# \[logstash.agent \] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError",

**URL:** <https://discuss.elastic.co/t/logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror/233802>\
**Category:** Logstash\
**Created:** [May 21, 2020, 7:36pm UTC](https://discuss.elastic.co/t/logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror/233802 "2020-05-21T19:36:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hanneu](https://avatars.discourse-cdn.com/v4/letter/h/7ab992/32.png) [@Hanneu](https://discuss.elastic.co/u/Hanneu)\
**Post date:** [May 21, 2020, 7:36pm UTC](https://discuss.elastic.co/t/logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror/233802/1 "2020-05-21T19:36:43Z")

</div>

Hello experts,  
Getting below error on logstash (LS) logs for all of the nodes.

`[2020-05-21T12:08:42,231][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of #, input, filter, output at line 4016, column 2 (byte 159543) after ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile\_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile\_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile\_sources'", "org/logstash/execution/AbstractPipelineExt.java:149:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:90:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:42:in `block in execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:92:in `block in exclusive'", "org/jruby/ext/thread/Mutex.java:148:in `synchronize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:92:in `exclusive'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:38:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:317:in `block in converge_state'"]}`

Elasticsearch version: 6.5.4  
Logstash version: 6.5.4  
Kibana verison: 6.5.4

LS service has been up and running on all LS nodes. Attached is the logstash.yml, input.conf, output.conf and ruby filter files. Any help is greatly appreciated.

Can't attach the files.  
input.conf looks like below:-  
input {  
beats {  
port =\> "5044"  
client\_inactivity\_timeout =\> "600"  
}  
}

Output.conf

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 22, 2020, 12:28pm UTC](https://discuss.elastic.co/t/logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror/233802/2 "2020-05-22T12:28:43Z")

</div>

> [@Hanneu](#):
>
> Expected one of #, input, filter, output at line 4016, column 2 (byte 159543) after ", :backtrace=\>

one of your config files is having syntax issues. looks like you put a whole bunch of .conf files in a same directory making logstash sees the error at line 4016

---

<div class="post-metadata">

**Author:** ![Hanneu](https://avatars.discourse-cdn.com/v4/letter/h/7ab992/32.png) [@Hanneu](https://discuss.elastic.co/u/Hanneu)\
**Post date:** [May 22, 2020, 3:54pm UTC](https://discuss.elastic.co/t/logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror/233802/3 "2020-05-22T15:54:30Z")

</div>

Hello Ptamba,  
Yes indeed there are lot of .conf files under /etc/logstash/conf.d. Could you please recommend IF these .conf files need to be moved to a different directory?  
[root@polelk04 logstash]# cd /etc/logstash/conf.d/  
[root@polelk04 conf.d]# ls -ltr  
total 212  
-rw-r--r--. 1 root root 2574 Jun 22 2018 eccgw\_filter.conf  
-rw-r--r--. 1 root root 368 Jun 22 2018 accesslog.conf  
-rw-r--r--. 1 root root 594 Jun 22 2018 tpcdb\_error.conf  
-rw-r--r--. 1 root root 4667 Oct 5 2018 epe\_tpc\_filter.conf  
-rw-r--r--. 1 root root 11524 Oct 8 2018 filter\_OCC\_MSG.conf  
-rw-r--r--. 1 root root 12510 Oct 15 2018 filter\_OCC\_MSG\_ts.conf  
-rw-r--r--. 1 root root 11772 Oct 15 2018 filter\_OCC\_DM\_ts.conf  
-rw-r--r--. 1 root root 5162 Oct 24 2018 filter\_CCN.conf  
-rw-r--r--. 1 root root 1766 Oct 24 2018 filter\_SDP.conf  
-rw-r--r--. 1 root root 7058 Oct 24 2018 filter\_CCN\_ts.conf  
-rw-r--r--. 1 root root 15088 Oct 24 2018 filter\_SDP\_ts.conf  
-rw-r--r--. 1 root root 20713 Oct 24 2018 filter\_AIR\_ts.conf  
drwxr-xr-x. 3 root root 4096 Nov 27 2018 bkup  
-rw-r--r--. 1 root root 49992 Nov 27 2018 filter\_AIR.conf  
-rw-r--r--. 1 root root 2119 Dec 17 2018 filter\_cc.conf  
drwxr-xr-x. 2 root root 100 Jul 25 2019 certs  
-rw-r--r--. 1 root root 9156 Sep 12 2019 filter\_OCC\_dm.conf  
-rw-r--r--. 1 root root 4869 May 21 11:11 output.conf  
-rw-r--r--. 1 root root 498 May 21 14:52 output\_cc.conf  
-rw-r--r--. 1 root root 471 May 21 14:58 output\_elk.conf  
-rw-r--r--. 1 root root 95 May 22 08:49 input.conf

Any help is greatly appreciated.

---

<div class="post-metadata">

**Author:** ![Hanneu](https://avatars.discourse-cdn.com/v4/letter/h/7ab992/32.png) [@Hanneu](https://discuss.elastic.co/u/Hanneu)\
**Post date:** [May 26, 2020, 7:38pm UTC](https://discuss.elastic.co/t/logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror/233802/4 "2020-05-26T19:38:43Z")

</div>

Hello experts,  
Any inputs or suggested workaround on this issue?

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 27, 2020, 2:37am UTC](https://discuss.elastic.co/t/logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror/233802/5 "2020-05-27T02:37:37Z")

</div>

you could try running logstash from CLI with config test and increase the log level to debug or trace

`logstash -f <path_to_config_di> --config.test_and_exit --log.level trace`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2020, 2:37am UTC](https://discuss.elastic.co/t/logstash-agent-failed-to-execute-action-action-logstash-create-pipeline-id-main-exception-logstash-configurationerror/233802/6 "2020-06-24T02:37:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
