# Error wen put pipeline line on conf file (version 8.7)

**URL:** https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887
**Category:** Logstash
**Tags:** elastic-stack-alerting
**Created:** [May 19, 2023, 7:46pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887 "2023-05-19T19:46:09Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![jefin\_dark](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)
#### Post date: [May 19, 2023, 7:46pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887/1 "2023-05-19T19:46:09Z")

</div>

Hello, i cant start service, because the logstash bring me this error when i put this lines in conf file.

The given configuration is invalid. Reason: Expected one of [\t\r\n], "#", "input", "filter", "output" at line 1, column 1

my conf file is

```auto
pipeline {
  pipeline_id => "mikrotik"
 }
  
input {
  udp {
    port => 5514
    codec => plain
  }
}

filter {
  grok {
    match => {
      "message" => "<%{POSINT:priority}>%{MONTH:month} %{MONTHDAY:day} %{TIME:time} %{DATA:hostname} %{WORD:event_type} %{GREEDYDATA:message_data}"
    }
  }

  mutate {
    convert => { "priority" => "integer" }
  }

  if [event_type] == "user" {
    grok {
      match => {
        "message_data" => "admin logged in from %{IP:source_ip} via %{WORD:login_method}"
      }
    }
  }

  if [event_type] == "filter" {
    grok {
      match => {
        "message_data" => "rule %{WORD:rule_action} by %{DATA:rule_modifier}"
      }
    }
  }
}

output {
  elasticsearch {
    hosts => ["https://192.168.12.109:9200"]
    index => "mikrotik_log-%{+YYYY.MM.dd}"
    user => "elastic"
    password => "xxxxxxxxxxxxxxx"
    ssl => true
    cacert => "/etc/logstash/http_ca.crt"
  }
}

```

Someone can help ?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 19, 2023, 7:54pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887/2 "2023-05-19T19:54:10Z")

</div>

Hi @jefin_dark Welcome to the community.

> **[Structure of a pipeline | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/configuration-file-structure.html)**

Take out this, I'm not sure where you got that from. That is not how you name a pipeline

> [@jefin\_dark](#):
>
> ```auto
> pipeline {
> pipeline_id => "mikrotik"
> }
> 
> ```

---

<div class="post-metadata">

### Author: ![jefin\_dark](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)
#### Post date: [May 19, 2023, 8:02pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887/3 "2023-05-19T20:02:10Z")

</div>

ok, if i take it out it will work.  
But if I add another conf file with another port, it will send duplicate data in the indexes inside the ELK.

thats other conf

```auto
input {
  beats {
    port => 5044
  }
}

filter {
  grok {
    match => {
      "[event_data][Data]" => [
        "Subject:\s*Security ID:\s*%{DATA:security_id}",
        "Subject:\s*Account Name:\s*%{DATA:account_name}",
        "Subject:\s*Account Domain:\s*%{DATA:account_domain}",
        "Subject:\s*Logon ID:\s*%{DATA:logon_id}",
        "Object:\s*Object Server:\s*%{DATA:object_server}",
        "Object:\s*Object Type:\s*%{DATA:object_type}",
        "Object:\s*Object Name:\s*%{DATA:object_name}",
        "Object:\s*Handle ID:\s*%{DATA:handle_id}",
        "Access:\s*Accesses:\s*%{DATA:accesses}",
        "Access:\s*Access Mask:\s*%{DATA:access_mask}",
        "Access:\s*Privileges:\s*%{DATA:privileges}"
      ]
    }
  }
}

output {
  elasticsearch {
    hosts => ["https://192.168.12.109:9200"]
    index => "srvvmfs01_log-%{+YYYY.MM.dd}"
    user => "elastic"
    password => " *****************"
    ssl => true
    cacert => "/etc/logstash/http_ca.crt"
  }
}

```

Could it be that I'm doing something wrong?

Can you help me ?

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 19, 2023, 8:17pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887/4 "2023-05-19T20:17:12Z")

</div>

I think you should read a little in the docs 🙂

This is how to run multiple independent pipelines naming them kind of like what you are trying to do... But do it in the correct place

> **[Multiple Pipelines | Logstash Reference \[8.7\] | Elastic](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html)**

---

<div class="post-metadata">

### Author: ![jefin\_dark](https://avatars.discourse-cdn.com/v4/letter/j/b38774/32.png) [@jefin\_dark](https://discuss.elastic.co/u/jefin_dark)
#### Post date: [May 19, 2023, 8:25pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887/5 "2023-05-19T20:25:41Z")

</div>

I've done this before.  
I'm going to mark it as done and open another topic and explain better what the error I'm facing.

Thank you for your help and attention

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [May 19, 2023, 8:49pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887/6 "2023-05-19T20:49:55Z")

</div>

Yeah you can open another topic or just show us all the configuration and what the actual error is.

If you put more than one configuration file in a directory and don't use pipeline.yml

The two configuration files get concatenated together so all events go to all outputs.

But you absolutely can put tags on the inputs and then use those tags to conditionally direct to the output you want.

That is a very common configuration

You could do that in one big conf file or two separate conf.

_Tell us what You're trying to accomplish and we can certainly help._

If you want to open another topic that's fine too...

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 16, 2023, 8:50pm UTC](https://discuss.elastic.co/t/error-wen-put-pipeline-line-on-conf-file-version-8-7/333887/7 "2023-06-16T20:50:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
