# \[ERROR\]\[logstash.instrument.periodicpoller.jvm\] Periodi cPoller: exception

**URL:** <https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281>\
**Category:** Logstash\
**Created:** [July 7, 2017, 2:08pm UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281 "2017-07-07T14:08:01Z")\
**Posts on this page:** 15\
**Page:** 2

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2017, 10:24am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/21 "2017-07-14T10:24:29Z")

</div>

Since your line begins with a # this is treated as an empty first column. You can either strip the first # on the line by using a mutate filter's gsub option or add a dummy column as the first column.

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [July 14, 2017, 2:38pm UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/22 "2017-07-14T14:38:06Z")

</div>

I am using below config file  
input {  
beats {  
port =\> 5042  
codec =\> multiline  
{  
pattern =\> "^#2.0"  
what =\> "previous"  
negate =\>"true"  
charset =\> "ISO-8859-1"  
} } }  
filter {  
csv {  
separator =\> "#"  
columns =\> ["m0","m1","DateTime","Timezone","Severity","Category","m6","CustomerMessageComponent","RuntimeComponent" ,"LogID","CorrelationID","Application","Location","User","Session","m2","PassportSession","PassportUserActivityID","PassportConnection","PassportConnectionCounter","Thread","m4","m5","ErrorMessage"]

}  
}  
output {  
if "trace" in [type]{  
elasticsearch {  
hosts =\> ["10.103.20.64"]  
index =\> "csvconfignine"  
} } }

After using this I am getting correct data in first 5 fields after that m6 field is blank and rest of the fields ("CustomerMessageComponent","RuntimeComponent" ,"LogID","CorrelationID","Application","Location","User","Session","m2","PassportSession","PassportUserActivityID","PassportConnection","PassportConnectionCounter","Thread","m4","m5","ErrorMessage") are not visible in kibana.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/2/1/214b262b86d5e2ba6755880493cad7237ba27cb0.png)

What is missing in config file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2017, 2:44pm UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/23 "2017-07-14T14:44:35Z")

</div>

Please copy/paste the raw JSON document instead of posting Kibana screenshots. The easiest way of getting that is by expanding a single event and navigating to its JSON tab.

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [July 14, 2017, 2:45pm UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/24 "2017-07-14T14:45:36Z")

