# Error when running pipelines.yml

**URL:** <https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710>\
**Category:** Logstash\
**Created:** [May 2, 2022, 7:20am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710 "2022-05-02T07:20:48Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![rrrrrrrrrrr](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Post date:** [May 2, 2022, 7:20am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/1 "2022-05-02T07:20:48Z")

</div>

Hello,

I'm a newbie in Elastic community and I'm trying to run my pipelines.yml on `/etc/logstash/` using this command `/usr/share/logstash/bin/logstash -f pipelines.yml` but all I'm getting is the error below...

```auto
[WARN] 2022-05-02 14:58:01.267 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified
[ERROR] 2022-05-02 14:58:06.399 [Converge PipelineAction::Create<main>] agent - Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"input\", \"filter\", \"output\" at line 5, column 1 (byte 221) after ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:187:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:50:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:384:in `block in converge_state'"]}

```

**pipelines.yml**

```auto
# This file is where you define your pipelines. You can define multiple.
# For more information on multiple pipelines, see the documentation:
# https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html

- pipeline.id: apache
  path.config: "/etc/logstash/conf.d/apache.conf"
  pipeline.workers: 1

```

**apache.conf**

```auto
input {
        kafka{
            bootstrap_servers => "ipaddress:port"
            topics => ["apache-topic"]
        }
}
filter {
         grok {
# GROK PATTERNS
        }
}
output {
        elasticsearch {
                hosts => ["localhost:9200"]
                index => "apache"
                user => "elastic"
                password => "password"
                }
        stdout{
                }
 }

```

I want to run the pipelines.yml since I think it will help me run the configuration files in just one instance as I have more than 10 configuration files. Thank you in advanced 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 2, 2022, 4:29pm UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/2 "2022-05-02T16:29:12Z")

</div>

> [@rrrrrrrrrrr](#):
>
> `Ignoring the 'pipelines.yml' file`

What command line are you using to start logstash?

---

<div class="post-metadata">

**Author:** ![rrrrrrrrrrr](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Post date:** [May 4, 2022, 2:00am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/3 "2022-05-04T02:00:34Z")

</div>

Hello @Badger it is

> systemctl start logstash

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2022, 3:20am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/4 "2022-05-04T03:20:04Z")

</div>

In that case we need to know what command line systemd is using to start the logstash service. In either the /lib/systemd/system or /etc/systemd/system directory there will probably be a file called something like logstash.service, and in that file I would expect there to be an ExecStart line that tells systemd how to start the program.

---

<div class="post-metadata">

**Author:** ![rrrrrrrrrrr](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Post date:** [May 4, 2022, 5:50am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/5 "2022-05-04T05:50:23Z")

</div>

I think its running on /etc/systemd/system because when I checked the /lib/systemd/system there's no logstash.service available. As for the content of logstash.service in /etc/systemd/system hhehre it is...

**logstash.service**

```auto
[Unit]
Description=logstash

[Service]
Type=simple
User=logstash
Group=logstash
# Load env vars from /etc/default/ and /etc/sysconfig/ if they exist.
# Prefixing the path with '-' makes it try to load, but if the file doesn't
# exist, it continues onward.
EnvironmentFile=-/etc/default/logstash
EnvironmentFile=-/etc/sysconfig/logstash
ExecStart=/usr/share/logstash/bin/logstash "--path.settings" "/etc/logstash"
Restart=always
WorkingDirectory=/
Nice=19
LimitNOFILE=16384

# When stopping, how long to wait before giving up and sending SIGKILL?
# Keep in mind that SIGKILL on a process can cause data loss.
TimeoutStopSec=infinity

[Install]
WantedBy=multi-user.target

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 4, 2022, 6:21am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/6 "2022-05-04T06:21:37Z")

</div>

> [@rrrrrrrrrrr](#):
>
> using this command `/usr/share/logstash/bin/logstash -f pipelines.yml` but all I'm getting is the error below...
> 
> ```auto
> [WARN] 2022-05-02 14:58:01.267 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified
> [ERROR] 2022-05-02 14:58:06.399 [Converge PipelineAction::Create<main>] agent - Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"input\", \"filter\", \"output\" at line 5, column 1 (byte 221) after ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:187:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:50:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:384:in `block in converge_state'"]}
> 
> ```

I am confused are you starting from the command line or systemd

That command above is manually starting logstash from the command line AND if you wanted to test you config then the command would be

`/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/apache.conf --path.settings /etc/logstash`

Not pointing at the `-f pipelines.yml`

---

<div class="post-metadata">

**Author:** ![rrrrrrrrrrr](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Post date:** [May 4, 2022, 9:05am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/7 "2022-05-04T09:05:10Z")

</div>

Hello @stephenb sorry for the confusion. What i'm trying to do here is that I'm trying to run the pipelines.yml since I have other configuration files and I want to run them in just one instance.

```auto
[ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"input\", \"filter\", \"output\" at line 5, column 1 (byte 221) after ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:187:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:50:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:384:in `block in converge_state'"]}

```

Pasting the error whenever I''m trying to run the pipelines.yml.

In addition, thank you for clarifying this, now I know.

> /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/apache.conf --path.settings /etc/logstash

Thank you! 😇

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 4, 2022, 1:41pm UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/8 "2022-05-04T13:41:53Z")

</div>

So if you just run

`/usr/share/logstash/bin/logstash --path.settings /etc/logstash`

That should use the `pipelines.yml` file assuming it is in the proper location

The -f option is used to point to a specific pipeline config file when you don't use it logstash used the pipelines.yml

---

<div class="post-metadata">

**Author:** ![rrrrrrrrrrr](https://avatars.discourse-cdn.com/v4/letter/r/50afbb/32.png) [@rrrrrrrrrrr](https://discuss.elastic.co/u/rrrrrrrrrrr)\
**Post date:** [May 5, 2022, 2:33am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/9 "2022-05-05T02:33:47Z")

</div>

It worked! Thank you @stephenb👏 👏 👏

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 2, 2022, 2:33am UTC](https://discuss.elastic.co/t/error-when-running-pipelines-yml/303710/10 "2022-06-02T02:33:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
