# Logstash Config File Error2

**URL:** <https://discuss.elastic.co/t/logstash-config-file-error2/170528>\
**Category:** Logstash\
**Created:** [March 1, 2019, 3:50pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528 "2019-03-01T15:50:59Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![brandonstephens922](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@brandonstephens922](https://discuss.elastic.co/u/brandonstephens922)\
**Post date:** [March 1, 2019, 3:51pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/1 "2019-03-01T15:51:00Z")

</div>

Can someone please review this file for errors? I have been over it and over it and I keep getting this error:  
[2019-03-01T14:46:07,935][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, =\> at line 3076, column 20 (byte 99857) after filter {\n if [syslog-host\_from] =~ "fireeye-nx" {\n json {\n source =\> "message"\n \n mutate ",

I have removed every mutate statement down to the last one and I still get the same error. Here is the original file. Does anyone see an issue?

filter {  
if [syslog-host\_from] =~ "fireeye-nx" {  
json {  
source =\> "message"

```
        mutate {
           remove_field => ["version", "appliance-id", "msg", "product", "occurred", "vlan", "class", "name", "interface", "ack"]
        }
        mutate {
           rename => { "appliance" => "server_name" }
           rename => ["[alert][dst][ip]", "destination_ip" ]
           rename => ["[alert][dst][port]", "destination_port" ]
           rename => ["[alert][dst][mac]", "destination_mac" ]
           rename => { "alert-url" => "signature_info" }
           rename => { "name" => "rule_type" }
           #action
           rename => ["[action][id]", "sid" ]
           rename => ["[action][severity]", "priority" ]
           rename => ["[action][uuid]", "uid" ]
           rename => ["[src][ip]", "source_ip" ]
           rename => ["[src][port]", "source_port" ]
           rename => ["[src][mac]", "source_mac" ]
           rename => ["[explanation][ips-detected][cve-id]", "cve" ]
           rename => ["[explanation][ips-detected][match-count]", "match-count" ]
           rename => ["[explanation][ips-detected][attack-mode]", "attack-mode" ]
           rename => ["[explanation][ips-detected][action-taken]", "action" ]
           rename => ["[explanation][ips-detected][sig-id]", "sid" ]
           rename => ["[explanation][ips-detected][mvx-status]", "mvx-status" ]
           rename => ["[explanation][ips-detected][sig-revision]", "rev" ]
           rename => ["[explanation][ips-detected][sig-name]", "alert" ]
         }
		 
		 mutate {
           replace => { "type" => "fireeye" }
  }         
 }
}

```

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 3:54pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/2 "2019-03-01T15:54:42Z")

</div>

You have a mutate filter nested inside a json filter. You need to add a } to close the json filter before the mutate filter.

---

<div class="post-metadata">

**Author:** ![brandonstephens922](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@brandonstephens922](https://discuss.elastic.co/u/brandonstephens922)\
**Post date:** [March 1, 2019, 3:55pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/3 "2019-03-01T15:55:52Z")

</div>

I actually added that change after a previous error. I will revert that change and post new error. Thank you for the quick response.

---

<div class="post-metadata">

**Author:** ![brandonstephens922](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@brandonstephens922](https://discuss.elastic.co/u/brandonstephens922)\
**Post date:** [March 1, 2019, 4:01pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/4 "2019-03-01T16:01:09Z")

</div>

New File:

filter {  
if [syslog-host\_from] =~ "fireeye-nx" {  
json {  
source =\> "message"  
}  
mutate {  
remove\_field =\> ["version", "appliance-id", "msg", "product", "occurred", "vlan", "class", "name", "interface", "ack"]  
}  
mutate {  
rename =\> { "appliance" =\> "server\_name" }  
rename =\> ["[alert][dst][ip]", "destination\_ip" ]  
rename =\> ["[alert][dst][port]", "destination\_port" ]  
rename =\> ["[alert][dst][mac]", "destination\_mac" ]  
rename =\> { "alert-url" =\> "signature\_info" }  
rename =\> { "name" =\> "rule\_type" }  
#action  
rename =\> ["[action][id]", "sid" ]  
rename =\> ["[action][severity]", "priority" ]  
rename =\> ["[action][uuid]", "uid" ]  
rename =\> ["[src][ip]", "source\_ip" ]  
rename =\> ["[src][port]", "source\_port" ]  
rename =\> ["[src][mac]", "source\_mac" ]  
rename =\> ["[explanation][ips-detected][cve-id]", "cve" ]  
rename =\> ["[explanation][ips-detected][match-count]", "match-count" ]  
rename =\> ["[explanation][ips-detected][attack-mode]", "attack-mode" ]  
rename =\> ["[explanation][ips-detected][action-taken]", "action" ]  
rename =\> ["[explanation][ips-detected][sig-id]", "sid" ]  
rename =\> ["[explanation][ips-detected][mvx-status]", "mvx-status" ]  
rename =\> ["[explanation][ips-detected][sig-revision]", "rev" ]  
rename =\> ["[explanation][ips-detected][sig-name]", "alert" ]  
}

```
         mutate {
           replace => { "type" => "fireeye" }
  }
 }
}

```

* * *

Error:  
[2019-03-01T15:58:56,463][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"TypeError", :message=\>"no implicit conversion of Array into Hash",

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 4:12pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/5 "2019-03-01T16:12:35Z")

</div>

> [@brandonstephens922](#):
>
> mutate {  
> rename =\> { "appliance" =\> "server\_name" }  
> rename =\> ["[alert][dst][ip]", "destination\_ip" ]

The first rename is OK, rename expects a hash. The second is not, since it contains an array.

