address=>"0.0.0.0:5044"}
[2023-01-10T14:51:18,671][INFO][logstash.javapipeline][main] Pipeline started {"pipeline.id"=>"main"}
[2023-01-10T14:51:18,761][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[2023-01-10T14:51:18,795][INFO][org.logstash.beats.Server][main][ce2fdef9acde0537739293792994b1a1ae0e29b3fd140617598905f53b5d65d3] Starting server on port: 5044

```

---

<div class="post-metadata">

**Author:** ![SP003](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sp003/32/112159_2.png) [@SP003](https://discuss.elastic.co/u/SP003)\
**Post date:** [January 11, 2023, 3:50pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599/8 "2023-01-11T15:50:28Z")

</div>

> [@Rios](#):
>
> s fine, LS has started on my host without any problems.

@Rios Thank you ! yes its working fine for me as well. Had some minor mistakes.  
Thanks again!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2023, 3:51pm UTC](https://discuss.elastic.co/t/error-logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror-message-expected-one-of-t-r-n-and-or-xor-nand/322599/9 "2023-02-08T15:51:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
