# Logstash 5.0 A plugin had an unrecoverable error

**URL:** <https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403>\
**Category:** Logstash\
**Created:** [October 31, 2016, 5:34am UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403 "2016-10-31T05:34:42Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [October 31, 2016, 5:34am UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403/1 "2016-10-31T05:34:42Z")

</div>

I have upgraded my ELK stack to 5.0. All seems running well but I'm not receiving any events to my elastic search from logstash. Following error occurs in logstash-plain.log file,

**[2016-10-31T10:59:30,638][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.**  
**Plugin: \<LogStash::Inputs::Beats port=\>5000, codec=\>\<LogStash::Codecs::Plain charset=\>"ISO-8859-1", id=\>"3c73c6dd66bc469b2a0c9384a730be709186aa24-1", enable\_metric=\>true\>,** **id=\>"3c73c6dd66bc469b2a0c9384a730be709186aa24-2", enable\_metric=\>true, host=\>"0.0.0.0", ssl=\>false, ssl\_verify\_mode=\>"none", include\_codec\_tag=\>true, ssl\_handshake\_timeout=\>10000, congestion\_threshold=\>5, target\_field\_for\_codec=\>"message", tls\_min\_version=\>1, tls\_max\_version=\>1.2, cipher\_suites=\>["TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_GCM\_SHA38",** **"TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384", "TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256", "TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256", "TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_CBC\_SHA384", "TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384", "TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256"], client\_inactivity\_timeout=\>60\>**  
**Error: event executor terminated**

And my logstash.conf file is as follows,

input {  
beats {  
port =\> 5000  
codec =\> plain{  
charset =\> "ISO-8859-1"  
}  
}  
tcp {  
port =\> 5000  
type =\> syslog  
codec =\> plain{  
charset =\> "ISO-8859-1"  
}  
}  
udp {  
port =\> 5000  
type =\> syslog  
codec =\> plain{  
charset =\> "ISO-8859-1"  
}  
}  
}

# First filter

filter {  
#ignore log comments  
if [message] =~ "^#" {  
drop {}  
}

grok {  
patterns\_dir =\> "./patterns"  
match =\> [  
"message", "%{TIMESTAMP\_ISO8601:timestamp} %{IPORHOST:serverip} %{WORD:verb} %{NOTSPACE:request} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:auth} %{IPORHOST:clientip} %{NOTSPACE:agent} %{NOTSPACE:referrer} %{NUMBER:response} %{NUMBER:sub\_response} %{NUMBER:sc\_status} %{NUMBER:responsetime}",  
"message", "%{TIMESTAMP\_ISO8601:timestamp} %{IPORHOST:serverip} %{WORD:verb} %{NOTSPACE:request} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:auth} %{IPORHOST:clientip} %{NOTSPACE:agent} %{NUMBER:response} %{NUMBER:sub\_response} %{NUMBER:sc\_status} %{NUMBER:responsetime}",  
"message", "%{TIMESTAMP\_ISO8601:timestamp} %{IPORHOST:serverip} %{WORD:verb} %{NOTSPACE:request} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:auth} %{IPORHOST:clientip} %{NOTSPACE:agent} %{NUMBER:response} %{NUMBER:sub\_response} %{NUMBER:sc\_status}"  
]  
}  
date {  
match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss"]  
locale =\> "en"  
}  
}

# Second filter

filter {  
if "\_grokparsefailure" in [tags] {

```
} else {
# on success remove the message field to save space
mutate {
  remove_field => ["message", "timestamp"]
}

```

}  
}

output {  
elasticsearch {  
hosts =\> ["172.24.80.86:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

Any idea about the issue??

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 31, 2016, 8:54am UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403/2 "2016-10-31T08:54:51Z")

</div>

I can see a couple of strange things that however does not seem related to the error message. The first is that you have multiple TCP based inputs (beats and tcp) listening to the same port, which will not work. The second one is that you in the output are using `%{[@metadata][beat]}`, which as far as I can tell will only be present in events coning from the beats input. Has this configuration worked in any other Logstash version?

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [October 31, 2016, 9:24am UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403/3 "2016-10-31T09:24:12Z")

</div>

Thankx Chrisrian. Listening the same port was the problem. After removing tcp and udp inputs logstash started to work. however how can I configure different inputs in the logstash config file. I need to collect syslog messages from a network device.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 31, 2016, 9:26am UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403/4 "2016-10-31T09:26:24Z")

</div>

You need to use a different port number that does not clash with one of the other inputs.

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [October 31, 2016, 9:35am UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403/5 "2016-10-31T09:35:15Z")

</div>

something like below?

> [@bopa](#):
>
> tcp {  
> port =\> 5001  
> type =\> syslog  
> codec =\> plain{  
> charset =\> "ISO-8859-1"  
> }  
> }  
> udp {  
> port =\> 5002  
> type =\> syslog  
> codec =\> plain{  
> charset =\> "ISO-8859-1"  
> }

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 31, 2016, 10:53am UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403/6 "2016-10-31T10:53:59Z")

</div>

The tcp and udp inputs do not conflict and can listen to the same port as long as the beats input does use a different port.

---

<div class="post-metadata">

**Author:** ![alabastru](https://avatars.discourse-cdn.com/v4/letter/a/a88e4f/32.png) [@alabastru](https://discuss.elastic.co/u/alabastru)\
**Post date:** [April 12, 2017, 2:05pm UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403/7 "2017-04-12T14:05:52Z")

</div>

I have the same problem - running all version 5.3 - elasticsearch, logstash, beats/filebeat. Worked for 2 days and then error was reported.  
10:05:01.186 [[main]\<beats] ERROR logstash.pipeline - A plugin had an unrecoverable error. Will restart this plugin.  
Plugin: \<LogStash::Inputs::Beats port=\>5044, id=\>"d5aff87894031cac2350a118f8b77e806cc5edda-19", enable\_metric=\>true, c  
odec=\>\<LogStash::Codecs::Plain id=\>"plain\_da1ec986-b8f2-45ff-bf48-b57e6fca0bef", enable\_metric=\>true, charset=\>"UTF-8"\>,  
host=\>"0.0.0.0", ssl=\>false, ssl\_verify\_mode=\>"none", include\_codec\_tag=\>true, ssl\_handshake\_timeout=\>10000, congestion  
_threshold=\>5, target\_field\_for\_codec=\>"message", tls\_min\_version=\>1, tls\_max\_version=\>1.2, cipher\_suites=\>["TLS\_ECDHE\_E  
CDSA\_WITH\_AES\_256\_GCM\_SHA384", "TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384", "TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256", "TLS_  
ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256", "TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_CBC\_SHA384", "TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384",  
"TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256"], client\_inactivity\_timeout=\>60\>  
Error: event executor terminated  
Beats config looks like this:  
input {  
beats {  
port =\> 5044  
#ssl =\> true  
#ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
#ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/logstash-5-0-a-plugin-had-an-unrecoverable-error/64403/8 "2017-07-06T04:27:08Z")

</div>