</div>

**Sample Data**

> #2.0#2017 07 11 01:04:32:391#0-500#Error#com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment#  
> #BC-ESI-WS-JAV-RT#webservices\_lib#C0008F16D17A00740000000400001D48#29014150000000005#[sap.com/com.sap.xi.mdt.beans#com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment#SM\_COLL\_GTA#51##D489991E65FD11E7BC6A000001BAB886#d489991e65fd11e7bc6a000001bab886##0#Thread](http://sap.com/com.sap.xi.mdt.beans#com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment#SM_COLL_GTA#51##D489991E65FD11E7BC6A000001BAB886#d489991e65fd11e7bc6a000001bab886##0#Thread)[HTTP Worker [@224911809],5,Dedicated\_Application\_Thread]#Plain##  
> process()  
> [EXCEPTION]  
> com.sap.engine.interfaces.webservices.runtime.RuntimeProcessException: javax.ejb.EJBAccessException: ASJ.ejb.005045 (Failed in component: [sap.com/com.sap.xi.mdt.beans](http://sap.com/com.sap.xi.mdt.beans), BC-XI-IS-WKB) ASJ.ejb.003001 Principal: SM\_COLL\_GTA (authentication method: password), policyContextID: [sap.com/com.sap.xi.mdt.beans](http://sap.com/com.sap.xi.mdt.beans)_com\_sap.xpi.mdt.afbean.jar, permission.name: AdapterMessageMonitoringBean, permission.actions: getMessageList,Remote,com.sap.aii.mdt.server.adapterframework.ws.AdapterFilter,java.lang.Integer  
> at com.sap.engine.services.ejb3.webservice.impl.DefaultImplementationContainer.invokeMethod(DefaultImplementationContainer.java:195)  
> at com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment.process0(RuntimeProcessingEnvironment.java:710)  
> at com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment.preProcess(RuntimeProcessingEnvironment.java:662)  
> at com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment.process(RuntimeProcessingEnvironment.java:322)  
> at com.sap.engine.services.webservices.runtime.servlet.ServletDispatcherImpl.doPostWOLogging(ServletDispatcherImpl.java:199)  
> at com.sap.engine.services.webservices.runtime.servlet.ServletDispatcherImpl.doPost(ServletDispatcherImpl.java:65)  
> at com.sap.engine.services.webservices.servlet.SoapServlet.doPost(SoapServlet.java:61)  
> at javax.servlet.http.HttpServlet.service(HttpServlet.java:754)  
> at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)  
> at com.sap.engine.services.servlets\_jsp.server.Invokable.invoke(Invokable.java:152)  
> at com.sap.engine.services.servlets\_jsp.server.Invokable.invoke(Invokable.java:38)  
> at com.sap.engine.services.servlets\_jsp.server.HttpHandlerImpl.runServlet(HttpHandlerImpl.java:466)  
> at com.sap.engine.services.servlets\_jsp.server.HttpHandlerImpl.handleRequest(HttpHandlerImpl.java:210)  
> at com.sap.engine.services.httpserver.server.RequestAnalizer.startServlet(RequestAnalizer.java:441)  
> at com.sap.engine.services.httpserver.server.RequestAnalizer.startServlet(RequestAnalizer.java:430)  
> at com.sap.engine.services.servlets\_jsp.filters.DSRWebContainerFilter.process(DSRWebContainerFilter.java:38)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.servlets\_jsp.filters.ServletSelector.process(ServletSelector.java:81)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.servlets\_jsp.filters.ApplicationSelector.process(ApplicationSelector.java:278)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.httpserver.filters.WebContainerInvoker.process(WebContainerInvoker.java:81)  
> at com.sap.engine.services.httpserver.chain.HostFilter.process(HostFilter.java:9)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.httpserver.filters.DefineHostFilter.process(DefineHostFilter.java:27)  
> at com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.httpserver.filters.MonitoringFilter.process(MonitoringFilter.java:29)  
> at com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.httpserver.filters.SessionSizeFilter.process(SessionSizeFilter.java:26)  
> at com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.httpserver.filters.MemoryStatisticFilter.process(MemoryStatisticFilter.java:57)  
> at com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.httpserver.filters.DSRHttpFilter.process(DSRHttpFilter.java:43)  
> at com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)  
> at com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)  
> at com.sap.engine.services.httpserver.server.Processor.chainedRequest(Processor.java:468)  
> at com.sap.engine.services.httpserver.server.Processor$FCAProcessorThread.process(Processor.java:262)  
> at com.sap.engine.services.httpserver.server.rcm.RequestProcessorThread.run(RequestProcessorThread.java:56)  
> at com.sap.engine.core.thread.execution.Executable.run(Executable.java:122)  
> at com.sap.engine.core.thread.execution.Executable.run(Executable.java:101)  
> at com.sap.engine.core.thread.execution.CentralExecutor$SingleThread.run(CentralExecutor.java:328)  
> Caused by: javax.ejb.EJBAccessException: ASJ.ejb.005045 (Failed in component: [sap.com/com.sap.xi.mdt.beans](http://sap.com/com.sap.xi.mdt.beans), BC-XI-IS-WKB) ASJ.ejb.003001 Principal: SM\_COLL\_GTA (authentication method: password), policyContextID: [sap.com/com.sap.xi.mdt.beans](http://sap.com/com.sap.xi.mdt.beans)_com\_sap.xpi.mdt.afbean.jar, permission.name: AdapterMessageMonitoringBean, permission.actions: getMessageList,Remote,com.sap.aii.mdt.server.adapterframework.ws.AdapterFilter,java.lang.Integer  
> at com.sap.engine.services.ejb3.runtime.impl.Interceptors\_SecurityCheck.invoke(Interceptors\_SecurityCheck.java:22)  
> at com.sap.engine.services.ejb3.runtime.impl.AbstractInvocationContext.proceed(AbstractInvocationContext.java:179)  
> at com.sap.engine.services.ejb3.runtime.impl.Interceptors\_ExceptionTracer.invoke(Interceptors\_ExceptionTracer.java:17)  
> at com.sap.engine.services.ejb3.runtime.impl.AbstractInvocationContext.proceed(AbstractInvocationContext.java:179)  
> at com.sap.engine.services.ejb3.runtime.impl.DefaultInvocationChainsManager.startChain(DefaultInvocationChainsManager.java:138)  
> at com.sap.engine.services.ejb3.webservice.impl.DefaultImplementationContainer.invokeMethod(DefaultImplementationContainer.java:186)  
> ... 44 more

> #

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [July 14, 2017, 2:48pm UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/25 "2017-07-14T14:48:06Z")

</div>

Sure

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2017, 5:14pm UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/26 "2017-07-14T17:14:29Z")

</div>

> Sample Data

What? No! That's not what I asked for. Please reread my post.

