# Issue with Ruby and logstash-input-imap

**URL:** <https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935>\
**Category:** Logstash\
**Created:** [June 7, 2018, 9:07am UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935 "2018-06-07T09:07:17Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexa](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@Alexa](https://discuss.elastic.co/u/Alexa)\
**Post date:** [June 7, 2018, 9:07am UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/1 "2018-06-07T09:07:17Z")

</div>

Afer configuring the impa plugin on logstash and running the following command:

bin/logstash -f email\_log.conf --path.data /var/lib/logstash/imap --config.reload.automatic

I get the following error:

[ERROR] 2018-06-06 13:33:11.795 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] agent - Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, =\> at line 13, column 20 (byte 214) after output {\n stdout { codec ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:105:in `block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:18:in`interval'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:94:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:348:in`block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

Checking at line 13 on the script task.rb I can see the following 🙂

class Task

... the full code output is:

require "thread"  
require "stud/interval"

module Stud

# A Task spawns a thread to execute the given block. execution completion and result retrieval is

# done using the Task#wait method. A Task is run once and the thread exists upon block completion.

# A task and its underlying thread are not reusable.

# 

# Task does not provide a mean to force-interrupt a running task, it only provides the #stop!

# method to signal the task for a stop request. The task or code block can use the #stop? method

# to check for a stop request. Note that the #stop! and #stop? methods are thread safe.

class Task  
# provide access to the underlying thread if ever needed.  
attr\_reader :thread

```
def initialize(*args, &block)
  # A queue to receive the result of the block
  # TODO(sissel): Don't use a queue, just store it in an instance variable.
  @queue = Queue.new

  @thread = Thread.new(@queue, *args) do |queue, *args|
    begin
      result = block.call(*args)
      queue << [:return, result]
    rescue => e
      queue << [:exception, e]
    end
  end # thread
end # def initialize

# wait waits for the task thread to complete and return the block return value
# if the block raises an exception, this exception is propagated in this
# wait method.
# @return [Object, Exception] block return value
def wait
  @thread.join
  reason, result = @queue.pop

  if reason == :exception
    #raise StandardError.new(result)
    raise result
  else
    return result
  end
end # def wait

# stop! requests the task to stop. the Thread#wakeup method is also
# called so that a sleeping task is waked up and has a chance to verify
# the stop request using the #stop? method. also see Stud.stop!
def stop!
  Stud.stop!(@thread)
end

# stop? returns true if this task stop! has been called
# See Stud.stop?
# @return [Boolean] true if the stop! has been called
def stop?
  Stud.stop?(@thread)
end
alias_method :interrupted?, :stop?

```

end # class Task  
end # module Stud

Is anybody able to assist with this error please, as the error notification seems to be pointing to the wrong place, else there may be a bug with this module on Elasticsearch 6.2.0

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2018, 10:30am UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/2 "2018-06-07T10:30:58Z")

</div>

It is noticing the error at line 13 of email\_log.conf. Can you post that file?

---

<div class="post-metadata">

**Author:** ![Alexa](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@Alexa](https://discuss.elastic.co/u/Alexa)\
**Post date:** [June 7, 2018, 11:19am UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/3 "2018-06-07T11:19:28Z")

</div>

Thank you for the pointer, I noticed that there was an extraneous \> in that line which I have since taken out and am restarting all the processes

Alexa

---

<div class="post-metadata">

**Author:** ![Alexa](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@Alexa](https://discuss.elastic.co/u/Alexa)\
**Post date:** [June 7, 2018, 11:30am UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/4 "2018-06-07T11:30:19Z")

</div>

> [@Alexa](#):
>
> email\_log.conf

I have edited and restarted the processes however this error is still showing. the email\_log.conf file is:

#email\_log.conf  
input {  
imap {  
host =\> "**..net"  
password =\> " **\*\*\***"  
user =\> "test-imap@**.net"  
port =\> 143  
check\_interval =\> 10  
folder =\> "Inbox"  
}  
}  
output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
index =\> "emails"  
document\_type =\> "email"  
hosts =\> "localhost:9200"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2018, 11:38am UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/5 "2018-06-07T11:38:23Z")

</div>

Exactly what error message do you get with that file?

---

<div class="post-metadata">

**Author:** ![Alexa](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@Alexa](https://discuss.elastic.co/u/Alexa)\
**Post date:** [June 7, 2018, 11:52am UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/6 "2018-06-07T11:52:38Z")

</div>

It has changed, now the error (I have everything set to perform stdout to console) is:

