# Error string not present and S3 input plugin restarts

**URL:** <https://discuss.elastic.co/t/error-string-not-present-and-s3-input-plugin-restarts/89659>\
**Category:** Logstash\
**Created:** [June 16, 2017, 7:24am UTC](https://discuss.elastic.co/t/error-string-not-present-and-s3-input-plugin-restarts/89659 "2017-06-16T07:24:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mukesh2802](https://avatars.discourse-cdn.com/v4/letter/m/3ab097/32.png) [@mukesh2802](https://discuss.elastic.co/u/mukesh2802)\
**Post date:** [June 16, 2017, 7:24am UTC](https://discuss.elastic.co/t/error-string-not-present-and-s3-input-plugin-restarts/89659/1 "2017-06-16T07:24:36Z")

</div>

Infrastructure details ,  
Running logstash 5.4.1 in a docker container.  
Following is my logstash.conf

> input {  
> http {  
> type =\> 'webhook'  
> }

> s3 {  
> bucket =\> "abcd"  
> region =\> "xyz"  
> prefix =\> "1234"  
> exclude\_pattern =\> "(?:2017030[1-9]|201703[10-31]|2017040[1-9]|201704[10-30])"  
> type =\> "known"  
> backup\_to\_bucket =\> "process"  
> delete =\> "true"  
> }

> }  
> filter {  
> if [type] =~ "known" {  
> mutate {  
> gsub =\> ["message", "[\]", "/"]  
> }  
> grok {  
> patterns\_dir =\> ["/opt/logstash/patterns", "/opt/logstash/extra\_patterns"]  
> match =\> { "message" =\> "%{CUSTOMSTAMP:timestamp}\t(?:%{IP:client}|-)\t(?:%{WORD:method}|-)\t(?:%{URIPATHPARAM:request}|-)\t%{NUMBER:status\_code:int}\t%{NUMBER:bytes:int}\t%{NUMBER:duration:int}\t(?:%{QS:referrer}|-)\t%{BLANKQUOTE}%{QS:agent}%{BLANKQUOTE}\t%{QS:cookie}" }  
> }  
> mutate {  
> rename =\> { "referrer" =\> "cs(Referrer)" }  
> rename =\> { "agent" =\> "cs(User-Agent)" }  
> }

> ```
> useragent {
> source => "cs(User-Agent)"
> target => "useragent"
> }
> 
> ```

> ```
> date {
> match => ["timestamp", "YYYY-MM-dd HH:mm:ss"]
> remove_field => "timestamp"
> }
> 
> ```

> ```
> geoip {
> source => "client"
> }
> 
> ```
> 
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> ["https://{{ ES\_NAME }}:443"]  
> index =\> "logstash-%{type}-v1-%{+YYYY.MM.dd}"  
> }  
> }

Error message as

> [ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.

> Plugin : LogStash::Inputs::S3

> Error:

Though logstash continues processing the logs, but it is hampering the efficiency and has become really slow, due to plugin restart.  
I have no clue where to start troubleshooting since the Error message is blank.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2017, 7:25am UTC](https://discuss.elastic.co/t/error-string-not-present-and-s3-input-plugin-restarts/89659/2 "2017-07-14T07:25:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
