# Logstash 6.7.0 on Raspberry Pi 3 B+ - java.lang.IllegalStateException

**URL:** <https://discuss.elastic.co/t/logstash-6-7-0-on-raspberry-pi-3-b-java-lang-illegalstateexception/174588>\
**Category:** Logstash\
**Created:** [March 29, 2019, 5:53pm UTC](https://discuss.elastic.co/t/logstash-6-7-0-on-raspberry-pi-3-b-java-lang-illegalstateexception/174588 "2019-03-29T17:53:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![James\_DeHaan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/james_dehaan/32/41868_2.png) [@James\_DeHaan](https://discuss.elastic.co/u/James_DeHaan)\
**Post date:** [March 29, 2019, 5:53pm UTC](https://discuss.elastic.co/t/logstash-6-7-0-on-raspberry-pi-3-b-java-lang-illegalstateexception/174588/1 "2019-03-29T17:53:38Z")

</div>

Howdy All

Quick background, I had tried to get this going:

https:// [github.com/TravisFSmith/SweetSecurity](http://github.com/TravisFSmith/SweetSecurity)

but removed LS 5.5.X completely and installed LS 6.7.0 via dpkg/logstash-6.7.0.deb

- Version:  
logstash-6.7.0

- Operating System:  
Linux raspberrypi 4.14.98-v7+ #1200 SMP Tue Feb 12 20:27:48 GMT 2019 armv7l GNU/Linu

- Config File (if you have sensitive info, please remove it):

root@raspberrypi:~# cat /etc/logstash/conf.d/logstash7.conf  
input {  
file {  
path =\> ["/var/log/suricata/\*.json"]  
sincedb\_path =\> ["/var/cache/logstash/sincedbs/since.db"]  
codec =\> json  
type =\> "SELKS"  
}

}

filter {  
if [type] == "SELKS" {  
date {  
match =\> ["timestamp", "ISO8601"]  
}  
ruby {  
code =\> "  
if event.get('[event\_type]') == 'fileinfo'  
event.set('[fileinfo][type]', event.get('[fileinfo][magic]').to\_s.split(',')[0])  
end  
"  
}  
ruby {  
code =\> "  
if event.get('[event\_type]') == 'alert'  
sp = event.get('[alert][signature]').to\_s.split(' group ')  
if (sp.length == 2) and /\A\d+\z/.match(sp[1])  
event.set('[alert][signature]', sp[0])  
end  
end  
"  
}  
metrics {  
meter =\> ["eve\_insert"]  
add\_tag =\> "metric"  
flush\_interval =\> 30  
}  
}

if [http] {  
useragent {  
source =\> "[http][http\_user\_agent]"  
target =\> "[http][user\_agent]"  
}  
}  
if [src\_ip] {  
geoip {  
source =\> "src\_ip"  
target =\> "geoip"  
#database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
if ![geoip.ip] {  
if [dest\_ip] {  
geoip {  
source =\> "dest\_ip"  
target =\> "geoip"  
#database =\> "/opt/logstash/vendor/geoip/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
}  
}  
}  
}

output {  
if [event\_type] and [event\_type] != 'stats' {  
elasticsearch {  
hosts =\> [MYAWS:443]  
index =\> "logstash-%{event\_type}-%{+YYYY.MM.dd}"  
template =\> "/etc/logstash/elasticsearch5-template.json"  
}  
} else {  
elasticsearch {  
hosts =\> [MYAWS:443]  
index =\> "logstash-%{+YYYY.MM.dd}"  
template =\> "/etc/logstash/elasticsearch5-template.json"  
}  
}  
}

- Sample Data:

{"timestamp":"2019-03-29T15:24:10.001031+0000","flow\_id":1398236122980813,"event\_type":"flow","src\_ip":"2.2.2.2","src\_port":54589,"dest\_ip":"1.1.1.1","dest\_port":53,"proto":"UDP","app\_proto":"dns","flow":{"pkts\_toserver":2,"pkts\_toclient":1,"bytes\_toserver":332,"bytes\_toclient":226,"start":"2019-03-29T15:19:08.664013+0000","end":"2019-03-29T15:19:08.719484+0000","age":0,"state":"established","reason":"timeout","alerted":false}}

{"timestamp":"2019-03-29T15:24:12.068563+0000","flow\_id":1597537657818067,"in\_iface":"eth1","event\_type":"dns","src\_ip":"2.2.2.2","src\_port":37639,"dest\_ip":"1.1.1.1","dest\_port":53,"proto":"UDP","dns":{"type":"query","id":1234,"rrname":"[a.root-servers.net](http://a.root-servers.net)","rrtype":"A","tx\_id":0}}

{"timestamp":"2019-03-29T15:24:12.081101+0000","flow\_id":1597537657818067,"in\_iface":"eth1","event\_type":"dns","src\_ip":"2.2.2.2","src\_port":53,"dest\_ip":"1.1.1.1","dest\_port":37639,"proto":"UDP","dns":{"type":"answer","id":1234,"rcode":"NOERROR","rrname":"[a.root-servers.net](http://a.root-servers.net)","rrtype":"A","ttl":59493,"rdata":"198.41.0.4"}}

- Steps to Reproduce:

IIRC it's important to have libjffi-1.2.so installed. I believe that's all fine.

I am not sure where the error is coming from - did I botch something or other?

I believe there's enough RAM/swap. I watched free mem go down but not fully consumed and released on the final error out.

Thanks in advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2019, 5:53pm UTC](https://discuss.elastic.co/t/logstash-6-7-0-on-raspberry-pi-3-b-java-lang-illegalstateexception/174588/2 "2019-04-26T17:53:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
