# How to identify the errors reported by logstash?

**URL:** <https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283>\
**Category:** Logstash\
**Created:** [November 3, 2021, 6:06am UTC](https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283 "2021-11-03T06:06:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [November 3, 2021, 6:06am UTC](https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283/1 "2021-11-03T06:06:20Z")

</div>

I can't understand where is the error?  
Who can share how to quickly identify the specific location of the error?

```auto
input {
  elasticsearch {
	hosts => ["192.168.10.141:9200"]
	index => "apm-*-error-*"
	query => '{ "query": 
	      { 
	          "range": { 
			        "@timestamp": { 
					       "gte": "2020-11-03T05:38:22.537Z",
						   "lte": "2021-11-03T05:38:22.537Z",
						   "format": "strict_date_optional_time"
					}
				}
		  }
	  }'
	scroll => "1m"
	size => "1000"
  }
}

```

> [ERROR] 2021-11-03 06:02:06.156 [Converge PipelineAction::Create] agent - Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", [A-Za-z0-9\_-], '"', "'", [A-Za-z\_], "-", [0-9], "[", "{" at line 26, column 12 (byte 444) after output {\n file {\n path =\> ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:187:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:391:in `block in converge\_state'"]}

I put the query statement in dev tools to execute, it is no problem.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/6/f6a4c01d202c695d35dee969aa1fc495634ac7fc.png)

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [November 3, 2021, 6:34am UTC](https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283/2 "2021-11-03T06:34:03Z")

</div>

> /usr/share/logstash/bin/logstash -e 'input { elasticsearch { hosts =\> {{ 192.168.10.141:9200 }} index =\> "apm-_-error-_" query =\> '{"query": { "range": { "@timestamp": { "gte": "2020-11-03T05:38:22.537Z","lte": "2021-11-03T05:38:22.537Z", "format": "strict\_date\_optional\_time" } } } }' scroll =\> "5m" size =\> "1000" user =\> "XXXX" password =\> "XXXX" } } output { file { path =\> "./output.csv" fields =\> ["@timestamp","trace.id", "service.name","http.request.body.original" } }'

I run it through the command line and it also shows an unknown error.

> ERROR: Unknown command '{'

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 3, 2021, 4:04pm UTC](https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283/3 "2021-11-03T16:04:07Z")

</div>

> [@wajika](#):
>
> LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", [A-Za-z0-9\_-], '"', "'", [A-Za-z\_], "-", [0-9], "[", "{" at line 26, column 12 (byte 444) after output {\n file {\n path =\> "

What does your output section look like? Whatever your path setting is, logstash does not like it. Do you have curly quotes around the path? If so, change them to regular double quotes.

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [November 4, 2021, 2:04am UTC](https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283/4 "2021-11-04T02:04:50Z")

</div>

According to you, is the focus of attention after the "after output" statement?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2021, 2:48am UTC](https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283/5 "2021-11-04T02:48:01Z")

</div>

The error message

> Expected one of ... at line 26, column 12 (byte 444) after output {\n file {\n path =\> "

tells you that when the configuration compiler reached the character after `output {\n file {\n path => ` it detected a problem. Sometimes this is due to a problem earlier in the configuration (a missing close quote, for example) and sometimes it is due to whatever comes next.

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [November 4, 2021, 3:05am UTC](https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283/6 "2021-11-04T03:05:33Z")

</div>

You are right, I want to know a quick way to find the wrong place.  
I noticed Expected one of ..... at line ,column ...., but I didn't immediately think that the error was there.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 2, 2021, 3:05am UTC](https://discuss.elastic.co/t/how-to-identify-the-errors-reported-by-logstash/288283/7 "2021-12-02T03:05:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
