# Expected one of #

**URL:** <https://discuss.elastic.co/t/expected-one-of/81114>\
**Category:** Logstash\
**Created:** [April 4, 2017, 9:57am UTC](https://discuss.elastic.co/t/expected-one-of/81114 "2017-04-04T09:57:08Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vivek\_Samaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_samaga/32/43285_2.png) [@Vivek\_Samaga](https://discuss.elastic.co/u/Vivek_Samaga)\
**Post date:** [April 4, 2017, 9:57am UTC](https://discuss.elastic.co/t/expected-one-of/81114/1 "2017-04-04T09:57:08Z")

</div>

Am using conditionals for output my config looks as below

output{  
if[type] == "access\_log"  
{  
elasticsearch{  
hosts =\> ["10.190.188.174:9200"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}  
else if [type] == "BPM"  
{  
elasticsearch{  
hosts =\> ["10.190.188.174:9200"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}  
else [type] == "syslog"  
{  
elasticsearch{  
hosts =\> ["10.190.188.174:9200"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2017, 9:57am UTC](https://discuss.elastic.co/t/expected-one-of/81114/2 "2017-04-04T09:57:40Z")

</div>

If you are getting an error, providing the complete thing would be helpful.

---

<div class="post-metadata">

**Author:** ![Vivek\_Samaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_samaga/32/43285_2.png) [@Vivek\_Samaga](https://discuss.elastic.co/u/Vivek_Samaga)\
**Post date:** [April 4, 2017, 9:58am UTC](https://discuss.elastic.co/t/expected-one-of/81114/3 "2017-04-04T09:58:22Z")

</div>

Expected one of #, if, { at line 170, column 6 (byte 5578) after output{

---

<div class="post-metadata">

**Author:** ![Vivek\_Samaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_samaga/32/43285_2.png) [@Vivek\_Samaga](https://discuss.elastic.co/u/Vivek_Samaga)\
**Post date:** [April 4, 2017, 9:58am UTC](https://discuss.elastic.co/t/expected-one-of/81114/4 "2017-04-04T09:58:37Z")

</div>

You mean whole of config file?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2017, 9:58am UTC](https://discuss.elastic.co/t/expected-one-of/81114/5 "2017-04-04T09:58:43Z")

</div>

Ok, so where is the rest of the config?

---

<div class="post-metadata">

**Author:** ![Vivek\_Samaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_samaga/32/43285_2.png) [@Vivek\_Samaga](https://discuss.elastic.co/u/Vivek_Samaga)\
**Post date:** [April 4, 2017, 9:59am UTC](https://discuss.elastic.co/t/expected-one-of/81114/6 "2017-04-04T09:59:19Z")

</div>

input {  
beats {  
port =\> 5044  
}  
}

filter {  
if "access\_logs" in [tags] {  
grok {  
match =\> {  
"message" =\> [  
"%{IPORHOST:x\_forwarded\_for} %{IPORHOST:load\_balancer} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb}%{SPACE}  
/%{WORD:application}}%{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-)  
(?:%{WORD:ServerHost}:%{WORD:ServerPort})",  
"%{IPORHOST:clientip} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb} /%{WORD:application}%{NOTSPACE:request}(?:  
HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-) (?:%{WORD:ServerHost}:%{WORD:ServerPort})",  
"%{IPORHOST:clientip} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb} /%{WORD:application}%{NOTSPACE:request}(?:  
HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-)"  
]  
}  
}  
}  
if "BPM" in [tags] {  
grok {  
match =\> {  
"message" =\> [  
"%{SYSLOG5424SD}%{SPACE}%{BASE16NUM:ThreadID}%{SPACE}%{WORD:ShortName}%{SPACE}%{WORD:EventType}%{SPACE}%{WORD:MessageIdentifier}:%{SPACE}%{GREEDYDATA:event}",  
"%{SYSLOG5424SD}%{SPACE}%{WORD:ThreadID}%{SPACE}%{WORD:Logger}%{SPACE}%{WORD:MessageType}%{SPACE}%{GREEDYDATA:event}"  
]  
}  
}  
}  
if "syslog" in [type][tags] {  
grok {  
match =\> {  
"message" =\> [  
"%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?:  
%{GREEDYDATA:syslog\_message}"  
]  
}  
}  
}  
}

output {  
if[type] == "access\_log"  
{  
elasticsearch {  
hosts =\> ["10.190.188.174:9200"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}  
else if [type] == "BPM"  
{  
elasticsearc {  
hosts =\> ["10.190.188.174:9200"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}  
else [type] == "syslog"  
{  
elasticsearc {  
hosts =\> ["10.190.188.174:9200"]  
index =\> "logstash-%{+YYYY.MM.dd}"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Vivek\_Samaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_samaga/32/43285_2.png) [@Vivek\_Samaga](https://discuss.elastic.co/u/Vivek_Samaga)\
**Post date:** [April 4, 2017, 10:02am UTC](https://discuss.elastic.co/t/expected-one-of/81114/7 "2017-04-04T10:02:01Z")

</div>

i tried with if condition outside the output as well.  
ANything needs to be changed?

---

<div class="post-metadata">

**Author:** ![Vivek\_Samaga](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vivek_samaga/32/43285_2.png) [@Vivek\_Samaga](https://discuss.elastic.co/u/Vivek_Samaga)\
**Post date:** [April 4, 2017, 10:17am UTC](https://discuss.elastic.co/t/expected-one-of/81114/8 "2017-04-04T10:17:49Z")

</div>

@warkolm any inputs??

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2017, 10:17am UTC](https://discuss.elastic.co/t/expected-one-of/81114/9 "2017-05-02T10:17:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
