# I can not install any LogStash plug-in in ES 5.0

**URL:** <https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313>\
**Category:** Logstash\
**Created:** [October 28, 2016, 4:40pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313 "2016-10-28T16:40:09Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![michelmooren](https://avatars.discourse-cdn.com/v4/letter/m/ebca7d/32.png) [@michelmooren](https://discuss.elastic.co/u/michelmooren)\
**Post date:** [October 28, 2016, 4:40pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/1 "2016-10-28T16:40:09Z")

</div>

I did a fresh install of ES 5.0.

When trying to install LS plug-ins like logstash-filter-multiline and logstash-filter-mutate I keep getting the following error message:  
An error occurred while installing logstash-core-event-java \<5.0.0\> , and Bundler can not continue.  
Make sure that 'gem instal logstash-core-event-java -v '5.0.0'' succeeds before bundling.

Any hints as to what may be causing this error would be much appreciated.

---

<div class="post-metadata">

**Author:** ![tsmori](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsmori/32/47626_2.png) [@tsmori](https://discuss.elastic.co/u/tsmori)\
**Post date:** [October 31, 2016, 7:56pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/2 "2016-10-31T19:56:50Z")

</div>

I have the same issue. I went through the process of installing jruby (not a requirement as far as I can see) and it still didn't work.

I tried building the gem directly, but I get a lot of different errors that way. For all I know it requires a specific version of ruby and/or jruby.

---

<div class="post-metadata">

**Author:** ![tsmori](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsmori/32/47626_2.png) [@tsmori](https://discuss.elastic.co/u/tsmori)\
**Post date:** [October 31, 2016, 8:29pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/3 "2016-10-31T20:29:18Z")

</div>

Following the doc exactly shows that you're supposed to run this from the install directory which for RHEL is /usr/share/logstash. So there is a bundled jruby binary, but the gem build crashes.

Fetching: ruby-maven-3.3.9.gem (100%)  
Successfully installed ruby-maven-3.3.9  
jar dependencies for logstash-core-event-java-5.0.0-java.gemspec . . .  
[ERROR] [ERROR] Some problems were encountered while processing the POMs:  
[FATAL] Non-parseable POM /usr/share/logstash/vendor/jruby/lib/ruby/shared/jars/gemspec\_pom.rb: only whitespace content allowed before start tag and not # (position: START\_DOCUMENT seen #... @1:1) @ line 1, column 1  
@  
[ERROR] The build could not read 1 project -\> [Help 1]  
[ERROR]  
[ERROR] The project (/usr/share/logstash/vendor/jruby/lib/ruby/shared/jars/gemspec\_pom.rb) has 1 error  
[ERROR] Non-parseable POM /usr/share/logstash/vendor/jruby/lib/ruby/shared/jars/gemspec\_pom.rb: only whitespace content allowed before start tag and not # (position: START\_DOCUMENT seen #... @1:1) @ line 1, column 1 -\> [Help 2]  
[ERROR]  
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.  
[ERROR] Re-run Maven using the -X switch to enable full debug logging.  
[ERROR]  
[ERROR] For more information about the errors and possible solutions, please read the following articles:  
[ERROR] [Help 1] [http://cwiki.apache.org/confluence/display/MAVEN/ProjectBuildingException](http://cwiki.apache.org/confluence/display/MAVEN/ProjectBuildingException)  
[ERROR] [Help 2] [http://cwiki.apache.org/confluence/display/MAVEN/ModelParseException](http://cwiki.apache.org/confluence/display/MAVEN/ModelParseException)  
ERROR: While executing gem ... (Errno::ENOENT)  
No such file or directory - /usr/share/logstash/vendor/jruby/lib/ruby/gems/shared/gems/logstash-core-event-java-5.0.0-java/deps.lst

At first glance, it seems that the gem is missing a file. Not sure though if that's the extent of the problem.

