# Logstash conf file will not work after filter section is added

**URL:** <https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770>\
**Category:** Logstash\
**Created:** [August 9, 2022, 7:16pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770 "2022-08-09T19:16:03Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lori\_Wallace](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lori_wallace/32/106465_2.png) [@Lori\_Wallace](https://discuss.elastic.co/u/Lori_Wallace)\
**Post date:** [August 9, 2022, 7:16pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770/1 "2022-08-09T19:16:03Z")

</div>

I am trying to ingest logs from a checkpoint firewall. My logstash config file checks out and works as long as I don't have the filter section in it. However, I need the data filtered so can you guys help me figure out what is wrong with this filter. I pulled this from the Checkpoint website.

input {  
tcp {  
port =\> 2812  
codec =\> plain  
type =\> syslog  
}  
}  
filter {  
if [type] == "syslog" {  
kv {  
allow\_duplicate\_values =\> false  
recursive =\> false  
field\_split =\> "|"  
}

```
    mutate {
        # Fields beginning with underscore are not supported by ES/Kibana, so rename them.
         rename => { "__nsons" => "nsons" }
         rename => { "__p_dport" => "p_dport" }
         rename => { "__pos" => "pos" }
         # Not necessary, just a field name preference.
         rename => { "originsicname" => "sicname" }
         # Example of removing specific fields
         # remove_field => ["connection_luuid", "loguid"]
         # String substitution
         # Strip the O\=.*$ and the ^CN= in the field.
         gsub => [
              "sicname", "CN\\=", "",
              "sicname", ",O\\=.*$",""
         ]
    }
}

```

}  
output {  
elasticsearch {  
hosts =\> ["[https://localhost:9200](https://localhost:9200)"]  
cacert =\> "C:\elastic\logstash-8.3.3-windows-x86\_64\logstash-8.3.3\config\certs\http\_ca.crt"  
user =\> logstash\_internal  
password =\> \*\*\*\*\*\*\*\*  
}  
}

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [August 9, 2022, 7:24pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770/2 "2022-08-09T19:24:12Z")

</div>

try

if ( "syslog" in [type]) {

---

<div class="post-metadata">

**Author:** ![Lori\_Wallace](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lori_wallace/32/106465_2.png) [@Lori\_Wallace](https://discuss.elastic.co/u/Lori_Wallace)\
**Post date:** [August 9, 2022, 7:33pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770/3 "2022-08-09T19:33:00Z")

</div>

I still get the same error.  
[2022-08-09T14:30:59,784][ERROR][logstash.config.sourceloader] Could not fetch all the sources {:exception=\>LogStash::ConfigLoadingError, :message=\>"The following config files contains non-ascii characters but are not UTF-8 encoded ["c:/elastic/logstash-8.3.3-windows-x86\_64/logstash-8.3.3/config/logstash2.conf"]", :backtrace=\>["C:/elastic/logstash-8.3.3-windows-x86\_64/logstash-8.3.3/logstash-core/lib/logstash/config/source/local.rb:99:in `read'", "C:/elastic/logstash-8.3.3-windows-x86_64/logstash-8.3.3/logstash-core/lib/logstash/config/source/local.rb:110:in `read'", "C:/elastic/logstash-8.3.3-windows-x86\_64/logstash-8.3.3/logstash-core/lib/logstash/config/source/local.rb:206:in `local_pipeline_configs'", "C:/elastic/logstash-8.3.3-windows-x86_64/logstash-8.3.3/logstash-core/lib/logstash/config/source/local.rb:177:in `pipeline\_configs'", "C:/elastic/logstash-8.3.3-windows-x86\_64/logstash-8.3.3/logstash-core/lib/logstash/config/source\_loader.rb:76:in `block in fetch'", "org/jruby/RubyArray.java:2584:in `collect'", "C:/elastic/logstash-8.3.3-windows-x86\_64/logstash-8.3.3/logstash-core/lib/logstash/config/source\_loader.rb:75:in `fetch'", "C:/elastic/logstash-8.3.3-windows-x86_64/logstash-8.3.3/logstash-core/lib/logstash/runner.rb:389:in `execute'", "C:/elastic/logstash-8.3.3-windows-x86\_64/logstash-8.3.3/vendor/bundle/jruby/2.5.0/gems/clamp-1.0.1/lib/clamp/command.rb:68:in `run'", "C:/elastic/logstash-8.3.3-windows-x86_64/logstash-8.3.3/logstash-core/lib/logstash/runner.rb:283:in `run'", "C:/elastic/logstash-8.3.3-windows-x86\_64/logstash-8.3.3/vendor/bundle/jruby/2.5.0/gems/clamp-1.0.1/lib/clamp/command.rb:133:in `run'", "c:\\elastic\\logstash-8.3.3-windows-x86_64\\logstash-8.3.3\\lib\\bootstrap\\environment.rb:90:in `'"]}  
[2022-08-09T14:30:59,784][FATAL][logstash.runner] The given configuration is invalid. Reason: Could not load the configuration file  
[2022-08-09T14:30:59,800][FATAL][org.logstash.Logstash] Logstash stopped processing because of an error: (SystemExit) exit  
org.jruby.exceptions.SystemExit: (SystemExit) exit  
at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:747) ~[jruby.jar:?]  
at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:710) ~[jruby.jar:?]  
at c\_3a\_.elastic.logstash\_minus\_8\_dot\_3\_dot\_3\_minus\_windows\_minus\_x86\_64.logstash\_minus\_8\_dot\_3\_dot\_3.lib.bootstrap.environment.(c:\elastic\logstash-8.3.3-windows-x86\_64\logstash-8.3.3\lib\bootstrap\environment.rb:91) ~[?:?]

