# Logs are getting parsed multiple times due to ?\[31mA plugin. can some one help me on this issue

**URL:** <https://discuss.elastic.co/t/logs-are-getting-parsed-multiple-times-due-to-31ma-plugin-can-some-one-help-me-on-this-issue/33293>\
**Category:** Logstash\
**Created:** [October 29, 2015, 7:23pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-multiple-times-due-to-31ma-plugin-can-some-one-help-me-on-this-issue/33293 "2015-10-29T19:23:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![sree1](https://avatars.discourse-cdn.com/v4/letter/s/c67d28/32.png) [@sree1](https://discuss.elastic.co/u/sree1)\
**Post date:** [October 29, 2015, 7:23pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-multiple-times-due-to-31ma-plugin-can-some-one-help-me-on-this-issue/33293/1 "2015-10-29T19:23:52Z")

</div>

I am newbie to elk .  
currently,I am working with logstash-2.0.0-beta2 . whenever, I will run my logstash conf file .I am getting following errors.  
1)io/console not supported; tty will not be manipulated  
2)Error: No such file or directory - R:/dev/null.13908.9128.258181 {:level=\>:error}?[0m  
3) ?[31mA plugin had an unrecoverable error. Will restart this plugin.  
my conf file:-  
input {  
file {  
path =\> "C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf"  
start\_position =\> beginning  
sincedb\_path =\> "/dev/null"

}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration}" }  
}  
}

output {  
elasticsearch { hosts =\> "localhost"}  
stdout { codec =\> rubydebug }  
}

my logs:-  
55.3.244.1 GET /index.html 15824 0.043

I am unable to find solution for these errors.please, help me.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 29, 2015, 7:25pm UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-multiple-times-due-to-31ma-plugin-can-some-one-help-me-on-this-issue/33293/2 "2015-10-29T19:25:42Z")

</div>

> 1)io/console not supported; tty will not be manipulated

I believe you can ignore this.

> 2)Error: No such file or directory - R:/dev/null.13908.9128.258181 {:level=\>:error}?[0m

"/dev/null" only works on non-Windows hosts. On Windows perhaps you can use "nul" instead.

---

<div class="post-metadata">

**Author:** ![sree1](https://avatars.discourse-cdn.com/v4/letter/s/c67d28/32.png) [@sree1](https://discuss.elastic.co/u/sree1)\
**Post date:** [October 30, 2015, 7:43am UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-multiple-times-due-to-31ma-plugin-can-some-one-help-me-on-this-issue/33293/3 "2015-10-30T07:43:21Z")

</div>

Thank you Magnusbaeck for your quick response.

I have tried what you have suggested but I am getting the same error and I a using the following versions:

## **Software:**

1)logstash-2.0.0-beta2  
2)elasticsearch-2.0.0-beta2  
3)kibana-4.2.0-beta1

## **my conf file:-**

input {  
file {  
path =\> "C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf"  
start\_position =\> beginning  
sincedb\_path =\> "nul"  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration}" }  
}  
}  
output {  
elasticsearch { hosts =\> "localhost"}  
stdout { codec =\> rubydebug }  
}

