# Logstash 1.5 dies with SyntaxError: (eval):9841: syntax error, unexpected tRBRACK

**URL:** <https://discuss.elastic.co/t/logstash-1-5-dies-with-syntaxerror-eval-9841-syntax-error-unexpected-trbrack/1850>\
**Category:** Logstash\
**Created:** [June 3, 2015, 3:32pm UTC](https://discuss.elastic.co/t/logstash-1-5-dies-with-syntaxerror-eval-9841-syntax-error-unexpected-trbrack/1850 "2015-06-03T15:32:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Suny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suny/32/22082_2.png) [@Suny](https://discuss.elastic.co/u/Suny)\
**Post date:** [June 3, 2015, 3:32pm UTC](https://discuss.elastic.co/t/logstash-1-5-dies-with-syntaxerror-eval-9841-syntax-error-unexpected-trbrack/1850/1 "2015-06-03T15:32:04Z")

</div>

Hi. We are switching to logstash 1.5.0-1 to be able to use Shield. But the --configtest throws  
SyntaxError: (eval):9841: syntax error, unexpected tRBRACK  
[exception][class] == "javax.servlet.ServletException"  
^  
eval at org/jruby/RubyKernel.java:1107  
initialize at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.0-java/lib/logstash/pipeline.rb:30  
execute at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.0-java/lib/logstash/agent.rb:109  
run at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.0-java/lib/logstash/runner.rb:87  
call at org/jruby/RubyProc.java:271  
run at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.0-java/lib/logstash/runner.rb:92  
call at org/jruby/RubyProc.java:271  
initialize at /opt/logstash/vendor/bundle/jruby/1.9/gems/stud-0.0.19/lib/stud/task.rb:12

(The lostash service dies with the same message in \*.err).

The config line that kills it is the second line of

```
    if [exception][message] == "Error while checking if webfilter is cookie session trackable" and
       [exception][class] == "javax.servlet.ServletException" {
        mutate {
            add_field => { "issue" => 103893 }
        }
    }

```

The config worked with logstash 1.4.2.  
If you prefer, I'll raise an github issue.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 3, 2015, 5:25pm UTC](https://discuss.elastic.co/t/logstash-1-5-dies-with-syntaxerror-eval-9841-syntax-error-unexpected-trbrack/1850/2 "2015-06-03T17:25:06Z")

</div>

This is a known bug that was fixed two weeks ago and should end up in 1.5.1.

> <https://github.com/elastic/logstash/pull/3281>

---

<div class="post-metadata">

**Author:** ![Suny](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/suny/32/22082_2.png) [@Suny](https://discuss.elastic.co/u/Suny)\
**Post date:** [June 5, 2015, 8:37am UTC](https://discuss.elastic.co/t/logstash-1-5-dies-with-syntaxerror-eval-9841-syntax-error-unexpected-trbrack/1850/3 "2015-06-05T08:37:35Z")

</div>

Thanks, it's good to know that it will work with the old configuration again, and until then joining the two lines fixes it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:38am UTC](https://discuss.elastic.co/t/logstash-1-5-dies-with-syntaxerror-eval-9841-syntax-error-unexpected-trbrack/1850/4 "2017-07-06T05:38:26Z")

</div>


