# Issue while running the logstash

**URL:** <https://discuss.elastic.co/t/issue-while-running-the-logstash/306884>\
**Category:** Kibana\
**Created:** [June 10, 2022, 12:14pm UTC](https://discuss.elastic.co/t/issue-while-running-the-logstash/306884 "2022-06-10T12:14:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akanksha2022](https://avatars.discourse-cdn.com/v4/letter/a/a5b964/32.png) [@Akanksha2022](https://discuss.elastic.co/u/Akanksha2022)\
**Post date:** [June 10, 2022, 12:14pm UTC](https://discuss.elastic.co/t/issue-while-running-the-logstash/306884/1 "2022-06-10T12:14:10Z")

</div>

runner - The given configuration is invalid. Reason: Failed to parse right-hand side of conditional [file]/etc/logstash/conf.d/logstash-grok.conf:70:45:```

---

<div class="post-metadata">

**Author:** ![Akanksha2022](https://avatars.discourse-cdn.com/v4/letter/a/a5b964/32.png) [@Akanksha2022](https://discuss.elastic.co/u/Akanksha2022)\
**Post date:** [June 10, 2022, 12:16pm UTC](https://discuss.elastic.co/t/issue-while-running-the-logstash/306884/2 "2022-06-10T12:16:09Z")

</div>

Is there any wrong with my config.

#1. Match 'message' field structure to corresponding fields. Doubled percent symbol is for correct ERB interpretation.  
grok {  
match =\> { "message" =\> '\<%{POSINT:syslog\_pri}\>%{SPACE}%{NUMBER:syslog\_version}%{SPACE}%{TIMESTAMP\_ISO8601:syslog\_timestamp}%{SPACE}%{DATA:syslog\_cdn\_id}%{SPACE}Apigee-Edge(%{SPACE}-%{SPACE})+%{GREEDYDATA:syslog\_message}' }  
keep\_empty\_captures =\> true  
tag\_on\_failure =\> ["\_grokparsefailure", "\_grok\_1"]  
}

#2. Create custom field(s).  
mutate {  
add\_field =\> { "collector\_id" =\> "logstash\_new\_test7--0ce8bb6cf7572a765" }  
}

#3. Amend "syslog\_message" string to make it parsable further by 'json' filter.  
mutate { gsub =\> ["syslog\_message", "\u0000", ""] }

#4. Json-ify the raw string data. Without 'target' option the JSON data will be stored at the root (top level) of the event.  
json { source =\> "syslog\_message" }

#5. Extract values from a field into their own fields by matching the pattern for /data api\_base\_path only and keep empty matches.  
if [api\_base\_path] =~ //data/ {  
grok {  
match =\> ["path\_suffix", "/(?[a-zA-Z]+).??(?\<response\_format\>[a-zA-Z]+)??/?$"]  
keep\_empty\_captures =\> true  
tag\_on\_failure =\> ["\_grokparsefailure", "\_grok\_2"]  
}  
}  
#6. Use the date from 'request\_timestamp' field as event's time in Kibana.

# It's important to execute this filter after 'request\_timestamp' has been created by grok/json filters.

date {  
match =\> ["request\_timestamp", "UNIX\_MS"]  
target =\> "@timestamp"  
}

#7. Miscellaneous fields processing section.  
if [http\_x\_forwarded\_for] {  
mutate { split =\> ["http\_x\_forwarded\_for", ","] }  
}  
#8. Extract geolocation data based on IPv4/IPv6 addresses. If no match is found, "\_geoip\_lookup\_failure" is added to tags.  
if [remote\_addr] {

```
# Copy 'remote_addr' field, strip spaces, text and split into array.
mutate { add_field => ["remote_addr_copy", "%{remote_addr}"] }
mutate { gsub => ["remote_addr_copy", " ", ""] }
mutate { gsub => ["remote_addr_copy", "^[a-zA-Z_-]+$", "" ] } # to avoid gsub'ing IPv6 addresses
mutate { split => ["remote_addr_copy", ","] }

# Strip off local IP ranges and pass only external IPs list to geoip filter.
ruby {
  code => "begin
             ips_list = event.get('remote_addr_copy')
             filtered_list = []
             ips_list.each do |ip|
               if ip !~ /(?:10|127|172\.(?:1[6-9]|2[0-9]^C[01])|192\.168)\..*/
                   filtered_list.push(ip)
               end
             end
             event.set('remote_addr_copy', filtered_list)
           end"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2022, 12:17pm UTC](https://discuss.elastic.co/t/issue-while-running-the-logstash/306884/3 "2022-07-08T12:17:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