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [July 17, 2017, 4:10am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/27 "2017-07-17T04:10:56Z")

</div>

JSON:-  
{  
"\_index": "csvconfigeight",  
"\_type": "trace",  
"\_id": "AV1BcJ3FyFBSkX8Zak1K",  
"\_score": null,  
"\_source": {  
"Timezone": "0-500",  
"m0": null,  
"Category": "com.sap.engine.services.ejb3.runtime",  
"offset": 10465895,  
"m1": "2.0\b",  
"input\_type": "log",  
"m6": null,  
"Severity": "Error",  
"source": "D:\png\logfiles\sap\test\defaultTrace\_00.18.trc",  
"message": "#2.0\b#2017 07 11 12:18:34:911#0-500#Error#com.sap.engine.services.ejb3.runtime#\ncom.sap.ASJ.ejb.005017#BC-JAS-EJB#ejb#C0008F16D17A048C0000000300001D48#29014150000000005#[sap.com/com.sap.xi.mdt.beans#com.sap.engine.services.ejb3.runtime#SM\_COLL\_GTA#919##FE215112665B11E7C302000001BAB886#fe215112665b11e7c302000001bab886##0#Thread](http://sap.com/com.sap.xi.mdt.beans#com.sap.engine.services.ejb3.runtime#SM_COLL_GTA#919##FE215112665B11E7C302000001BAB886#fe215112665b11e7c302000001bab886##0#Thread)[HTTP Worker [@224911809],5,Dedicated\_Application\_Thread]#Plain##\nSystem exception \n[EXCEPTION]\njavax.ejb.EJBAccessException: ASJ.ejb.005045 (Failed in component: [sap.com/com.sap.xi.mdt.beans](http://sap.com/com.sap.xi.mdt.beans), BC-XI-IS-WKB) ASJ.ejb.003001 Principal: SM\_COLL\_GTA (authentication method: password), policyContextID: [sap.com/com.sap.xi.mdt.beans\*com\_sap.xpi.mdt.afbean.jar](http://sap.com/com.sap.xi.mdt.beans*com_sap.xpi.mdt.afbean.jar), [permission.name](http://permission.name): AdapterMessageMonitoringBean, permission.actions: getMessageList,Remote,com.sap.aii.mdt.server.adapterframework.ws.AdapterFilter,java.lang.Integer\n\tat com.sap.engine.services.ejb3.runtime.impl.Interceptors\_SecurityCheck.invoke(Interceptors\_SecurityCheck.java:22)\n\tat com.sap.engine.services.ejb3.runtime.impl.AbstractInvocationContext.proceed(AbstractInvocationContext.java:179)\n\tat com.sap.engine.services.ejb3.runtime.impl.Interceptors\_ExceptionTracer.invoke(Interceptors\_ExceptionTracer.java:17)\n\tat com.sap.engine.services.ejb3.runtime.impl.AbstractInvocationContext.proceed(AbstractInvocationContext.java:179)\n\tat com.sap.engine.services.ejb3.runtime.impl.DefaultInvocationChainsManager.startChain(DefaultInvocationChainsManager.java:138)\n\tat com.sap.engine.services.ejb3.webservice.impl.DefaultImplementationContainer.invokeMethod(DefaultImplementationContainer.java:186)\n\tat com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment.process0(RuntimeProcessingEnvironment.java:710)\n\tat com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment.preProcess(RuntimeProcessingEnvironment.java:662)\n\tat com.sap.engine.services.webservices.espbase.server.runtime.RuntimeProcessingEnvironment.process(RuntimeProcessingEnvironment.java:322)\n\tat com.sap.engine.services.webservices.runtime.servlet.ServletDispatcherImpl.doPostWOLogging(ServletDispatcherImpl.java:199)\n\tat com.sap.engine.services.webservices.runtime.servlet.ServletDispatcherImpl.doPost(ServletDispatcherImpl.java:65)\n\tat com.sap.engine.services.webservices.servlet.SoapServlet.doPost(SoapServlet.java:61)\n\tat javax.servlet.http.HttpServlet.service(HttpServlet.java:754)\n\tat javax.servlet.http.HttpServlet.service(HttpServlet.java:847)\n\tat com.sap.engine.services.servlets\_jsp.server.Invokable.invoke(Invokable.java:152)\n\tat