# Log stash Configuration Error

**URL:** <https://discuss.elastic.co/t/log-stash-configuration-error/116280>\
**Category:** Logstash\
**Created:** [January 19, 2018, 5:00pm UTC](https://discuss.elastic.co/t/log-stash-configuration-error/116280 "2018-01-19T17:00:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [January 19, 2018, 5:00pm UTC](https://discuss.elastic.co/t/log-stash-configuration-error/116280/1 "2018-01-19T17:00:15Z")

</div>

When I start Logstash I get the below error. I am trying to separate my Gelf and Filebeat input into different indices. Can anyone offer any help?  
Inputs:

```
input {
  gelf {
    host => "10.16.0.5"
    port => 20001
    type => "Gelf"
  }
}

input {
  beats {
    host => "10.16.0.5"
    port => 5044
    type => "Filebeat"
  }
}

```

Outputs:

```
 output {
    if [type] == "Gelf"
        {
            elasticsearch {
            hosts => "localhost:9200"
            user => "elastic"
            password => "dshufhu)}Wk47278C*gx@'fe29[=$$/:"
            index => "Gelf-%{+YYYY.MM.dd}"
            }
    else
        {
            elasticsearch {
            hosts => "localhost:9200"
            user => "elastic"
            password => "dshufhu)}Wk47278C*gx@'fe29[=$$/:"
            index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
            }
      }
    }

```

> [2018-01-19T16:48:24,625][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, =\> at line 29, column 23 (byte 425) after output {\nif [type] == "Gelf"\n {\n elasticsearch {\n hosts =\> "localhost:9200"\n user =\> "elastic"\n password =\> dshufhu)}Wk47278C\*gx@'fe29[=$$/: index =\> "Gelf-%{+YYYY.MM.dd}"\n }\nelse\n {\n elasticsearch ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:50:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:51:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:171:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:335:in `block in converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with\_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:332:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:319:in `converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:166:in `block in converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:164:in `converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:90:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:343:in `block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

cheers,

G

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 23, 2018, 10:14am UTC](https://discuss.elastic.co/t/log-stash-configuration-error/116280/2 "2018-01-23T10:14:01Z")

</div>

There's a `}` missing before `else`.

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [January 23, 2018, 12:45pm UTC](https://discuss.elastic.co/t/log-stash-configuration-error/116280/3 "2018-01-23T12:45:05Z")

</div>

@magnusbaeck cheers for that! I thought it looked about right, I think the } in the password was throwing me off as I was using the PuTTy terminal to check which brackets we're lining up.

Also what type does Logstash ships the logs as? I was wondering what the best way to sort Filebeat logs is, would I sort them on the path field?

Cheers

G

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 23, 2018, 8:37pm UTC](https://discuss.elastic.co/t/log-stash-configuration-error/116280/4 "2018-01-23T20:37:53Z")

</div>

> ```
> index => "Gelf-%{+YYYY.MM.dd}"
> 
> ```

Index names can't contain uppercase characters.

> Also what type does Logstash ships the logs as?

That depends on the output plugin and its codec.

> I was wondering what the best way to sort Filebeat logs is, would I sort them on the path field?

You mean how to distinguish between different kinds of logs? Yes, you can use the path to the log but I don't think it's a very good choice. Make sure you create the fields you need in order to keep log events apart. Maybe you want an application name field? That together with the hostname and maybe type of log should be sufficient to uniquely identify a particular event stream.

---

<div class="post-metadata">

**Author:** ![MultiplierMultiplier](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/multipliermultiplier/32/25063_2.png) [@MultiplierMultiplier](https://discuss.elastic.co/u/MultiplierMultiplier)\
**Post date:** [January 23, 2018, 9:44pm UTC](https://discuss.elastic.co/t/log-stash-configuration-error/116280/5 "2018-01-23T21:44:13Z")

</div>

Thanks for all of that, I'll change my config tomorrow and let you know how I get along.

As with separating different types of logs, are you saying to add something like the 'application' field in Filebeat itself?

Cheers,

G

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 25, 2018, 10:09am UTC](https://discuss.elastic.co/t/log-stash-configuration-error/116280/6 "2018-01-25T10:09:40Z")

</div>

> As with separating different types of logs, are you saying to add something like the 'application' field in Filebeat itself?

Yes, that's a good idea.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 22, 2018, 10:10am UTC](https://discuss.elastic.co/t/log-stash-configuration-error/116280/7 "2018-02-22T10:10:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
