# Got an Error - exception=\>#\<ArgumentError: invalid byte sequence in UTF-8\>,

**URL:** <https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780>\
**Category:** Logstash\
**Created:** [February 1, 2019, 8:00pm UTC](https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780 "2019-02-01T20:00:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![shubhamblackstratus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhamblackstratus/32/60703_2.png) [@shubhamblackstratus](https://discuss.elastic.co/u/shubhamblackstratus)\
**Post date:** [February 1, 2019, 8:00pm UTC](https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780/1 "2019-02-01T20:00:40Z")

</div>

Kindly find the below error log over here.

Feb 02 06:24:49 logstashbox logstash[1082]: [2019-02-02T06:24:49,357][ERROR][logstash.pipeline] Error ne\_id=\>"main", :plugin=\>"#LogStash::FilterDelegator:0x5af6ed72", :error=\>"invalid byte sequence in UTF-8", :0 run\>"}  
Feb 02 06:24:49 logstashbox logstash[1082]: [2019-02-02T06:24:49,428][ERROR][logstash.pipeline] Pipeliipeline\_id=\>"main", :exception=\>#\<ArgumentError: invalid byte sequence in UTF-8\>, :backtrace=\>["org/jruby/Ruby"org/jruby/RubyString.java:1607:in `=~'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/jls-grok-0.11.5/ck in add_patterns_from_file'", "org/jruby/RubyIO.java:3290:in`each'", "/usr/share/logstash/vendor/bundle/jru.5/lib/grok-pure.rb:70:in `add_patterns_from_file'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstogstash/filters/grok.rb:403:in`block in add\_patterns\_from\_files'", "org/jruby/RubyArray.java:1734:in `each'",r/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:399:in`add\_patterns\_from\_fi/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:279:in `block in regis.java:1734:in`each'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.4/lib/logs `block in register'", "org/jruby/RubyHash.java:1343:in`each'", "/usr/share/logstash/vendor/bundle/jruby/2.3.-4.0.4/lib/logstash/filters/grok.rb:270:in `register'", "org/logstash/config/ir/compiler/AbstractFilterDelegat", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:242:in`register\_plugin'", "/usr/share/logstash/pipeline.rb:253:in `block in register_plugins'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/pipeline.rb:253:in `register_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:595:in, "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:263:in`start\_workers'", "/usr/share/logstash/lopeline.rb:200:in `run'", "/usr/share/ Feb 02 06:24:49 logstashbox logstash[1082]: logstash/logstash-core/lib/logstash/pipeline.rb:160:in`block in s:0x1b47e310 run\>"}  
Feb 02 06:24:49 logstashbox logstash[1082]: [2019-02-02T06:24:49,498][ERROR][logstash.agent] Failedain, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineActionlt: false", :backtrace=\>nil}  
Feb 02 06:24:50 logstashbox logstash[1082]: [2019-02-02T06:24:50,698][INFO][logstash.agent] Succes endpoint {:port=\>9600}

* * *

It seemed encoding related query but I did not know what to do in development file.

Please help..!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 1, 2019, 8:03pm UTC](https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780/2 "2019-02-01T20:03:23Z")

</div>

What does the configuration look like?

---

<div class="post-metadata">

**Author:** ![shubhamblackstratus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhamblackstratus/32/60703_2.png) [@shubhamblackstratus](https://discuss.elastic.co/u/shubhamblackstratus)\
**Post date:** [February 1, 2019, 8:11pm UTC](https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780/3 "2019-02-01T20:11:18Z")

</div>

Configuration of Logstash :

