# Log flooded with error messages

**URL:** <https://discuss.elastic.co/t/log-flooded-with-error-messages/220897>\
**Category:** Logstash\
**Created:** [February 25, 2020, 4:45pm UTC](https://discuss.elastic.co/t/log-flooded-with-error-messages/220897 "2020-02-25T16:45:11Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![stefan\_schumacher](https://avatars.discourse-cdn.com/v4/letter/s/ecccb3/32.png) [@stefan\_schumacher](https://discuss.elastic.co/u/stefan_schumacher)\
**Post date:** [February 26, 2020, 12:11pm UTC](https://discuss.elastic.co/t/log-flooded-with-error-messages/220897/3 "2020-02-26T12:11:12Z")

</div>

Hello,

I have started logstash manually and monitored the output. There are sections like the following:  
(Hostnames and IPs replaced by XXX)

"log" =\> {  
"offset" =\> 36099,  
"file" =\> {  
"path" =\> "/var/log/nginx/access\_corporate-lounge.de.log"  
}  
},  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied",  
[1] "nginx-geoip"  
],  
"clientip" =\> "89.XXX",  
"request" =\> "/",  
"message" =\> "89.XXX - - [26/Feb/2020:13:03:46 +0100] "GET / HTTP/1.1" 301 178 "-" "check\_http/v2.2 (monitoring-plugins 2.2)"",  
"httpversion" =\> "1.1",  
"ident" =\> "-",  
"referrer" =\> ""-"",  
"auth" =\> "-",  
"verb" =\> "GET",  
"@timestamp" =\> 2020-02-26T12:03:46.000Z,  
"response" =\> 301,  
"ecs" =\> {  
"version" =\> "1.1.0"  
},  
"agent" =\> {  
"id" =\> "b79a760d-b445-430b-86eb-c27229ebea56",  
"ephemeral\_id" =\> "32cda409-1a33-4864-a478-9c83110f45ce",  
"version" =\> "7.5.2",  
"hostname" =\> "xxxx",  
"type" =\> "filebeat"  
},  
"@version" =\> "1",  
"host" =\> {  
"containerized" =\> false,  
"os" =\> {  
"family" =\> "debian",  
"version" =\> "9 (stretch)",  
"codename" =\> "stretch",  
"kernel" =\> "4.9.0-8-amd64",  
"platform" =\> "debian",  
"name" =\> "Debian GNU/Linux"  
},  
"hostname" =\> "xxxxxx",  
"id" =\> "522a68580a704f4b85b17ef9c7e870a7",  
"architecture" =\> "x86\_64",  
"name" =\> "xxxxx"  
},  
"bytes" =\> 178,  
"geoip" =\> {  
"region\_code" =\> "NH",  
"ip" =\> "89.XXX",  
"timezone" =\> "Europe/Amsterdam",  
"country\_code2" =\> "NL",  
"city\_name" =\> "Schellinkhout",  
"latitude" =\> 52.6371,  
"country\_name" =\> "Netherlands",  
"country\_code3" =\> "NL",  
"postal\_code" =\> "1697",  
"continent\_code" =\> "EU",  
"region\_name" =\> "North Holland",  
"longitude" =\> 5.1224,  
"location" =\> {  
"lat" =\> 52.6371,  
"lon" =\> 5.1224  
}  
},  
"input" =\> {  
"type" =\> "log"

interspersed with the errors seen in the logstash logs:  
[ERROR] 2020-02-26 13:08:45.590 [[main]\>worker1] useragent - Uknown error while parsing user agent data {:exception=\>#\<TypeError: cannot convert instance of class org.jruby.RubyHash to class java.lang.String\>, :field=\>"agent", :event=\>#LogStash::Event:0x18ece00f}

[ERROR] 2020-02-26 13:07:50.580 [[main]\>worker2] useragent - Uknown error while parsing user agent data {:exception=\>#\<TypeError: cannot convert instance of class org.jruby.RubyHash to class java.lang.String\>, :field=\>"agent", :event=\>#LogStash::Event:0x596ebf58}

Is this of any help in diagnosing the problem?

Yours faithfully  
Stefan

---

_[View the full topic](https://discuss.elastic.co/t/log-flooded-with-error-messages/220897)._
