# Expected one of #, { in logstash configuration parsing

**URL:** <https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479>\
**Category:** Logstash\
**Created:** [May 18, 2018, 11:36am UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479 "2018-05-18T11:36:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ishantanu](https://avatars.discourse-cdn.com/v4/letter/i/da6949/32.png) [@ishantanu](https://discuss.elastic.co/u/ishantanu)\
**Post date:** [May 18, 2018, 11:36am UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479/1 "2018-05-18T11:36:43Z")

</div>

Hi,  
I am receiving the below error of checking logstash parsing:

```auto
Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of #, { at line 28, column 22 (byte 951) after filter {\n if \"onm-server\" in [tags] {\n grok {\n keep_empty_captures => true\n patterns_dir => [\"/etc/logstash/conf.d/patterns\"]\n match => { \"message\" => \"%{DATE:date}%{SPACE}%{MONTH:month}%{SPACE}%{YEAR:year}%{SPACE}%{TIME:time}%{SPACE}%{SPACE}%{LOGLEVEL:log_level}%{SPACE}%{START_END:msg_onm}\" }\n tag_on_failure => [\"grok1\"]\n remove_tag => [\"_grokparsefailure\"]\n }\n\n grok {\n patterns_dir => [\"/etc/logstash/conf.d/patterns\"]\n match => { \"message\" => \"%{DATE:date}%{SPACE}%{MONTH:month}%{SPACE}%{YEAR:year}%{SPACE}%{TIME:time}%{SPACE}%{SPACE}%{LOGLEVEL:log_level}%{SPACE}%{START_END:msg_onm}\\s+%{LOGLEVEL:log_err}%{SPACE}%{NUMBER:error_no}\\s+\" }\n tag_on_failure => [\"grok2\"]\n remove_tag => [\"_grokparsefailure\"]\n }\n\n if \"grok2\" in [tags] {\n tag_on_failure ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:50:in `compile_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:51:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:166:in `block in converge_state_and_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:164:in `converge_state_and_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:90:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:348:in `block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

```

Here's my config:

```auto
input {
  beats {
    port => 5044
  }
}

# The filter part of this file is commented out to indicate that it is
# optional.

filter {
  if "onm-server" in [tags] {
    grok {
      keep_empty_captures => true
      patterns_dir => ["/etc/logstash/conf.d/patterns"]
      match => { "message" => "%{DATE:date}%{SPACE}%{MONTH:month}%{SPACE}%{YEAR:year}%{SPACE}%{TIME:time}%{SPACE}%{SPACE}%{LOGLEVEL:log_level}%{SPACE}%{START_END:msg_onm}" }
      tag_on_failure => ["grok1"]
      remove_tag => ["_grokparsefailure"]
    }

    grok {
      patterns_dir => ["/etc/logstash/conf.d/patterns"]
      match => { "message" => "%{DATE:date}%{SPACE}%{MONTH:month}%{SPACE}%{YEAR:year}%{SPACE}%{TIME:time}%{SPACE}%{SPACE}%{LOGLEVEL:log_level}%{SPACE}%{START_END:msg_onm}\s+%{LOGLEVEL:log_err}%{SPACE}%{NUMBER:error_no}\s+" }
      tag_on_failure => ["grok2"]
      remove_tag => ["_grokparsefailure"]
    }

    if "grok2" in [tags] {
      tag_on_failure => []
    } else if "grok1" in [tags] {
      remove_tag => ["grok1"]
    }
    mutate {
      convert => { "error_no" => "integer" }
    }

  }

```

I've been looking at the `if` condition but I was not able to track down the issue.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 18, 2018, 11:40am UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479/2 "2018-05-18T11:40:21Z")

</div>

> [@ishantanu](#):
>
> if "grok2" in [tags] {  
> tag\_on\_failure =\>   
> } else if "grok1" in [tags] {  
> remove\_tag =\> ["grok1"]  
> }

You do not have any filters, e.g. mutate, defined in this block.

---

<div class="post-metadata">

**Author:** ![ishantanu](https://avatars.discourse-cdn.com/v4/letter/i/da6949/32.png) [@ishantanu](https://discuss.elastic.co/u/ishantanu)\
**Post date:** [May 18, 2018, 11:46am UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479/3 "2018-05-18T11:46:22Z")

</div>

Tried by adding `mutate { remove_tag => ["grok2"] }`, but still didn't work.

**Update** :

This worked. Just a question, why is that `tag_on_failure` requires mutate filter and `remove_tag` doesn't? I only added `mutate` filter in `if` condition only.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 21, 2018, 9:26pm UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479/4 "2018-05-21T21:26:30Z")

</div>

> This worked. Just a question, why is that tag\_on\_failure requires mutate filter and remove\_tag doesn't? I only added mutate filter in if condition only.

It's very hard to understand what you're asking. An example might help.

---

<div class="post-metadata">

**Author:** ![ishantanu](https://avatars.discourse-cdn.com/v4/letter/i/da6949/32.png) [@ishantanu](https://discuss.elastic.co/u/ishantanu)\
**Post date:** [May 22, 2018, 4:48am UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479/5 "2018-05-22T04:48:52Z")

</div>

Okay. Here's an example:

```auto
if "grok2" in [tags] {
      tag_on_failure => []
} else if "grok1" in [tags] {
      mutate { remove_tag => ["grok1"] }
}

```

If you can see we're using `mutate` for `remove_tag`. But `tag_on_failure` works without it (at least I think it does, I might be wrong). I just wanted to know if there's a difference as I am trying to explain between these two.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 22, 2018, 10:16am UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479/6 "2018-05-22T10:16:31Z")

</div>

Putting `tag_on_failure => []` alone inside an if block doesn't work. `tag_on_failure` is an option to the grok filter.

---

<div class="post-metadata">

**Author:** ![ishantanu](https://avatars.discourse-cdn.com/v4/letter/i/da6949/32.png) [@ishantanu](https://discuss.elastic.co/u/ishantanu)\
**Post date:** [May 22, 2018, 10:28am UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479/7 "2018-05-22T10:28:09Z")

</div>

Okay. Thanks for the information.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2018, 10:39am UTC](https://discuss.elastic.co/t/expected-one-of-in-logstash-configuration-parsing/132479/8 "2018-06-19T10:39:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