com.sap.engine.services.servlets\_jsp.server.Invokable.invoke(Invokable.java:38)\n\tat com.sap.engine.services.servlets\_jsp.server.HttpHandlerImpl.runServlet(HttpHandlerImpl.java:466)\n\tat com.sap.engine.services.servlets\_jsp.server.HttpHandlerImpl.handleRequest(HttpHandlerImpl.java:210)\n\tat com.sap.engine.services.httpserver.server.RequestAnalizer.startServlet(RequestAnalizer.java:441)\n\tat com.sap.engine.services.httpserver.server.RequestAnalizer.startServlet(RequestAnalizer.java:430)\n\tat com.sap.engine.services.servlets\_jsp.filters.DSRWebContainerFilter.process(DSRWebContainerFilter.java:38)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.servlets\_jsp.filters.ServletSelector.process(ServletSelector.java:81)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.servlets\_jsp.filters.ApplicationSelector.process(ApplicationSelector.java:278)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.httpserver.filters.WebContainerInvoker.process(WebContainerInvoker.java:81)\n\tat com.sap.engine.services.httpserver.chain.HostFilter.process(HostFilter.java:9)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.httpserver.filters.DefineHostFilter.process(DefineHostFilter.java:27)\n\tat com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.httpserver.filters.MonitoringFilter.process(MonitoringFilter.java:29)\n\tat com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.httpserver.filters.SessionSizeFilter.process(SessionSizeFilter.java:26)\n\tat com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.httpserver.filters.MemoryStatisticFilter.process(MemoryStatisticFilter.java:57)\n\tat com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.httpserver.filters.DSRHttpFilter.process(DSRHttpFilter.java:43)\n\tat com.sap.engine.services.httpserver.chain.ServerFilter.process(ServerFilter.java:12)\n\tat com.sap.engine.services.httpserver.chain.AbstractChain.process(AbstractChain.java:78)\n\tat com.sap.engine.services.httpserver.server.Processor.chainedRequest(Processor.java:468)\n\tat com.sap.engine.services.httpserver.server.Processor$FCAProcessorThread.process(Processor.java:262)\n\tat com.sap.engine.services.httpserver.server.rcm.RequestProcessorThread.run(RequestProcessorThread.java:56)\n\tat com.sap.engine.core.thread.execution.Executable.run(Executable.java:122)\n\tat com.sap.engine.core.thread.execution.Executable.run(Executable.java:101)\n\tat com.sap.engine.core.thread.execution.CentralExecutor$SingleThread.run(CentralExecutor.java:328)\n\n#",  
"type": "trace",  
"DateTime": "2017 07 11 12:18:34:911",  
"tags": [  
"multiline",  
"beats\_input\_codec\_multiline\_applied"  
],  
"@timestamp": "2017-07-14T14:11:14.024Z",  
"@version": "1",  
"beat": {  
"hostname": "INFARSZC90433",  
"name": "INFARSZC90433",  
"version": "5.2.2"  
},  
"host": "INFARSZC90433"  
},  
"fields": {  
"@timestamp": [  
1500041474024  
]  
},  
"sort": [  
1500041474024  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 17, 2017, 8:42am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/28 "2017-07-17T08:42:29Z")

</div>

The reason the CSV parsing stops after the m6 column is the newline character. This is a known bug (below). You're using Filebeat to collect the logs, right? If so you might be able to work around the bug by moving the multiline processing to Filebeat. You should do that anyway since it'll be more reliable, but if it also solves this problem then all the better.