---

<div class="post-metadata">

**Author:** ![jordansissel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordansissel/32/44957_2.png) [@jordansissel](https://discuss.elastic.co/u/jordansissel)\
**Post date:** [October 31, 2016, 9:55pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/4 "2016-10-31T21:55:12Z")

</div>

Can you show your complete command where you are running logstash-plugin?

---

<div class="post-metadata">

**Author:** ![tsmori](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsmori/32/47626_2.png) [@tsmori](https://discuss.elastic.co/u/tsmori)\
**Post date:** [November 1, 2016, 2:06pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/5 "2016-11-01T14:06:00Z")

</div>

> [@tsmori](#):
>
> logstash-core-event-java-5.0.0-java

Sure, I was running this from within the /usr/share/logstash directory:

./bin/logstash-plugin install logstash-input-beats

However this appears to be a known issue, possibly with jruby or some component of it. It seems that some part of the build isn't honoring proxy settings, although even downloading and trying to build the plugin locally didn't work either.

> <https://github.com/elastic/logstash/issues/5966>
>
> This is very similar to https://github.com/elastic/logstash/issues/5581, however… proposed solution (update certs) doesn't work for CentOS
> \- LS Version: alpha4/alpha5/beta1 (last version confirmed working alpha2, no chance to try with alpha3)
> \- Operating System: fully updated CentOS 7.
> \- Steps to Reproduce: Installation of any local gem will fail with a reference to 
> 
> \`\`\`
> \# cat /etc/redhat-release 
> CentOS Linux release 7.2.1511 (Core) 
> 
> \# rpm -qa logstash java-\\\*
> logstash-5.0.0~beta1-1.noarch
> java-1.8.0-openjdk-headless-1.8.0.101-3.b13.el7\_2.x86\_64
> 
> \# /usr/share/logstash/bin/logstash-plugin install --local --no-verify /home/maciej/logstash-filter-translate-3.0.0.gemInstalling logstash-filter-translate
> which: no javac in (/usr/local/sbin:/sbin:/usr/sbin:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:/root/bin)
> Error Bundler::InstallError, retrying 1/10
> An error occurred while installing logstash-core-event-java (5.0.0.pre.beta1), and Bundler cannot continue.
> Make sure that \`gem install logstash-core-event-java -v '5.0.0.pre.beta1'\` succeeds before bundling.
> \`\`\`

---

<div class="post-metadata">

**Author:** ![tsmori](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsmori/32/47626_2.png) [@tsmori](https://discuss.elastic.co/u/tsmori)\
**Post date:** [November 1, 2016, 2:13pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/6 "2016-11-01T14:13:03Z")

</div>

And I've just confirmed this. From a server with full internet access the plugin built without any errors.

There was a fix for Ubuntu where you just had to run a command to update certs, but that command doesn't exist on Fedora-based linux.

---

<div class="post-metadata">

**Author:** ![jordansissel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordansissel/32/44957_2.png) [@jordansissel](https://discuss.elastic.co/u/jordansissel)\
**Post date:** [November 1, 2016, 10:40pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/7 "2016-11-01T22:40:03Z")

</div>

> [@tsmori](#):
>
> There was a fix for Ubuntu where you just had to run a command to update certs

I'm confused. Why do you think this is an SSL certificate problem? It doesn't look like one, to me.

---

<div class="post-metadata">

**Author:** ![jordansissel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordansissel/32/44957_2.png) [@jordansissel](https://discuss.elastic.co/u/jordansissel)\
**Post date:** [November 1, 2016, 10:41pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/8 "2016-11-01T22:41:17Z")

</div>

Let's step back for a moment. I have some questions --

1. What command(s) did you run to install logstash?
2. What operating system and version are you on?

---

<div class="post-metadata">

**Author:** ![tsmori](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsmori/32/47626_2.png) [@tsmori](https://discuss.elastic.co/u/tsmori)\
**Post date:** [November 2, 2016, 11:22am UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/9 "2016-11-02T11:22:57Z")

</div>

I'm on Red Hat Enterprise version 7. Logstash is installed via RPM. And I'm not sure why this was solved previously for Ubuntu with the update-ca-certs command. If you follow the Issue link, the core problem is that something involved with the plugin installation isn't honoring OS proxy settings. It didn't seem like an Elastic problem, more like something with jruby's gem build process.

