# Failing with multi-file config and auto reload flag

**URL:** <https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168>\
**Category:** Logstash\
**Created:** [April 3, 2016, 12:50pm UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168 "2016-04-03T12:50:27Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![StavSap](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@StavSap](https://discuss.elastic.co/u/StavSap)\
**Post date:** [April 3, 2016, 12:50pm UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/1 "2016-04-03T12:50:27Z")

</div>

Hi,

i have an issue running in multi-files configuration (using folder with \*.conf files) and auto-reload flag (--auto-reload)  
this causes a crash and shutdown of log stash when i am sending the syslog event for parsing.

i am seeing error message

"NoMethodError: undefined method `multi\_filter' for nil:NilClass"

please advise if any one having this issue.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2016, 7:18am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/2 "2016-04-04T07:18:15Z")

</div>

Providing more details would be helpful!

What version are you on? What about java? What OS? Can you provide the full error?

---

<div class="post-metadata">

**Author:** ![StavSap](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@StavSap](https://discuss.elastic.co/u/StavSap)\
**Post date:** [April 4, 2016, 7:35am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/3 "2016-04-04T07:35:36Z")

</div>

tried also with the -r flag, same issue

details:

error:

Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {"exception"=\>#\<NoMethodError: undefined method `multi_filter' for nil:NilClass>, "backtrace"=>["(eval):1026:in`cond\_func\_29'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):1023:in`cond\_func\_29'", "(eval):508:in `filter_func'", "/auto/apollo_users/ssapir/logstash-2.3.0/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.0-java/lib/logstash/pipeline.rb:271:in`filter\_batch'", "org/jruby/RubyArray.java:1613:in `each'", "org/jruby/RubyEnumerable.java:852:in`inject'", "/auto/apollo\_users/ssapir/logstash-2.3.0/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.0-java/lib/logstash/pipeline.rb:269:in `filter_batch'", "/auto/apollo_users/ssapir/logstash-2.3.0/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.0-java/lib/logstash/pipeline.rb:227:in`worker\_loop'", "/auto/apollo\_users/ssapir/logstash-2.3.0/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.0-java/lib/logstash/pipeline.rb:205:in `start_workers'"], :level=>:error} NoMethodError: undefined method`multi\_filter' for nil:NilClass  
cond\_func\_29 at (eval):1026  
each at org/jruby/RubyArray.java:1613  
cond\_func\_29 at (eval):1023  
filter\_func at (eval):508  
filter\_batch at /auto/apollo\_users/ssapir/logstash-2.3.0/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.0-java/lib/logstash/pipeline.rb:271  
each at org/jruby/RubyArray.java:1613  
inject at org/jruby/RubyEnumerable.java:852  
filter\_batch at /tmp/logstash-2.3.0/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.0-java/lib/logstash/pipeline.rb:269  
worker\_loop at /tmp/logstash-2.3.0/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.0-java/lib/logstash/pipeline.rb:227  
start\_workers at /tmp/logstash-2.3.0/vendor/bundle/jruby/1.9/gems/logstash-core-2.3.0-java/lib/logstash/pipeline.rb:205

java:

java version "1.8.0\_31"  
Java(TM) SE Runtime Environment (build 1.8.0\_31-b13)  
Java HotSpot(TM) 64-Bit Server VM (build 25.31-b07, mixed mode)

OS:

Linux 3.10.0-327.10.1.el7.x86\_64 x86\_64

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2016, 7:39am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/4 "2016-04-04T07:39:11Z")

</div>

Ok so what do your filters look like?

---

<div class="post-metadata">

**Author:** ![StavSap](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@StavSap](https://discuss.elastic.co/u/StavSap)\
**Post date:** [April 4, 2016, 7:47am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/5 "2016-04-04T07:47:54Z")

</div>

about 5 files, one defines input and output, 4 other filters like grok, kv, prune, mutate.

it works perfectly without the auto reload flag, i worked with them on previous version (2.2.2) without any issue.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2016, 7:48am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/6 "2016-04-04T07:48:33Z")

</div>

If you can't provide them then we cannot replicate, which makes it very hard to help solve.

---

<div class="post-metadata">

**Author:** ![StavSap](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@StavSap](https://discuss.elastic.co/u/StavSap)\
**Post date:** [April 4, 2016, 7:53am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/7 "2016-04-04T07:53:35Z")

</div>

input  
{  
tcp {  
port =\> 1465  
type =\> syslog  
add\_field =\> {"plugin" =\> 1}  
}  
tcp {  
port =\> 1466  
type =\> syslog  
add\_field =\> {"plugin" =\> 2}  
}  
tcp {  
port =\> 1467  
type =\> syslog  
add\_field =\> {"plugin" =\> 3}  
}  
tcp {#for testing  
port =\> 1469  
}  
}

filter  
{  
mutate  
{  
remove\_field =\> "port"  
convert =\> ["plugin", "integer"]  
rename =\> {"message" =\> "received\_message"}  
}  
}

output  
{  
#stdout {}

```
if [parse_status] == "failed" 
  {
      elasticsearch 
    {         
        index => "failed" 
        document_type => "log"
        hosts => ["10.8.120.28"] 
    }
  }
  else
  {
    elasticsearch 
    {         
        index => "events" 
        document_type => "log"
        hosts => ["10.8.120.28"] 
        template => "/tmp/logstash-2.2.2/bin/elasticsearch-template.json"
           template_name => "events"
        manage_template => "true"
        template_overwrite => "true"
    }
  }

