# Log Stash config error

**URL:** <https://discuss.elastic.co/t/log-stash-config-error/61135>\
**Category:** Logstash\
**Created:** [September 21, 2016, 1:13pm UTC](https://discuss.elastic.co/t/log-stash-config-error/61135 "2016-09-21T13:13:24Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![alvaroca1](https://avatars.discourse-cdn.com/v4/letter/a/58f4c7/32.png) [@alvaroca1](https://discuss.elastic.co/u/alvaroca1)\
**Post date:** [September 21, 2016, 1:13pm UTC](https://discuss.elastic.co/t/log-stash-config-error/61135/1 "2016-09-21T13:13:24Z")

</div>

Good day,  
I'm trying to load a logstash config with multiple grok filters and it gives me an error when I run a config test

.\logstash.bat : io/console not supported; tty will not be manipulated  
At line:1 char:1

- .\logstash.bat -f .\logstasg.conf -t
- 

```auto
  + CategoryInfo : NotSpecified: (io/console not ... be manipulated:String) [], RemoteException
  + FullyQualifiedErrorId : NativeCommandError

```

{:timestamp=\>"2016-09-21T08:59:10.007000-0400", :message=\>"The given configuration is invalid. Reason: Expected one of #, =\> at line 11, column 6 (byte 6  
8) after filter {\n grok {\n if ", :level=\>:fatal}

---

<div class="post-metadata">

**Author:** ![alvaroca1](https://avatars.discourse-cdn.com/v4/letter/a/58f4c7/32.png) [@alvaroca1](https://discuss.elastic.co/u/alvaroca1)\
**Post date:** [September 21, 2016, 1:14pm UTC](https://discuss.elastic.co/t/log-stash-config-error/61135/2 "2016-09-21T13:14:37Z")

</div>

This is my conf file: any help will be extremely appreciated.

input {

beats {

```
port => 5044

```

}  
}

filter {  
grok {  
if [event\_id] == 4743 {  
grok {  
match =\> { "message" =\>" (?#4625)(?[\w|\s]+.)\n\nSubject:\n\s_Security\sID:\s+(?\<subject\_security\_id\>.+)\n\s+Account\sName:\s+(?\<account\_name\>.+)\n\s+Account\sDomain:\s+(?\<account\_domain\>\w+)\n\s+Logon\sID:\s+(?\<logon\_id\>.+)\n\nLogon\sType:\s+(?\<logon\_type\>\d+)\n\nAccount\sFor\sWhich\sLogon\sFailed:\n\s+Security\sID:\s+(.+)\n\s+Account\sName:\s+(?\<logon\_failure\_account\_name\>.+)\n\s+Account\sDomain:\s+(?\<logon\_failure\_account\_domain\>\w+)\n\nFailure\sInformation:\n\s+Failure\sReason:\s+(?\<failure\_reason\>.+)\n\s+Status:\s+(?\<failure\_status\>.+)  
}  
}  
}  
if [event\_id] == 4740 {  
grok {  
match =\> { "message" =\>" (?#4740)(?[\w|\s]+.)\n\nSubject:\n\s_Security\sID:\s+(.+)\n\s+Account\sName:\s+(?\<account\_name\>.+)\n\s+Account\sDomain:\s+(?\<account\_domain\>\w+)\n\s+Logon\sID:\s+(?\<logon\_id\>.+)\n\nAccount\sThat\sWas\sLocked Out:\n\s+Security\sID:\s+(.+)\n\s+Account\sName:\s+(?\<locked\_account\_name\>.+)\n\nAdditional\sInformation:\n\s+Caller\sComputer\sName:\s+(?\<caller\_computer\_name\>.+)" }  
}  
}  
}  
if [event\_id] == 4743 {  
grok {  
match =\> { "message" =\> " (?#4743)(?[\w|\s]+.)\n\nSubject:\n\s\*Security\sID:\s+(?\<subject\_security\_id\>[^\s]+)\n\s+Account\sName:\s+(?\<account\_name\>\w+)\n\s+Account\sDomain:\s+(?\<account\_domain\>\w+)\n\s+Logon\sID:\s+(?\<logon\_id\>.+)\n\nTarget\sComputer:\n\s+Security\sID:\s+(?\<target\_security\_id\>[^\s]+)\n\s+Account\sName:\s+(?\<target\_account\_name\>.+)\n\s+Account\sDomain:\s+(?\<target\_account\_domain\>.+)" }  
}  
}  
}  
}

output {  
elasticsearch {  
hosts =\> ["192.168.10.80:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 21, 2016, 1:58pm UTC](https://discuss.elastic.co/t/log-stash-config-error/61135/3 "2016-09-21T13:58:11Z")

</div>

Please move your post to the Logstash category since it has nothing to do with logstash-forwarder.

It looks like there's no closing double quote for the first grok expression.

---

<div class="post-metadata">

**Author:** ![alvaroca1](https://avatars.discourse-cdn.com/v4/letter/a/58f4c7/32.png) [@alvaroca1](https://discuss.elastic.co/u/alvaroca1)\
**Post date:** [September 21, 2016, 2:31pm UTC](https://discuss.elastic.co/t/log-stash-config-error/61135/4 "2016-09-21T14:31:11Z")

</div>

how would that look?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 21, 2016, 2:35pm UTC](https://discuss.elastic.co/t/log-stash-config-error/61135/5 "2016-09-21T14:35:48Z")

</div>

What? There's no double quote at the end of your first grok expression. I don't know how to explain that in another way.

---

<div class="post-metadata">

**Author:** ![trenzalore](https://avatars.discourse-cdn.com/v4/letter/t/ac91a4/32.png) [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Post date:** [September 21, 2016, 2:37pm UTC](https://discuss.elastic.co/t/log-stash-config-error/61135/6 "2016-09-21T14:37:51Z")

</div>

you missed a " at the end of your first match.  
you also have too many {  
Check all your opening and closing brackets, you have too many of them

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:37am UTC](https://discuss.elastic.co/t/log-stash-config-error/61135/7 "2017-07-06T04:37:33Z")

</div>


