# Logstash config error reason=\>"Expected one of #, \\", ', }

**URL:** <https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594>\
**Category:** Logstash\
**Created:** [July 15, 2016, 7:25am UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594 "2016-07-15T07:25:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Saurabh\_Jambhule](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Post date:** [July 15, 2016, 7:25am UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/1 "2016-07-15T07:25:40Z")

</div>

Why this error is coming...  
input {  
file {  
path =\> ["Documents/apache-sample-dataset.log"]  
type =\> "apache"  
start\_position =\> "beginning"  
}  
}

filter {  
if [type] == "apache" {  
grok {  
match =\> ["message", "%{COMBINEDAPACHELOG}"]  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "Documents/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float" ]  
}  
}

output {  
elasticsearch {  
host =\> localhost  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 15, 2016, 7:29am UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/2 "2016-07-15T07:29:59Z")

</div>

What line is it reporting on?

---

<div class="post-metadata">

**Author:** ![Saurabh\_Jambhule](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Post date:** [July 15, 2016, 7:34am UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/3 "2016-07-15T07:34:27Z")

</div>

at line 3, column 1 (byte 20) after input \t{\n \tfile\t{\n

---

<div class="post-metadata">

**Author:** ![cb2015](https://avatars.discourse-cdn.com/v4/letter/c/7993a0/32.png) [@cb2015](https://discuss.elastic.co/u/cb2015)\
**Post date:** [July 15, 2016, 6:48pm UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/4 "2016-07-15T18:48:39Z")

</div>

I can't see the root of your problem, but one thing that has helped me immensely in troubleshooting a config file is to comment out everything but the first step, and then "build" the config back up from there, doing the --configtest thing every step. So you could start with  
input {  
file {  
path =\> ["Documents/apache-sample-dataset.log"]  
type =\> "apache"  
start\_position =\> "beginning"  
}  
}

#filter {  
#if [type] == "apache" {  
#grok {  
#match =\> ["message", "%{COMBINEDAPACHELOG}"]  
#}  
#}  
#date {  
#match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
#}  
#geoip {  
#source =\> "clientip"  
#target =\> "geoip"  
#database =\> "Documents/GeoLiteCity.dat"  
#add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
#add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
#}  
#mutate {  
#convert =\> ["[geoip][coordinates]", "float" ]  
#}  
#}

#output {  
#elasticsearch {  
#host =\> localhost  
#}  
#}

and add on from there

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [July 16, 2016, 2:56pm UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/5 "2016-07-16T14:56:15Z")

</div>

> [@Saurabh\_Jambhule](#):
>
> path =\> ["Documents/apache-sample-dataset.log"]

You need to use a full path for this file, I think. Windows or Linux?

---

<div class="post-metadata">

**Author:** ![Saurabh\_Jambhule](https://avatars.discourse-cdn.com/v4/letter/s/c0e974/32.png) [@Saurabh\_Jambhule](https://discuss.elastic.co/u/Saurabh_Jambhule)\
**Post date:** [July 24, 2016, 7:09pm UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/6 "2016-07-24T19:09:50Z")

</div>

Thank you. It is now working.

---

<div class="post-metadata">

**Author:** ![manopmk](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@manopmk](https://discuss.elastic.co/u/manopmk)\
**Post date:** [March 21, 2017, 1:53pm UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/7 "2017-03-21T13:53:07Z")

</div>

Im Using mac im unable to configure apache log.  
im getting error  
**" Error: Expected one of #, ", ', -, [, {,] at line 4, column 14 (byte 33) after input { file { path =\> [**

i tried  
path =\> "/Users/tcstsb3/Downloads/log/access\_log.log"

path =\> ["/user....../apache.log"]

path =\> ["user....../apache.log"]

same error only im getting,

ANY ONE PLZ HELP ME

input {

file {   
path =\> [“/Users/tcstsb3/Downloads/log/access\_log”]  
type =\> "apache"  
}

}

filter {

```
grok {
  match => { “message” => “%{COMBINEDAPACHELOG}” }
}

```

}

output {  
elasticsearch {  
hosts =\> [“10.145.40.24:9200”]  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 21, 2017, 8:20pm UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/9 "2017-03-21T20:20:17Z")

</div>

Please start your own thread.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/logstash-config-error-reason-expected-one-of/55594/10 "2017-07-06T04:27:41Z")

</div>


