# Logstash config file execution error?

**URL:** <https://discuss.elastic.co/t/logstash-config-file-execution-error/70869>\
**Category:** Logstash\
**Created:** [January 8, 2017, 9:14am UTC](https://discuss.elastic.co/t/logstash-config-file-execution-error/70869 "2017-01-08T09:14:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [January 8, 2017, 9:14am UTC](https://discuss.elastic.co/t/logstash-config-file-execution-error/70869/1 "2017-01-08T09:14:02Z")

</div>

Hi,  
I have one config file which is used to analyse the slowlogs and keep it in file.The code for that is

input {  
file {  
path =\> "C:\Users\571952\Downloads\elasticsearch-5.1.1\elasticsearch-5.1.1\logs\elasticsearch\_index\_search\_slowlog"  
start\_position =\> "beginning"  
}  
}

filter {  
grok { # parses the common bits  
match =\> ["message", "[%{URIHOST}:%{ISO8601\_SECOND}][%{LOGLEVEL:log\_level}]  
[%{DATA:es\_slowquery\_type}]\s\*[%{DATA:es\_host}]\s\*[%{DATA:es\_index}]\s\*[%{DATA:es\_shard}]\s_took[%{DATA:es\_duration}],\s_took\_millis[%{DATA:es\_duration\_ms:float}],\s_types[%{DATA:es\_types}],\s_stats[%{DATA:es\_stats}],\s_search\_type[%{DATA:es\_search\_type}],\s_total\_shards[%{DATA:es\_total\_shards:float}],\s_source[%{GREEDYDATA:es\_source}],\s_extra\_source[%{GREEDYDATA:es\_extra\_source}]"]  
}

mutate {  
gsub =\> [  
"source\_body", "], extra\_source[$", ""  
]  
}  
}

output {  
file {  
path =\> "C:\Users\571952\Desktop\logstash-5.1.1\just\_queries"  
codec =\> "json\_lines"

}  
}

when i tried executing it in my cmd prompt it is showing error like this

[2017-01-04T18:30:32,032][ERROR][logstash.agent] Pipeline aborted due to error  
{:exception=\>#\<RegexpError: premature end of char-class: /], extra\_source[$/\>, :backtrac  
e=\>["org/jruby/RubyRegexp.java:1424:in `initialize'", "C:/Users/571952/Desktop/logstash-5 .1.1/vendor/bundle/jruby/1.9/gems/logstash-filter-mutate-3.1.3/lib/logstash/filters/mutat e.rb:196:in`register'", "org/jruby/RubyArray.java:1653:in `each_slice'", "C:/Users/57195 2/Desktop/logstash-5.1.1/vendor/bundle/jruby/1.9/gems/logstash-filter-mutate-3.1.3/lib/lo gstash/filters/mutate.rb:184:in`register'", "C:/Users/571952/Desktop/logstash-5.1.1/logs  
tash-core/lib/logstash/pipeline.rb:230:in `start_workers'", "org/jruby/RubyArray.java:161 3:in`each'", "C:/Users/571952/Desktop/logstash-5.1.1/logstash-core/lib/logstash/pipeline  
.rb:230:in `start_workers'", "C:/Users/571952/Desktop/logstash-5.1.1/logstash-core/lib/lo gstash/pipeline.rb:183:in`run'", "C:/Users/571952/Desktop/logstash-5.1.1/logstash-core/l  
ib/logstash/agent.rb:292:in `start\_pipeline'"]}  
[2017-01-04T18:30:32,141][INFO][logstash.agent] Successfully started Logstash  
API endpoint {:port=\>9600}  
[2017-01-04T18:30:35,036][WARN][logstash.agent] stopping pipeline {:id=\>"main  
"}

My slowlog content is like this:

[2016-12-28T15:53:21,341][DEBUG][index.search.slowlog.query] [vVhZxH7] [sw][0] took[184.7micros], took\_millis[0], types[], stats[], search\_type[QUERY\_THEN\_FETCH], total\_shards[5], source[{  
"ext" : { }  
}],

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2017, 6:38am UTC](https://discuss.elastic.co/t/logstash-config-file-execution-error/70869/2 "2017-01-09T06:38:32Z")

</div>

Since you didn't post your configuration or the logs as preformatted text some parts might've disappeared, but I suspect the problem is that you need to escape the square brackets in the gsub regexp. Square brackets have a special meaning in regexps and if you want literal matches you need to escape the brackets.

---

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [January 9, 2017, 7:12am UTC](https://discuss.elastic.co/t/logstash-config-file-execution-error/70869/3 "2017-01-09T07:12:30Z")

</div>

Hi,  
Sry.. i cant able to get your point like "escape the square brackets in gsub regexp". Can you explain in brief?  
Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 9, 2017, 8:09am UTC](https://discuss.elastic.co/t/logstash-config-file-execution-error/70869/4 "2017-01-09T08:09:13Z")

</div>

Change

```nohighlight
mutate {
  gsub => [
    "source_body", "], extra_source[$", ""
  ]
}

```

to

```nohighlight
mutate {
  gsub => [
    "source_body", "\], extra_source\[$", ""
  ]
}

```

Perhaps the dollar sign should be escaped too? I don't know what your data looks like so I can't tell.

---

<div class="post-metadata">

**Author:** ![Yaswanth](https://avatars.discourse-cdn.com/v4/letter/y/94ad74/32.png) [@Yaswanth](https://discuss.elastic.co/u/Yaswanth)\
**Post date:** [January 9, 2017, 9:10am UTC](https://discuss.elastic.co/t/logstash-config-file-execution-error/70869/5 "2017-01-09T09:10:10Z")

</div>

Thanks,that change which you had mentioned is worked fine. But i cant able to see just\_queries in my output folder.It seems my logstash is started successfully but nothing happened ..

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a99868d6d1296f10570294d0a809a1b8826e9b17.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 6, 2017, 9:10am UTC](https://discuss.elastic.co/t/logstash-config-file-execution-error/70869/6 "2017-02-06T09:10:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