## **_My logs:-_**

55.3.244.1 GET /index.html 15824 0.043

## **ERROR:**

**←[32mWorker threads expected: 1, worker threads started: 1 {:level=\>:info}←[0m**  
{  
"message" =\> "55.3.244.1 GET /index.html 15824 0.043\r",  
"@version" =\> "1",  
"@timestamp" =\> "2015-10-30T07:31:53.458Z",  
"host" =\> "Q07500-2K1",  
"path" =\> "C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf",  
"client" =\> "55.3.244.1",  
"method" =\> "GET",  
"request" =\> "/index.html",  
"bytes" =\> "15824",  
"duration" =\> "0.043"  
}  
**←[32mPipeline started {:level=\>:info}←[0m**  
**Logstash startup completed**  
{  
"message" =\> "55.3.244.1 GET /index.html 15824 0.043\r",  
"@version" =\> "1",  
"@timestamp" =\> "2015-10-30T07:31:54.557Z",  
"host" =\> "Q07500-2K1",  
"path" =\> "C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf",  
"client" =\> "55.3.244.1",  
"method" =\> "GET",  
"request" =\> "/index.html",  
"bytes" =\> "15824",  
"duration" =\> "0.043"  
}  
**503587847-325748-2621440 0 2 120**  
**←[31mA plugin had an unrecoverable error. Will restart this plugin.**  
**Plugin: \<LogStash::Inputs::File path=\>["C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf"], start\_position=\>"beginning", sincedb\_path=\>"nul",**  
**Error: No such file or directory - nul.13908.13824.841500 or nul {:level=\>:error}←[0m**  
{  
"message" =\> "55.3.244.1 GET /index.html 15824 0.043\r",  
"@version" =\> "1",  
"@timestamp" =\> "2015-10-30T07:32:01.348Z",  
"host" =\> "Q07500-2K1",  
"path" =\> "C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf",  
"client" =\> "55.3.244.1",  
"method" =\> "GET",  
"request" =\> "/index.html",  
"bytes" =\> "15824",  
"duration" =\> "0.043"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 30, 2015, 7:55am UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-multiple-times-due-to-31ma-plugin-can-some-one-help-me-on-this-issue/33293/4 "2015-10-30T07:55:05Z")

</div>

Okay, well don't set `sincedb_path` then or set it to a known fixed path or your choosing. If your goal indeed is to make Logstash process the file from the top every time you can delete the sincedb file before you run Logstash.

---

<div class="post-metadata">

**Author:** ![sree1](https://avatars.discourse-cdn.com/v4/letter/s/c67d28/32.png) [@sree1](https://discuss.elastic.co/u/sree1)\
**Post date:** [November 2, 2015, 9:14am UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-multiple-times-due-to-31ma-plugin-can-some-one-help-me-on-this-issue/33293/5 "2015-11-02T09:14:53Z")

</div>

Hi Magnusbaeck  
Thank you for your quick response.  
I have worked what you have suggested but it is working by commenting the elasticsearch such as "#elasticsearch {hosts=\>" localhost"}". if I uncomment the elasticsearch line I am getting error like

←[32mWorker threads expected: 1, worker threads started: 1 {:level=\>:info}←[0m  
←[32mAutomatic template management enabled {:manage\_template=\>"true", :level=\>:info}←[0m  
←[32mUsing mapping template {:template=\>{"template"=\>"logstash-_", "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "omit\_norms"=\>true}, "dynamic\_templates"=\>[{"message\_field"=\>{"match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"  
"string", "index"=\>"analyzed", "omit\_norms"=\>true}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"string", "index"=\>"analyzed", "omit\_norms"=\>true, "fields"=\>{"raw"=\>{"type"=\>"string", "index"=\>"not\_analyzed", "ignore\_above"=\>256}}}}}], "properties"=\>{"@ve  
ion"=\>{"type"=\>"string", "index"=\>"not\_analyzed"}, "geoip"=\>{"type"=\>"object", "dynamic"=\>true, "properties"=\>{"location"=\>{"type"=\>"geo\_point"}}}}}}}, :level=\>:info}←[0m  
←[32mNew Elasticsearch output {:hosts=\>["localhost"], :level=\>:info}←[0m  
{  
"message" =\> "55.3.244.1 GET /index.html 15824 0.043\r",  
"@version" =\> "1",  
"@timestamp" =\> "2015-11-02T05:36:54.660Z",  
"host" =\> "Q07500-2K1",  
"path" =\> "C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf",  
"client" =\> "55.3.244.1",  
"method" =\> "GET",  
"request" =\> "/index.html",  
"bytes" =\> "15824",  
"duration" =\> "0.043"  
}  
←[32mPipeline started {:level=\>:info}←[0m  
Logstash startup completed