---

<div class="post-metadata">

**Author:** ![brandonstephens922](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@brandonstephens922](https://discuss.elastic.co/u/brandonstephens922)\
**Post date:** [March 1, 2019, 4:15pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/6 "2019-03-01T16:15:30Z")

</div>

How would I go about fixing this? Would I need a separate mutate statement for arrays?

---

<div class="post-metadata">

**Author:** ![brandonstephens922](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@brandonstephens922](https://discuss.elastic.co/u/brandonstephens922)\
**Post date:** [March 1, 2019, 4:31pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/7 "2019-03-01T16:31:54Z")

</div>

To provide context the fields are nested in the log:

[alert][dst][ip] is actually

alert:  
dst:  
ip  
port  
mac

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 4:40pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/8 "2019-03-01T16:40:25Z")

</div>

> [@Badger](#):
>
> rename =\> ["[alert][dst][ip]", "destination\_ip" ]

That should be

```
 rename => { "[alert][dst][ip]" => "destination_ip" }

```

---

<div class="post-metadata">

**Author:** ![brandonstephens922](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@brandonstephens922](https://discuss.elastic.co/u/brandonstephens922)\
**Post date:** [March 1, 2019, 6:11pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/9 "2019-03-01T18:11:51Z")

</div>

OK, so that definitely fixed the config file. New issue though, the logs are not showing up in Kibana anymore and when they are ingested Logstash is throwing the following alert:

[2019-03-01T18:04:46,124][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"logstash-syslog-2019.03.01", :\_type=\>"doc", :routing=\>nil}, #LogStash::Event:0x64390edd], :response=\>{"index"=\>{"\_index"=\>"logstash-syslog-2019.03.01", "\_type"=\>"doc", "\_id"=\>"dtBuOmkBH9aLgbCWEjuq", "status"=\>400, "error"=\>{"type"=\>"mapper\_parsing\_exception", "reason"=\>"failed to parse field [alert] of type [text]", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"=\>"Can't get text on a START\_OBJECT at 1:174"}}}}}

My guess is that the "alert" field that it mentions is coming back blank as this is the parent field of many nested fields. See log below:  
{  
"alert": {  
"ack": "no",  
"action": "blocked",  
"alert-url": "[https://hexxxxx-cms-ssh.hex01.helix.apps.xxxxxx.xxx/event\_stream/events\_for\_bot?ev\_id=1450064&lms\_iden=0025905E4418](https://hexxxxx-cms-ssh.hex01.helix.apps.xxxxxx.xxx/event_stream/events_for_bot?ev_id=1450064&lms_iden=0025905E4418)",  
"dst": {  
"ip": "x.x.x.x"  
},  
"explanation": {  
"malware-detected": {  
"malware": {  
"name": "Phish.URL"  
}  
}  
},  
"id": "1450064",  
"name": "infection-match",  
"occurred": "2019-03-01T17:49:09Z",  
"severity": "minr",  
"src": {  
"host": "xxxxxxx",  
"ip": "x.x.x.x",  
"vlan": "0"  
},  
"uuid": "95486f3b-f231-4bd1-xxxx-173bxxxxxx19"  
},  
"appliance": "xxxxxxx",  
"appliance-id": "xxxxxxx",  
"msg": "concise",  
"product": "xxxxxxx",  
"version": "xxxxxxxx"  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 6:20pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/10 "2019-03-01T18:20:15Z")

</div>

Is the error message in the elasticsearch log file more informative?

---

<div class="post-metadata">

**Author:** ![brandonstephens922](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@brandonstephens922](https://discuss.elastic.co/u/brandonstephens922)\
**Post date:** [March 1, 2019, 6:40pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/11 "2019-03-01T18:40:43Z")

</div>

Im afraid elastic doesn't generate a log for this event at all.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 7:39pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/12 "2019-03-01T19:39:59Z")

</div>

> [@brandonstephens922](#):
>
> "failed to parse field [alert] of type [text]"

So elasticsearch expects alert to be a text field, not a structured object. It has to be one or the other. What does alert look like on the records already in elasticsearch?

---

<div class="post-metadata">

**Author:** ![brandonstephens922](https://avatars.discourse-cdn.com/v4/letter/b/a4c791/32.png) [@brandonstephens922](https://discuss.elastic.co/u/brandonstephens922)\
**Post date:** [March 1, 2019, 7:48pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/13 "2019-03-01T19:48:08Z")

</div>

It is starting to look more and more like this log source needs a dedicated template. I was trying to avoid that by renaming fields to match the existing template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2019, 7:48pm UTC](https://discuss.elastic.co/t/logstash-config-file-error2/170528/14 "2019-03-29T19:48:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