input {  
file {  
type =\> "CiscoASALog"  
path =\> "/var/log/remotehosts/asa.log"  
}  
}  
filter {  
if [type] == "CiscoASALog" {  
grok {  
match =\> ["message", "%{CISCOTIMESTAMP:timestamp} %{HOSTNAME:hostname}? ?%%{CISCOTAG:ciscotag}: %{GREEDYDATA:cisco\_message}"]  
}  
syslog\_pri { }  
date {  
match =\> ["timestamp",  
"MMM dd HH:mm:ss",  
"MMM d HH:mm:ss",  
"MMM dd yyyy HH:mm:ss",  
"MMM d yyyy HH:mm:ss"  
]  
timezone =\> "Australia/Sydney"  
}  
if "\_grokparsefailure" not in [tags] {  
mutate {  
rename =\> ["cisco\_message", "message"]  
remove\_field =\> ["timestamp"]  
}  
}  
grok {  
match =\> [  
"message", "%{CISCOFW106001}",  
"message", "%{CISCOFW106006\_106007\_106010}",  
"message", "%{CISCOFW106014}",  
"message", "%{CISCOFW106015}",  
"message", "%{CISCOFW106021}",  
"message", "%{CISCOFW106023}",  
"message", "%{CISCOFW106100}",  
"message", "%{CISCOFW110002}",  
"message", "%{CISCOFW302010}",  
"message", "%{CISCOFW302013\_302014\_302015\_302016}",  
"message", "%{CISCOFW302020\_302021}",  
"message", "%{CISCOFW305011}",  
"message", "%{CISCOFW313001\_313004\_313008}",  
"message", "%{CISCOFW313005}",  
"message", "%{CISCOFW402117}",  
"message", "%{CISCOFW402119}",  
"message", "%{CISCOFW419001}",  
"message", "%{CISCOFW419002}",  
"message", "%{CISCOFW500004}",  
"message", "%{CISCOFW602303\_602304}",  
"message", "%{CISCOFW710001\_710002\_710003\_710005\_710006}",  
"message", "%{CISCOFW713172}",  
"message", "%{CISCOFW733100}"  
]  
}  
}  
}

output {  
file {  
path =\> "/var/log/logstash/asafeb.log"  
}  
}

- Sample Data:  
Feb 2 07:05:05 shubhamshah.test %ASA-6-305012: Teardown dynamic TCP translation from any:192.168.7.148/57394 to outside:10.0.0.2/57394 duration 1:00:01  
Feb 2 07:03:34 shubhamshah.test %ASA-6-305012: Teardown dynamic TCP translation from any:192.168.7.148/57437 to outside:10.0.0.2/57437 duration 0:00:00  
Feb 2 07:03:36 shubhamshah.test %ASA-6-302014: Teardown TCP connection 2665925 for outside:8.8.8.8/443 to inside:192.168.1.148/57438 duration 0:00:01 bytes 51790 TCP FINs

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 1, 2019, 8:32pm UTC](https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780/4 "2019-02-01T20:32:08Z")

</div>

If I am reading the stack correctly it is registering the grok plugin and reading patterns from files. If you enable --log.level debug it should log each pattern as it adds it. It will also log where it is loading patterns from

```
[DEBUG][logstash.filters.grok] Grok patterns path {:paths=>["/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-patterns-core-4.1.2/patterns", "/usr/share/logstash/patterns/*"]}

```

The pattern that causes the error will be immediately after the last pattern logged, so you will have to find which file _that_ pattern is in and find which would be loaded next. Also, try

file /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-patterns-core-4.1.2/patterns/\* /usr/share/logstash/patterns/\*

For the directories that are shown in your logfile (which may be different, depending on versions).

I am able to reproduce the issue by dropping a binary file into /usr/share/logstash/patterns/

---

<div class="post-metadata">

**Author:** ![shubhamblackstratus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhamblackstratus/32/60703_2.png) [@shubhamblackstratus](https://discuss.elastic.co/u/shubhamblackstratus)\
**Post date:** [February 1, 2019, 8:46pm UTC](https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780/5 "2019-02-01T20:46:12Z")

</div>

Thank you Badger.

Can I drop my all debug logs because I am still not able to find particular pattern which makes trouble ?

Shubham

---

<div class="post-metadata">

**Author:** ![shubhamblackstratus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shubhamblackstratus/32/60703_2.png) [@shubhamblackstratus](https://discuss.elastic.co/u/shubhamblackstratus)\
**Post date:** [February 1, 2019, 9:01pm UTC](https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780/6 "2019-02-01T21:01:01Z")

</div>

Thank you so much man... Issue got resolved. found anonymous rpm download under /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-patterns-core-4.1.2/patterns/\* . So I just deleted it and issue got resolved.

Have a great time ahead..!

~Shubham

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2019, 9:01pm UTC](https://discuss.elastic.co/t/got-an-error-exception-argumenterror-invalid-byte-sequence-in-utf-8/166780/7 "2019-03-01T21:01:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
