# :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of \[ \\\\t\\\\r\\\\n\], \\"#\\", \[A-Za-z0-9\_-\], '\\"', \\"'\\", \[A-Za-z\_\], \\"-\\", \[0-9\], \\"\[\\", \\"{\\", \\"\]\\"

**URL:** <https://discuss.elastic.co/t/exception-logstash-configurationerror-message-expected-one-of-t-r-n-a-za-z0-9-a-za-z-0-9/261903>\
**Category:** Logstash\
**Created:** [January 22, 2021, 10:44am UTC](https://discuss.elastic.co/t/exception-logstash-configurationerror-message-expected-one-of-t-r-n-a-za-z0-9-a-za-z-0-9/261903 "2021-01-22T10:44:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ashishkpal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashishkpal/32/82753_2.png) [@ashishkpal](https://discuss.elastic.co/u/ashishkpal)\
**Post date:** [January 22, 2021, 10:44am UTC](https://discuss.elastic.co/t/exception-logstash-configurationerror-message-expected-one-of-t-r-n-a-za-z0-9-a-za-z-0-9/261903/1 "2021-01-22T10:44:23Z")

</div>

hi,  
i want to push the ELB logs from s3 to ELK for the same have i have written the logstash.conf file like this

input {  
s3 {  
access\_key\_id =\> "..."  
secret\_access\_key =\> "..."  
bucket =\> "..."  
region =\> "eu-central-1"  
prefix =\> "dxlb/AWSLogs/.../elasticloadbalancing/eu-central-1/2019/09/"  
type =\> "elb"  
}  
}

filter {  
if [type] == "elb" {  
grok {  
match =\> [ "message", "%{WORD:connection} %{TIMESTAMP\_ISO8601:timestamp} %{NOTSPACE:elb} %{IP:clientip}:%{INT:clientport:float} (?:(%{IP:backendip}:?:%{INT:backendport:int})|-) %{NUMBER:request\_processing\_time:float} %{NUMBER:backend\_processing\_time:float} %{N  
UMBER:response\_processing\_time:float} (?:-|%{INT:elb\_status\_code:int}) (?:-|%{INT:backend\_status\_code:int}) %{INT:received\_bytes:int} %{INT:sent\_bytes:int} "%{ELB\_REQUEST\_LINE}" "(?:-|%{DATA:user\_agent})" (?:-|%{NOTSPACE:ssl\_cipher}) (?:-|%{NOTSPACE:ssl\_protocol})  
" ]  
#match =\> ["message", "%{ELB\_ACCESS\_LOG} "%{DATA:userAgent}"( %{NOTSPACE:ssl\_cipher} %{NOTSPACE:ssl\_protocol})?"]  
}  
date {  
match =\> ["timestamp", "ISO8601"]  
}  
geoip {  
source =\> "clientip"  
}  
}  
}

output {  
if [type] == "elb" {  
elasticsearch {  
hosts =\> [“localhost:9200”]  
index =\> "logstash-%{+YYYY.MM}"  
user =\> "..."  
password =\> "..."  
}  
}  
}

but after applying this i getting this error. please help me out to sort this one

[2021-01-22T10:05:39,833][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit  
[2021-01-22T10:06:02,720][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.10.2", "jruby.version"=\>"jruby 9.2.13.0 (2.5.7) 2020-08-03 9a89c94bcc OpenJDK 64-Bit Server VM 11.0.8+10 on 11.0.8+10 +indy +jit [linux-x86\_64]"}  
[2021-01-22T10:06:05,859][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", [A-Za-z0-9\_-], '"', "'", [A-Za-z\_], "-", [0-9], "[", "{", "]" at line 32, column 27 (byte 1194) after output {\nif [type] == "elb" {\n elasticsearch {\n hosts =\> [", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:184:in ` initialize'", "org/logstash/execution/JavaBasePipelineExt.java:69:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in ` initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:365:in ` block in converge\_state'"]}  
[2021-01-22T10:06:06,196][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2021-01-22T10:06:11,103][INFO][logstash.runner] Logstash shut down.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2021, 10:44am UTC](https://discuss.elastic.co/t/exception-logstash-configurationerror-message-expected-one-of-t-r-n-a-za-z0-9-a-za-z-0-9/261903/2 "2021-02-19T10:44:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
