# I have problem with the logstash configuration

**URL:** <https://discuss.elastic.co/t/i-have-problem-with-the-logstash-configuration/249189>\
**Category:** Logstash\
**Created:** [September 18, 2020, 11:43pm UTC](https://discuss.elastic.co/t/i-have-problem-with-the-logstash-configuration/249189 "2020-09-18T23:43:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pablo\_Rivadeneira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pablo_rivadeneira/32/75848_2.png) [@Pablo\_Rivadeneira](https://discuss.elastic.co/u/Pablo_Rivadeneira)\
**Post date:** [September 18, 2020, 11:43pm UTC](https://discuss.elastic.co/t/i-have-problem-with-the-logstash-configuration/249189/1 "2020-09-18T23:43:46Z")

</div>

this is my configuration file

input {  
file {  
path =\> ["C:/Users/user03/Documents/sistema\_TPG/88.-Elasticsearch/testlog.log"]  
start\_position =\> "beginning"  
sincedb\_path =\> "C:/logstash/logstash/sincedb/logdbpath.txt"  
sincedb\_write\_interval =\> 10  
}  
}  
filter {  
mutate {  
add\_field =\> { "title" =\> "app test" }  
remove\_field =\> ["tags" ,"host", "path", "@version", "column5", "@timestamp", "log-level"]  
rename =\> ["@timestamp", "date"]  
}  
grok {  
match =\> { "timestamp" =\> "^(?\<date\_registro\>.{16})" }  
match =\> { "message" =\> "%{LOGLEVEL:log-level}" }  
}  
date {  
match =\> ["timestamp" , "yyyy-MM-dd HH:mm:ss"]  
}  
}

output {

```
  if [log-level] == "ERROR" {
     stdout { codec => rubydebug }
       elasticsearch { 
        hosts => "http://localhost:9200"   
        index => "website" 
      }
  } 

```

}  
this is my log file

2020-09-15 18:39:59 INFO NotificacionCumpleanios:70 - ingresa al proceso paso 1  
2020-09-15 18:39:59 INFO NotificacionCumpleanios:70 - ingresa al proceso paso 2  
2020-09-15 18:39:59 INFO NotificacionCumpleanios:70 - ingresa al proceso paso 3  
2020-09-15 18:39:59 INFO NotificacionCumpleanios:70 - ingresa al proceso paso 4  
2020-09-15 18:39:59 INFO NotificacionCumpleanios:70 - ingresa al proceso paso 5 dentro de Try  
2020-09-15 18:39:59 ERROR NotificacionCumpleanios:42 - Exception: Esta es una Exception intencional

The problem I have is that when reading the [log-level] field, the matrix does not always work, when it is not, it is not evaluated and it is not sent to logstash despite deleting the log file sincedb\_path =\> "C: / logstash / logstash / sincedb / logdbpath.txt "

work on windows operating system

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 16, 2020, 11:44pm UTC](https://discuss.elastic.co/t/i-have-problem-with-the-logstash-configuration/249189/2 "2020-10-16T23:44:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