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 9, 2022, 8:26pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770/4 "2022-08-09T20:26:37Z")

</div>

> [@Lori\_Wallace](#):
>
> The following config files contains non-ascii characters but are not UTF-8 encoded ["c:/elastic/logstash-8.3.3-windows-x86\_64/logstash-8.3.3/config/logstash2.conf"]

Without seeing _exactly_ what is in that file (e.g. you upload the filters to a gist or other file sharing site) we cannot say what characters logstash is objecting to.

---

<div class="post-metadata">

**Author:** ![Lori\_Wallace](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lori_wallace/32/106465_2.png) [@Lori\_Wallace](https://discuss.elastic.co/u/Lori_Wallace)\
**Post date:** [August 9, 2022, 8:34pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770/5 "2022-08-09T20:34:16Z")

</div>

logstash2.conf is the config file that I initially pasted into my first post.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 9, 2022, 9:14pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770/6 "2022-08-09T21:14:26Z")

</div>

And as you can see some parts of it have been consumed as formatting, and in any case, non-ASCII characters may have been modified in the posting process.

In Powershell you could

```
Format-Hex -Path "c:/elastic/logstash-8.3.3-windows-x86_64/logstash-8.3.3/config/logstash2.conf"

```

and look for any ? in the rightmost column.

---

<div class="post-metadata">

**Author:** ![Lori\_Wallace](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lori_wallace/32/106465_2.png) [@Lori\_Wallace](https://discuss.elastic.co/u/Lori_Wallace)\
**Post date:** [August 10, 2022, 1:02pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770/7 "2022-08-10T13:02:28Z")

</div>

Ok, I ran the above command against my conf file and didn't find any question marks in the far right column. Very cool tool by the way. I am completely new at all of this and I am trying to get my initial build up and running against the checkpoint logs. Where do I go from here? I figure I will continue to get the following error from logstash if I don't deploy the filter that Checkpoint suggested.

[2022-08-09T10:45:07,789][ERROR][logstash.outputs.elasticsearch][main][83f3e8cc021b50a2ca04775d130dcc4754968715acc993cbd42bbdce83d20b67] Encountered a retryable error (will retry with exponential backoff) {:code=\>403, :url=\>"[https://localhost:9200/\_bulk](https://localhost:9200/_bulk)", :content\_length=\>257005}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 7, 2022, 1:03pm UTC](https://discuss.elastic.co/t/logstash-conf-file-will-not-work-after-filter-section-is-added/311770/8 "2022-09-07T13:03:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