Our logstash servers are not open to the internet, so I have to rely on proxy to get access to anything and I have to specify what sites I need access to.

---

<div class="post-metadata">

**Author:** ![michelmooren](https://avatars.discourse-cdn.com/v4/letter/m/ebca7d/32.png) [@michelmooren](https://discuss.elastic.co/u/michelmooren)\
**Post date:** [November 7, 2016, 9:57am UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/10 "2016-11-07T09:57:03Z")

</div>

Downloaded and extracted the logstash 5 TAR.

command used to install the plugin: bin\logstash-plugin  
install logstash-filter-translate

os: windows 7 Professional SP1

If I try to install the gem as suggested in the error message, then I get the following error:

jar dependencies for logstash-core-event-java-5.0.0-java.gemspec . . .  
[ERROR] [ERROR] Some problems were encountered while processing the POMs:  
[FATAL] Non-parseable POM H:\Development\ELK5\logstash-5.0.0\vendor\jruby\lib\ruby\shared\jars\gemspec\_pom.rb: only whitespace content allowed before start tag and not # (position: START\_DOCUMENT seen #... @1:1) @ line 1, column 1  
@  
[ERROR] The build could not read 1 project -\> [Help 1]  
[ERROR]  
[ERROR] The project (H:\Development\ELK5\logstash-5.0.0\vendor\jruby\lib\ruby\shared\jars\gemspec\_pom.rb) has 1 error  
[ERROR] Non-parseable POM H:\Development\ELK5\logstash-5.0.0\vendor\jruby\lib\ruby\shared\jars\gemspec\_pom.rb: only whitespace content allowed before start tag and not # (position: START\_DOCUMENT seen #... @1:1) @ line 1, column 1 -\> [Help 2]  
[ERROR]  
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.  
[ERROR] Re-run Maven using the -X switch to enable full debug logging.  
[ERROR]  
[ERROR] For more information about the errors and possible solutions, please read the following articles:  
[ERROR] [Help 1] [http://cwiki.apache.org/confluence/display/MAVEN/ProjectBuildingException](http://cwiki.apache.org/confluence/display/MAVEN/ProjectBuildingException)  
[ERROR] [Help 2] [http://cwiki.apache.org/confluence/display/MAVEN/ModelParseException](http://cwiki.apache.org/confluence/display/MAVEN/ModelParseException)

---

<div class="post-metadata">

**Author:** ![pdevrien](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@pdevrien](https://discuss.elastic.co/u/pdevrien)\
**Post date:** [November 23, 2016, 5:28pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/11 "2016-11-23T17:28:46Z")

</div>

Is there already a solution to this?  
I'm experiencing the same issue. I'm behind a proxy.

Thanks.

---

<div class="post-metadata">

**Author:** ![tbmorris78](https://avatars.discourse-cdn.com/v4/letter/t/65b543/32.png) [@tbmorris78](https://discuss.elastic.co/u/tbmorris78)\
**Post date:** [November 24, 2016, 1:25am UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/12 "2016-11-24T01:25:04Z")

</div>

I'm also having this problem, but I am on an isolated network with no Internet access. I have to burn anything I want to CD/DVD and transfer it to my network. Any ideas would be greatly appreciated.