←[33mFailed action. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-2015.11.02", :\_type=\>"logs", :\_routing=\>nil}, #\<LogStash::Event:0x38b449 @metadata\_accessors=#\<LogStash::Util::Accessors:0x185e95d @store={"path"=\>"C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf",  
retry\_count"=\>0}, @lut={"[path]"=\>[{"path"=\>"C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf", "retry\_count"=\>0}, "path"]}\>, @cancelled=false, @data={"message"=\>"55.3.244.1 GET /index.html 15824 0.043\r", "@version"=\>"1", "@timestamp"=\>"2015-11-02T05:36:54.660Z", "host"=\>"Q07500-2K1  
"path"=\>"C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf", "client"=\>"55.3.244.1", "method"=\>"GET", "request"=\>"/index.html", "bytes"=\>"15824", "duration"=\>"0.043"}, @metadata={"path"=\>"C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf", "retry\_count"=\>0}, @accessors=#  
ogStash::Util::Accessors:0x2a0546 @store={"message"=\>"55.3.244.1 GET /index.html 15824 0.043\r", "path"=\>[{"message"=\>"55.3.244.1 GET /index.html 15824 0.043\r", "@version"=\>"1", "@timestamp"=\>"2015-11-02T05:36:54.660Z", "host"=\>"Q07500-2K1", "path"=\>"C:/basefarm/logstash-2.0.0-beta2/logstash-  
0.0-beta2/g1a.conf", "client"=\>"55.3.244.1", "method"=\>"GET", "request"=\>"/index.html", "bytes"=\>"15824", "duration"=\>"0.043"}, "path"], "message"=\>[{"message"=\>"55.3.244.1 GET /index.html 15824 0.043\r", "@version"=\>"1", "@timestamp"=\>"2015-11-02T05:36:54.660Z", "host"=\>"Q07500-2K1", "path"=\>"C:/  
sefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf", "client"=\>"55.3.244.1", "method"=\>"GET", "request"=\>"/index.html", "bytes"=\>"15824", "duration"=\>"0.043"}, "message"], "client"=\>[{"message"=\>"55.3.244.1 GET /index.html 15824 0.043\r", "@version"=\>"1", "@timestamp"=\>"2015-11-02T05:36:54.  
0Z", "host"=\>"Q07500-2K1", "path"=\>"C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf", "client"=\>"55.3.244.1", "method"=\>"GET", "request"=\>"/index.html", "bytes"=\>"15824", "duration"=\>"0.043"}, "client"], "method"=\>[{"message"=\>"55.3.244.1 GET /index.html 15824 0.043\r", "@version"=\>  
", "@timestamp"=\>"2015-11-02T05:36:54.660Z", "host"=\>"Q07500-2K1", "duration"=\>[{"message"=\>"55.3.244.1 GET /index.html 15824 0.043\r", "@version"=\>"1", "@timestamp"=\>"2015-11-02T05:36:54.660Z", "host"=\>"Q07500-2K1", "path"=\>"C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.conf", "client"=\>"55.3.244.1", "method"=\>"  
T", "request"=\>"/index.html", "bytes"=\>"15824", "duration"=\>"0.043"}, "duration"], "type"=\>[{"message"=\>"55.3.244.1 GET /index.html 15824 0.043\r", "@version"=\>"1", "@timestamp"=\>"2015-11-02T05:36:54.660Z", "host"=\>"Q07500-2K1", "path"=\>"C:/basefarm/logstash-2.0.0-beta2/logstash-2.0.0-beta2/g1a.co  
", "client"=\>"55.3.244.1", "method"=\>"GET", "request"=\>"/index.html", "bytes"=\>"15824", "duration"=\>"0.043"}, "type"]}\>\>], :response=\>{"index"=\>{"\_index"=\>"logstash-2015.11.02", "\_type"=\>"logs", "\_id"=\>nil, "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"mapping [_default_]  
**"caused\_by"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"Mapping definition for [geoip] has unsupported parameters: [path : full]"}}}}, :level=\>:warn}←[0m**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:24am UTC](https://discuss.elastic.co/t/logs-are-getting-parsed-multiple-times-due-to-31ma-plugin-can-some-one-help-me-on-this-issue/33293/6 "2017-07-06T05:24:34Z")

</div>