> <https://github.com/logstash-plugins/logstash-filter-csv/issues/34>

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [July 17, 2017, 10:31am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/29 "2017-07-17T10:31:53Z")

</div>

It won't work for me.They said "I believe the spec was - only if it was enclosed in quotes." and my data is not enclosed in quotes.  
Could you please suggest me some solution with existing grok pattern?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 18, 2017, 6:31am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/30 "2017-07-18T06:31:44Z")

</div>

You should be able to use a grok expression like this:

```
(?<column1>[^#]*)#(?<column2>[^#]*)#...

```

That is, capture into each column sequences of characters of any kind _except_ #, which is the column separator.

Over and out.

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [July 20, 2017, 11:45am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/31 "2017-07-20T11:45:12Z")

</div>

Hi,  
I tried above grok pattern.My config file is ![](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb76ab972be08190068126a5f2d7c61bd7d8e580.png)

```
   beats {
	port => 5042
	 codec => multiline
         {
          pattern => "^#2.0"
          what => "previous"
          negate =>"true"
		  charset => "ISO-8859-1"
         }
}

```

}  
filter  
{  
if "trc-prd" in [type]{  
grok {  
match =\> {"message" =\> "#(?\<prd\_m1\>[^#]_)#(?\<prd\_DateTime\>[^#]_)#(?\<prd\_Timezone\>[^#]_)#(?\<prd\_Severity\>[^#]_)#(?\<prd\_Category\>[^#]_)#(?\<prd\_m6\>[^#]_)#(?\<prd\_CustomerMessageComponent\>[^#]_)#(?\<prd\_RuntimeComponent\>[^#]_)#(?\<prd\_LogID\>[^#]_)#(?\<prd\_CorrelationID\>[^#]_)#(?\<prd\_Application\>[^#]_)#(?\<prd\_Location\>[^#]_)#(?\<prd\_User\>[^#]_)#(?\<prd\_Session\>[^#]_)#(?\<prd\_m2\>[^#]_)#(?\<prd\_PassportSession\>[^#]_)#(?\<prd\_PassportUserActivityID\>[^#]_)#(?\<prd\_PassportConnection\>[^#]_)#(?\<prd\_PassportConnectionCounter\>[^#]_)#(?\<prd\_Thread\>[^#]_)#(?\<prd\_m4\>[^#]_)#(?\<prd\_m5\>[^#]_)#(?\<prd\_ErrorMessage\>[^#]\*)#"}  
}   
mutate  
{  
#remove\_tag =\> ["multiline"],  
remove\_field =\> ["prd\_m1","prd\_m4","prd\_m6","prd\_m2","prd\_m5"]  
strip =\> ["prd\_DateTime"]  
}  
date {  
match =\> ["prd\_DateTime", "YYYY MM dd HH:mm:ss:SSS"]  
timezone =\> "EST"  
target =\> "prd\_DateTime"  
}  
}  
}   
output {

```
if "trc-prd" in [type]{
	elasticsearch {
		hosts => ["10.103.20.64"]
		index => "sap-trace-app-logs-k8p"  
	}
}

```

}

But still I am facing same issue.  
reason"=\>"Document contains at least one immense term in  
field="prd\_ErrorMessage" (whose UTF8 encoding is longer than the max length 32  
766), all of which were skipped. Please correct the analyzer to not produce suc  
h terms. The prefix of the first immense term is: '[10, 80, 114, 105, 99, 101,  
69, 120, 112, 108, 111, 115, 105, 111, 110, 66, 101, 97, 110, 32, 87, 83, 58, 72  
, 97, 115, 104, 32, 109, 97]...', original message: bytes can be at most 32766 i  
n length; got 43526", "caused\_by"=\>{"type"=\>"max\_bytes\_length\_exceeded\_exception  
", "reason"=\>"bytes can be at most 32766 in length; got 43526"}}}}}

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [July 20, 2017, 12:08pm UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/32 "2017-07-20T12:08:34Z")

</div>

I am loading log files from 4 sources(K2P,K8P,K2Q and K8Q) and 7 servers. Filebeat is running separately on each source.Volume of data is too high.  
Is there anything in filebeat to manage data load.I am reading three type of file defaultTrace\ __.trc,applications\__.log,security\_00.\*.log but format of data is same in all the log files.

Please suggest something to resolve this.