[ERROR] 2018-06-07 11:51:03.882 [[main]\<imap] pipeline - A plugin had an unrecoverable error. Will restart this plugin.  
Pipeline\_id:main  
Plugin: \<LogStash::Inputs::IMAP host=\>"[bandal.owta.net](http://bandal.owta.net)", password=\>, user=\>"test-imap@owta.net", port=\>143, check\_interval=\>10, folder=\>"Inbox", id=\>"c5687598a52bbd85958d432fd18433530c150d94801456b1fbb544308bbb558a", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_c35559f2-eaa6-4958-9316-495b3cc47dbd", enable\_metric=\>true, charset=\>"UTF-8"\>, secure=\>true, verify\_cert=\>true, fetch\_count=\>50, lowercase\_headers=\>true, delete=\>false, expunge=\>false, strip\_attachments=\>false, content\_type=\>"text/plain"\>  
Error: Unrecognized SSL message, plaintext connection?  
Exception: OpenSSL::SSL::SSLError  
Stack: org/jruby/ext/openssl/SSLSocket.java:218:in `connect' uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/imap.rb:1492:in`start\_tls\_session'  
uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/imap.rb:1085:in `initialize' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-imap-3.0.6/lib/logstash/inputs/imap.rb:61:in`connect'  
/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-imap-3.0.6/lib/logstash/inputs/imap.rb:76:in `check_mail' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-imap-3.0.6/lib/logstash/inputs/imap.rb:69:in`block in run'  
/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:20:in `interval' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-imap-3.0.6/lib/logstash/inputs/imap.rb:68:in`run'  
/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:514:in `inputworker' /usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:507:in`block in start\_input'

---

<div class="post-metadata">

**Author:** ![Alexa](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@Alexa](https://discuss.elastic.co/u/Alexa)\
**Post date:** [June 7, 2018, 11:53am UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/7 "2018-06-07T11:53:28Z")

</div>

The complaint is about ssl. The imap mailbox is starttls and I am not employing (currently) any form of ssl on the stack

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2018, 12:30pm UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/8 "2018-06-07T12:30:31Z")

</div>

SSL is on by default. Set 'secure =\> false' for the imap plugin.

---

<div class="post-metadata">

**Author:** ![Alexa](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@Alexa](https://discuss.elastic.co/u/Alexa)\
**Post date:** [June 7, 2018, 12:43pm UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/9 "2018-06-07T12:43:50Z")

</div>

> [@Badger](#):
>
> Set 'secure =\> false' for the imap plugin

Thank you so much for the pointers. I had noted that it was doing this by default and have now set it to false, along with trying the config with verify\_cert set and not set:

#email\_log.conf  
input {  
imap {  
host =\> "[bandal.owta.net](http://bandal.owta.net)"  
password =\> "GrabFiles"  
user =\> "[test-imap@owta.net](mailto:test-imap@owta.net)"  
port =\> 143  
secure =\> false  
verify\_cert =\> true  
check\_interval =\> 300  
folder =\> "Inbox"  
}  
}  
output {  
stdout { codec =\> rubydebug }  
elasticsearch {  
index =\> "emails"  
document\_type =\> "email"  
hosts =\> "localhost:9200"  
}

It is however still erroring on trying to connect to the imap mailbox:

[ERROR] 2018-06-07 12:41:30.925 [[main]\<imap] pipeline - A plugin had an unrecoverable error. Will restart this plugin.  
Pipeline\_id:main  
Plugin: \<LogStash::Inputs::IMAP host=\>"[bandal.owta.net](http://bandal.owta.net)", password=\>, user=\>"[test-imap@owta.net](mailto:test-imap@owta.net)", port=\>143, secure=\>false, verify\_cert=\>true, check\_interval=\>300, folder=\>"Inbox", id=\>"51191afd186cc52fe992d9de46d6ee3524721585ad3ccb5b742a60728a54bda0", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_feafede3-8759-414b-8e4e-d2408c204c06", enable\_metric=\>true, charset=\>"UTF-8"\>, fetch\_count=\>50, lowercase\_headers=\>true, delete=\>false, expunge=\>false, strip\_attachments=\>false, content\_type=\>"text/plain"\>  
Error: cleartext logins disabled  
Exception: Net::IMAP::NoResponseError  
Stack: uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/imap.rb:1196:in `get_tagged_response' uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/imap.rb:1250:in `block in send\_command'  
uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/monitor.rb:214:in `mon_synchronize' uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/imap.rb:1232:in `send\_command'  
uri:classloader:/META-INF/jruby.home/lib/ruby/stdlib/net/imap.rb:436:in `login' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-imap-3.0.6/lib/logstash/inputs/imap.rb:62:in `connect'  
/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-imap-3.0.6/lib/logstash/inputs/imap.rb:76:in `check_mail' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-imap-3.0.6/lib/logstash/inputs/imap.rb:69:in `block in run'  
/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:20:in `interval' /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-input-imap-3.0.6/lib/logstash/inputs/imap.rb:68:in `run'  
/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:514:in `inputworker' /usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:507:in `block in start\_input'

Alexa

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 7, 2018, 1:16pm UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/10 "2018-06-07T13:16:29Z")

</div>

> [@Alexa](#):
>
> Error: cleartext logins disabled

I think that is telling you that you have to use SSL. The IMAP server is configured not to let you send credentials across the network unencrypted. So you need to switch secure to be true, and change the port to the IMAP SSL port. Or just not set the port if your IMAP server listens on 993.

---

<div class="post-metadata">

**Author:** ![Alexa](https://avatars.discourse-cdn.com/v4/letter/a/e36b37/32.png) [@Alexa](https://discuss.elastic.co/u/Alexa)\
**Post date:** [June 7, 2018, 1:33pm UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/11 "2018-06-07T13:33:35Z")

</div>

I am checking just this with the administrator of the mail server as we speak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2018, 1:33pm UTC](https://discuss.elastic.co/t/issue-with-ruby-and-logstash-input-imap/134935/12 "2018-07-05T13:33:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