Terry

---

<div class="post-metadata">

**Author:** ![pdevrien](https://avatars.discourse-cdn.com/v4/letter/p/ba9def/32.png) [@pdevrien](https://discuss.elastic.co/u/pdevrien)\
**Post date:** [November 24, 2016, 9:06am UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/13 "2016-11-24T09:06:18Z")

</div>

I found the solution when using proxy.  
Two articles:

> <https://github.com/elastic/logstash/issues/6044>

  
Need to configure proxy settings in:  
/usr/share/logstash/vendor/bundle/jruby/1.9/gems/ruby-maven-libs-3.3.9/maven-home/conf/settings.xml

I Also tried advise from

> <https://github.com/elastic/logstash/issues/2557>

but not sure it had an impact.  
(add export JAVA\_OPTS="$JAVA\_OPTS -Dhttp.proxyHost=HOST -Dhttp.proxyPort=PORT"  
in /usr/share/logstash/bin/logstash-plugin before the ruby\_exec)

---

<div class="post-metadata">

**Author:** ![cperriot](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cperriot](https://discuss.elastic.co/u/cperriot)\
**Post date:** [November 25, 2016, 5:45pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/14 "2016-11-25T17:45:22Z")

</div>

Same problem here. I tried everything suggested above.

On logstash 5.0.1 installed behind a proxy on a windows server I tried : logstash-plugin.bat install logstash-filter-elapsed  
and it failed:  
\> C:\logstash-5.0.1\bin\>logstash-plugin.bat install logstash-filter-elapsed

> Validating logstash-filter-elapsed  
> Installing logstash-filter-elapsed  
> Plugin version conflict, aborting  
> ERROR: Installation Aborted, message: Bundler could not find compatible versions  
> for gem "logstash-core-plugin-api":  
> In snapshot (Gemfile.lock):  
> logstash-core-plugin-api (= 2.1.16)  
> In Gemfile:  
> logstash-devutils (~\> 1.1) java depends on  
> logstash-core-plugin-api (~\> 2.0) java  
> logstash-input-s3 (\>= 0) java depends on  
> logstash-mixin-aws (\>= 0) java depends on  
> logstash-core-plugin-api (\<= 2.99, \>= 1.60) java  
> [...]  
> logstash-filter-elapsed (\>= 0) java depends on  
> logstash-core-plugin-api (~\> 1.0) java  
> logstash-core-plugin-api (\>= 0) java  
> Running `bundle update` will rebuild your snapshot from scratch, using only  
> the gems in your Gemfile, which may resolve the conflict.  
> Bundler could not find compatible versions for gem "logstash-core":  
> In snapshot (Gemfile.lock):  
> logstash-core (= 5.0.1)  
> In Gemfile:  
> logstash-core-plugin-api (\>= 0) java depends on  
> logstash-core (= 5.0.1) java  
> logstash-filter-elapsed (\>= 0) java depends on  
> logstash-core (\< 2.0.0, \>= 1.4.0) java

> ```
> logstash-core (>= 0) java
> 
> ```

> Running `bundle update` will rebuild your snapshot from scratch, using only  
> the gems in your Gemfile, which may resolve the conflict.  
> Bundler could not find compatible versions for gem "logstash":  
> In Gemfile:  
> logstash-filter-elapsed (\>= 0) java depends on  
> logstash (\< 2.0.0, \>= 1.4.0) java  
> Could not find gem 'logstash (\< 2.0.0, \>= 1.4.0) java', which is required by gem  
> 'logstash-filter-elapsed (\>= 0) java', in any of the sources.

---

<div class="post-metadata">

**Author:** ![cperriot](https://avatars.discourse-cdn.com/v4/letter/c/f475e1/32.png) [@cperriot](https://discuss.elastic.co/u/cperriot)\
**Post date:** [November 25, 2016, 8:30pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/15 "2016-11-25T20:30:17Z")

</div>

I just tried home without any proxy and I'm getting the same error under windows 10 with a fresh logstash download.

---

<div class="post-metadata">

**Author:** ![helloworld](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/helloworld/32/33768_2.png) [@helloworld](https://discuss.elastic.co/u/helloworld)\
**Post date:** [November 27, 2016, 1:46pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/16 "2016-11-27T13:46:57Z")

</div>

My VM(RHEL-6) is also behind the proxy and have gone through the similar kind of issues when I am trying to install logstash-filter-yaml plugin. Seems both online and offline methods are failing.