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [August 11, 2017, 8:58am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/33 "2017-08-11T08:58:31Z")

</div>

Hi ,  
I used new grok pattern suggested by you but still I am facing timeout error.

> [2017-08-10T22:02:21,185][ERROR][logstash.instrument.periodicpoller.jvm] Periodi  
> cPoller: exception {:poller=\>#\<LogStash::Instrument::PeriodicPoller::JVM:0x611eb  
> cfa @task=#\<Concurrent::TimerTask:0x5d444bd3 @observers=#\<Concurrent::Collection  
> ::CopyOnNotifyObserverSet:0x599dd9b8 @observers={#\<LogStash::Instrument::Periodi  
> cPoller::JVM:0x611ebcfa ...\>=\>:update}\>, @timeout\_interval=60.0, @running=#, @StoppedEvent=#\<Concurrent::Event:0x62df52cb  
> @set=false, @iteration=0\>, @execution\_interval=1.0, @do\_nothing\_on\_deref=true, @  
> run\_now=nil, @freeze\_on\_deref=nil, @executor=#\<Concurrent::SafeTaskExecutor:0x55  
> 381731 @task=#\<Proc:0x2e07be91@G:/ELK\_Softwares/exe/logstash-5.0.0-truncate/logs  
> tash-5.0.0/logstash-core/lib/logstash/instrument/periodic\_poller/base.rb:52\>, @e  
> xception\_class=StandardError\>, @StopEvent=#\<Concurrent::Event:0x67b7aa55 @set=fa  
> lse, @iteration=0\>, @value=nil, @copy\_on\_deref=nil, @dup\_on\_deref=nil\>, @peak\_th  
> reads=55, @peak\_open\_fds=-1, @metric=#\<LogStash::Instrument::Metric:0x7f66e562 @  
> collector=#\<LogStash::Instrument::Collector:0x65e1c98c @agent=nil, @metric\_store  
> =#\<LogStash::Instrument::MetricStore:0x6af2e420 @store=#\<Concurrent:🗺0x79923  
> cd9 @default\_proc=nil\>, @structured\_lookup\_mutex=#Mutex:0x23add4bc, @fast\_look  
> up=#\<Concurrent:🗺0x6b28785e @default\_proc=nil\>\>, @observer\_state=false, @sna  
> pshot\_task=#\<Concurrent::TimerTask:0x168642ff @observers=#\<Concurrent::Collectio  
> n::CopyOnNotifyObserverSet:0x7e1ac002 @observers={#\<LogStash::Instrument::Collec  
> tor:0x65e1c98c ...\>=\>:update}\>, @timeout\_interval=600.0, @running=#\<Concurrent::  
> AtomicBoolean:0x1b1d87e4\>, @StoppedEvent=#\<Concurrent::Event:0x3fa8afc2 @set=fal  
> se, @iteration=0\>, @execution\_interval=1.0, @do\_nothing\_on\_deref=true, @run\_now=  
> nil, @freeze\_on\_deref=nil, @executor=#\<Concurrent::SafeTaskExecutor:0x179a62e5 @  
> task=#\<Proc:0x5b930ef4@G:/ELK\_Softwares/exe/logstash-5.0.0-truncate/logstash-5.0  
> .0/logstash-core/lib/logstash/instrument/collector.rb:87\>, @exception\_class=Stan  
> dardError\>, @StopEvent=#\<Concurrent::Event:0x2c4690c5 @set=false, @iteration=0\>,  
> @value=false, @copy\_on\_deref=nil, @dup\_on\_deref=nil\>\>\>, @options={:polling\_inte  
> rval=\>1, :polling\_timeout=\>60}\>, :result=\>nil, :exception=\>#\<Concurrent::Timeout  
> Error: Concurrent::TimeoutError\>, :executed\_at=\>2017-08-10 22:02:21 -0500}

---

<div class="post-metadata">

**Author:** ![swatititame](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@swatititame](https://discuss.elastic.co/u/swatititame)\
**Post date:** [August 11, 2017, 8:59am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/34 "2017-08-11T08:59:42Z")

</div>

Please let me know if you have any idea regarding this error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2017, 9:00am UTC](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281/35 "2017-09-08T09:00:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/error-logstash-instrument-periodicpoller-jvm-periodi-cpoller-exception/92281.md?page=1)