```

}

---

<div class="post-metadata">

**Author:** ![StavSap](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@StavSap](https://discuss.elastic.co/u/StavSap)\
**Post date:** [April 4, 2016, 7:54am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/8 "2016-04-04T07:54:13Z")

</div>

input{

}

filter{  
if [plugin] == 1  
{  
syslog\_pri  
{  
syslog\_pri\_field\_name =\> "syslog5424\_pri"  
}

```
grok
{
  match => {"received_message" => "%{SYSLOG5424PRI}%{SYSLOGTIMESTAMP}%{GREEDYDATA}%{WORD:action}%{SPACE}%{IP} %{NOTSPACE} %{GREEDYDATA:kv_data}"}
}

kv 
{ 
  source => "kv_data"    
  #trimkey => "\s"  
  #field_split => "?;?"
  #value_split => ":"
}

mutate
{
  remove_field => "kv_data"
  rename =>{"src" => "source_ip"}
  rename =>{"dst" => "target_ip"}
}

```

}  
}  
output{

}

---

<div class="post-metadata">

**Author:** ![StavSap](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@StavSap](https://discuss.elastic.co/u/StavSap)\
**Post date:** [April 4, 2016, 7:54am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/9 "2016-04-04T07:54:30Z")

</div>

input{

}

filter{  
if [plugin] == 2  
{  
syslog\_pri  
{  
syslog\_pri\_field\_name =\> "syslog5424\_pri"  
}  
grok  
{  
match =\> {"received\_message" =\> "%{SYSLOG5424PRI}%{SYSLOGTIMESTAMP} %{NOTSPACE}%{SPACE}%{GREEDYDATA:kv\_data}"}  
}

```
kv 
{ 
  source => "kv_data"    
  value_split => ":"    
}

mutate
{
  remove_field => "kv_data"
}

grok
{
  match => {"alert_message" => "%{GREEDYDATA}source address %{IP:source_ip}%{GREEDYDATA}destination address %{IP:target_ip}%{GREEDYDATA}"}
  tag_on_failure => [] #dont tag if failed, not all messages have this.
}

```

}  
}  
output{

}

---

<div class="post-metadata">

**Author:** ![StavSap](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@StavSap](https://discuss.elastic.co/u/StavSap)\
**Post date:** [April 4, 2016, 7:54am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/10 "2016-04-04T07:54:52Z")

</div>

input{

}

filter{  
if [plugin] == 3  
{  
syslog\_pri  
{  
syslog\_pri\_field\_name =\> "syslog5424\_pri"  
}

```
grok
{
  match => {"received_message" => "%{SYSLOG5424PRI}%{SYSLOGTIMESTAMP} %{WORD:product}: %{DATE:date} %{TIME:time} %{WORD:severity} %{WORD:radware_id} %{NOTSPACE:catagory} \"%{DATA:attack_name}\" %{NOTSPACE:protocol} %{IP:source_ip} %{NUMBER:source_port} %{IP:target_ip} %{NUMBER:target_port} %{NUMBER:physical_port} %{WORD:context} \"%{DATA:policy_name}\" %{WORD:attack_status} %{WORD:packet_count} %{NOTSPACE:bandwidth} %{NOTSPACE:vlan_tag} %{NOTSPACE:mpls_rd} %{NOTSPACE:mpls_tag} %{NOTSPACE:risk} %{NOTSPACE:action} %{NOTSPACE:unique_id}"}
}   

```

}  
}  
output{

}

---

<div class="post-metadata">

**Author:** ![StavSap](https://avatars.discourse-cdn.com/v4/letter/s/bb73d2/32.png) [@StavSap](https://discuss.elastic.co/u/StavSap)\
**Post date:** [April 4, 2016, 7:55am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/11 "2016-04-04T07:55:17Z")

</div>

input{

}

filter{

if "\_grokparsefailure" in [tags]  
{  
prune {  
add\_field =\> {"parse\_status" =\> "failed"}  
whitelist\_names =\> ["plugin", "received\_message", "host", "@timestamp", "tags"]  
}  
}  
else  
{  
mutate  
{  
add\_field =\> {"parse\_status" =\> "success"}  
remove\_field =\> "received\_message"  
}

```
geoip 
{
  source => "source_ip"
  target => "source_geoip"
  database => "/tmp/logstash-2.2.2/bin/GeoLocation_City.dat"
}

geoip 
{
  source => "target_ip"
  target => "target_geoip"
  database => "/tmp/logstash-2.2.2/bin/GeoLocation_City.dat"
}

```

}  
}

output{

}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2016, 8:28am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/12 "2016-04-04T08:28:13Z")

</div>

Just a quick tip, you don't need so many empty input and output stanzas.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:04am UTC](https://discuss.elastic.co/t/failing-with-multi-file-config-and-auto-reload-flag/46168/13 "2017-07-06T05:04:08Z")

</div>


