# Fingerprint plugin crashes

**URL:** <https://discuss.elastic.co/t/fingerprint-plugin-crashes/69468>\
**Category:** Logstash\
**Created:** [December 19, 2016, 3:28pm UTC](https://discuss.elastic.co/t/fingerprint-plugin-crashes/69468 "2016-12-19T15:28:20Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![IuriiSergiichuk](https://avatars.discourse-cdn.com/v4/letter/i/e68b1a/32.png) [@IuriiSergiichuk](https://discuss.elastic.co/u/IuriiSergiichuk)\
**Post date:** [December 19, 2016, 3:28pm UTC](https://discuss.elastic.co/t/fingerprint-plugin-crashes/69468/1 "2016-12-19T15:28:20Z")

</div>

Hello there.  
I'm using ELK 5.1.1 stack and right now was trying to configure fingerprint plugin to generate hash-code for URL links.  
Here's part of configuration:

```auto
input {
      http{
            type => "frontend_event"
      }
}
filter {
    de_dot{

    }
    if [type] == 'frontend_event' {
        date {
            match => ["timestamp", "ISO8601", "UNIX_MS"]
            remove_field => ["timestamp"]
        }
        mutate{
            add_field => {
            "user_agent_unparsed" => "%{[headers][http_user_agent]}"
            }
        }
        useragent {
            source => "user_agent_unparsed"
            target => "user_agent"
            remove_field => ["user_agent_unparsed"]
        }
        if [eventType] == 'SEARCH' {
            fingerprint {
                source => ["url"]
                target => "search_url_hash"
                method => "SHA1"
            }
        }
        if [eventType] == 'OPEN_PAGE' {
            fingerprint {
                source => ["searchUrl"]
                target => "search_url_hash"
                method => "SHA1"
            }
        }
    }
}
output{
    elasticsearch{}
}

```

And while logstash is setting up, I receive following error:

```auto
15:25:55.325 [[main]-pipeline-manager] ERROR logstash.agent - Pipeline aborted due to error {:exception=>#<LogStash::ConfigurationError: translation missing: en.logstash.agent.configuration.invalid_plugin_register>, :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-fingerprint-3.0.2/lib/logstash/filters/fingerprint.rb:60:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:230:in `start_workers'", "org/jruby/RubyArray.java:1613:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:230:in `start_workers'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:183:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:292:in `start_pipeline'"]}

```

From my point of view, it's kind of a bug, but maybe someone could find any config-related problems, I do appreciate any help.

P.S. Also `logstash -f /etc/logstash/conf.d/ -t` returns:

```auto
/usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/ -t
Could not find log4j2 configuration at path /etc/logstash/log4j2.properties. Using default config which logs to console
Configuration OK
15:25:10.371 [LogStash::Runner] INFO logstash.runner - Using config.test_and_exit mode. Config Validation Result: OK. Exiting Logstash

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 20, 2016, 6:58am UTC](https://discuss.elastic.co/t/fingerprint-plugin-crashes/69468/2 "2016-12-20T06:58:55Z")

</div>

The poor error message is a bug, but the root cause in an incomplete configuration. This is the error message that should've been presented to you (according to the stack trace):

> Key value is empty. please fill in a subnet prefix length

What's confusing here is that this message only comes when using IPV4\_METHOD as the method, which you're not according to the configuration you posted. Anyway, the root cause is that you're not setting the `key` configuration option.

---

<div class="post-metadata">

**Author:** ![IuriiSergiichuk](https://avatars.discourse-cdn.com/v4/letter/i/e68b1a/32.png) [@IuriiSergiichuk](https://discuss.elastic.co/u/IuriiSergiichuk)\
**Post date:** [December 20, 2016, 7:53am UTC](https://discuss.elastic.co/t/fingerprint-plugin-crashes/69468/3 "2016-12-20T07:53:58Z")

</div>

I do confirm, that adding `key` fixes error, but, probably documentation for this plugin should be adjusted in a following way:

1. As a raw Hash functions do not require any keys, probably smth like HMAC-Hash functions are used, that's why Key is required even for SHA1 - you need to point, that not SHA1, SHA-256, etc. are used, but HMAC-SHA1, HMAC-SHA-256 etc.

2. Key should be **required** , while you cannot use this plugin without key.

Also, I've looked through plugin [github repo](https://github.com/logstash-plugins/logstash-filter-fingerprint) and found that there is already an issue about HMAC and simple hash function: [Provide hash functions in addition to HMAC functions #18](https://github.com/logstash-plugins/logstash-filter-fingerprint/issues/18)

I do think, that at least documentation should be updated, if implementation update cannot be done easily.

Anyway, thank you for help, @magnusbaeck.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 20, 2016, 8:13am UTC](https://discuss.elastic.co/t/fingerprint-plugin-crashes/69468/4 "2016-12-20T08:13:37Z")

</div>

> 1. Key should be required, while you cannot use this plugin without key.

That's not quite true. The MURMUR3, UUID, and PUNCTUATION methods don't make use of the key.

---

<div class="post-metadata">

**Author:** ![IuriiSergiichuk](https://avatars.discourse-cdn.com/v4/letter/i/e68b1a/32.png) [@IuriiSergiichuk](https://discuss.elastic.co/u/IuriiSergiichuk)\
**Post date:** [December 20, 2016, 8:16am UTC](https://discuss.elastic.co/t/fingerprint-plugin-crashes/69468/5 "2016-12-20T08:16:48Z")

</div>

OK, maybe you're right as for those 3 algorithms, but anyway documentation should be somehow adjusted, cause right now it's not clear that you should set some `key` for Hash-function (really, hash-functions do **NOT** require any key, but HMAC **do** require).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2017, 8:17am UTC](https://discuss.elastic.co/t/fingerprint-plugin-crashes/69468/6 "2017-01-17T08:17:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
