# Error start logstash after update from 5.4.3 to 5.5

**URL:** <https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418>\
**Category:** Logstash\
**Created:** [July 10, 2017, 7:24am UTC](https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418 "2017-07-10T07:24:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [July 10, 2017, 7:24am UTC](https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418/1 "2017-07-10T07:24:47Z")

</div>

Hi,

I updated my elastic stask from 5.4.3 to 5.5.0. When i start logstash, i got some error

Data flow : Log -\> logstash collector(v5.5) -\> RabbitMQ (v3.6.1) -\> Logstash proccessor (filter)(v5.5) -\> ES(v5.5)

This is error log from logstash processor.

[Logstash proccessor error](https://pastebin.com/kTGShr9P)

My logstash proccess config

> input {  
> rabbitmq {  
> host =\> "10.1.6.244"  
> queue =\> "logstash-queue"  
> key =\> "logstash-key"  
> exchange =\> "logstash"  
> threads =\> 5  
> exclusive =\> false  
> prefetch\_count =\> 256  
> vhost =\> "elastic-stack"  
> port =\> 5677  
> user =\> "logstash"  
> password =\> "password"  
> }

> }

> output {  
> elasticsearch {  
> hosts =\> ["[https://10.1.6.196:9200](https://10.1.6.196:9200)", "[https://10.1.6.197:9200](https://10.1.6.197:9200)", "[https://10.1.6.198:9200](https://10.1.6.198:9200)"]  
> user =\> "myuser"  
> cacert =\> "/etc/logstash/ca.pem"  
> ssl =\> true  
> password =\> "mypassword"  
> manage\_template =\> false  
> flush\_size =\> 5000  
> index =\> "%{beatname}-%{+xxxx.ww}"  
> document\_type =\> "%{beattype}"  
> }  
> }

And here is log logstash collector

[https://pastebin.com/qsJA5YQN](https://pastebin.com/qsJA5YQN)

my logstash collector config

> input {  
> beats {  
> port =\> 5044  
> }  
> }  
> filter {  
> if [type] == "wineventlog" and [event\_id] == 5156 {  
> drop { }  
> }  
> mutate {  
> add\_field =\> {"beatname" =\> "%{[@metadata][beat]}"}  
> add\_field =\> {"beattype" =\> "%{[@metadata][type]}"}  
> }  
> }

> output {  
> rabbitmq {  
> exchange =\> "logstash"  
> exchange\_type =\> "direct"  
> key =\> "logstash-key"  
> host =\> "10.1.6.244"  
> vhost =\> "elastic-stack"  
> durable =\> true  
> persistent =\> true  
> port =\> 5677  
> user =\> "logstash"  
> password =\> "password"  
> }  
> }

Before update to V5.5, it's woking with my config, no problem.  
Thanks!

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [July 10, 2017, 2:57pm UTC](https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418/2 "2017-07-10T14:57:26Z")

</div>

I can't repro that error with the test configs you've posted. I suspect that the bug is related to the actual username/password. Can you repro the errors with the test configs you've posted?

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [July 10, 2017, 3:07pm UTC](https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418/3 "2017-07-10T15:07:23Z")

</div>

Also, I'm noting that you have an ES error in your collector config, even though you aren't using ES there. Do you have xpack enabled and sending stats to Elasticsearch? I'm thinking the bug could be related to your xpack username / password. Do you use unusual formatting of either field?

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [July 10, 2017, 9:08pm UTC](https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418/4 "2017-07-10T21:08:52Z")

</div>

This appears to be a difference in escape handling in explicit usernames.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [July 11, 2017, 12:16am UTC](https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418/5 "2017-07-11T00:16:07Z")

</div>

Made an issue to track this [https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/618](https://github.com/logstash-plugins/logstash-output-elasticsearch/issues/618)

---

<div class="post-metadata">

**Author:** ![tatdat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tatdat/32/113160_2.png) [@tatdat](https://discuss.elastic.co/u/tatdat)\
**Post date:** [July 11, 2017, 12:54am UTC](https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418/6 "2017-07-11T00:54:25Z")

</div>

Yeah,  
I enabled xpack and sending stats to ES.

i changed password (no special character) and it's worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2017, 1:09am UTC](https://discuss.elastic.co/t/error-start-logstash-after-update-from-5-4-3-to-5-5/92418/7 "2017-08-08T01:09:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