---

<div class="post-metadata">

**Author:** ![Akulatraxas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/akulatraxas/32/14011_2.png) [@Akulatraxas](https://discuss.elastic.co/u/Akulatraxas)\
**Post date:** [December 20, 2016, 12:27pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/17 "2016-12-20T12:27:43Z")

</div>

Same issue on RHEL 7 and Centos7 in Logstash 5.1 (logstash-5.1.1-1.noarch)

-bash-4.2$ bin/logstash-plugin install logstash-filter-translate  
Validating logstash-filter-translate  
Installing logstash-filter-translate  
Error Bundler::InstallError, retrying 1/10  
An error occurred while installing logstash-core-event-java (5.1.1), and Bundler cannot continue.  
Make sure that `gem install logstash-core-event-java -v '5.1.1'` succeeds before bundling.  
WARNING: SSLSocket#session= is not supported

---

<div class="post-metadata">

**Author:** ![deanso](https://avatars.discourse-cdn.com/v4/letter/d/94ad74/32.png) [@deanso](https://discuss.elastic.co/u/deanso)\
**Post date:** [December 20, 2016, 4:59pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/18 "2016-12-20T16:59:30Z")

</div>

Same issue on RHEL 6 with fresh install of logstash-5.1.1

command to install plugin:  
export HTTP\_PROXY=http://proxy.local  
bin/logstash-plugin install logstash-filter-translate  
Validating logstash-filter-translate  
Installing logstash-filter-translate  
which: no javac in (/usr/local/sbin:/usr/sbin:/sbin:/home/logstash/bin:/usr/bin/java:/home/logstash/bin:/usr/bin/java)  
Error Bundler::InstallError, retrying 1/10  
An error occurred while installing logstash-core-event-java (5.1.1), and Bundler cannot continue.  
Make sure that `gem install logstash-core-event-java -v '5.1.1'` succeeds before bundling.

---

<div class="post-metadata">

**Author:** ![daniellienert](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniellienert/32/31435_2.png) [@daniellienert](https://discuss.elastic.co/u/daniellienert)\
**Post date:** [December 21, 2016, 4:27pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/19 "2016-12-21T16:27:13Z")

</div>

Hey,

same here on a Ubuntu 16.04.1 LTS box for a fresh logstash-5.1.1 installation:

```
/usr/share/logstash/bin/logstash-plugin install logstash-filter-elasticsearch
Validating logstash-filter-elasticsearch
Installing logstash-filter-elasticsearch
OpenJDK 64-Bit Server VM warning: INFO: os::commit_memory(0x00000000f4100000, 74448896, 0) failed; error='Cannot allocate memory' (errno=12)
Error Bundler::InstallError, retrying 1/10
An error occurred while installing logstash-core-event-java (5.1.1), and Bundler cannot continue.
Make sure that `gem install logstash-core-event-java -v '5.1.1'` succeeds before bundling.
WARNING: SSLSocket#session= is not supported
OpenJDK 64-Bit Server VM warning: INFO: os::commit_memory(0x00000000f4300000, 78118912, 0) failed; error='Cannot allocate memory' (errno=12)
```

---

<div class="post-metadata">

**Author:** ![deanso](https://avatars.discourse-cdn.com/v4/letter/d/94ad74/32.png) [@deanso](https://discuss.elastic.co/u/deanso)\
**Post date:** [December 21, 2016, 5:19pm UTC](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313/20 "2016-12-21T17:19:10Z")

</div>

I see you get an sslSocket warning. I also saw it in one of my (many) attempts.  
It could be ssl related: ie that the proxy doesn't allow the use of https?

[Next page](https://discuss.elastic.co/t/i-can-not-install-any-logstash-plug-in-in-es-5-0/64313.md?page=2)
