# Logstash configuration - comment breaks the logstash configuration

**URL:** <https://discuss.elastic.co/t/logstash-configuration-comment-breaks-the-logstash-configuration/180802>\
**Category:** Logstash\
**Created:** [May 13, 2019, 11:55am UTC](https://discuss.elastic.co/t/logstash-configuration-comment-breaks-the-logstash-configuration/180802 "2019-05-13T11:55:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [May 13, 2019, 11:55am UTC](https://discuss.elastic.co/t/logstash-configuration-comment-breaks-the-logstash-configuration/180802/1 "2019-05-13T11:55:33Z")

</div>

Hello.

I am running Logstash 6.7.0

My config is:

> input { stdin { } }  
> filter {  
> json { source =\> "message" }  
> if [Severity] == "INFO" {  
> #comment line 5  
> mutate {  
> add\_field =\> {  
> "@timestamp" =\> "%{timestamp}" #comment line 8  
> "[event][logsource][host]" =\> "%{myfield}" #comment line 9  
> }  
> }  
> }  
> }  
> output {  
> stdout { codec =\> rubydebug }  
> }

I get following error:  
`ERROR] 2019-05-13 13:54:41.785 [Converge PipelineAction::Create<main>] agent - Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of #, {, } at line 9, column 4 (byte 185) after filter {\n json { source => \"message\" }\n if [Severity] == \"INFO\" {\n#comment line 5\n mutate {\n add_field => {\n \"@timestamp\" => \"%{timestamp}\" #comment line 8\n ", :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile\_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile\_sources'", "org/jruby/RubyArray.java:2577:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile\_sources'", "org/logstash/execution/AbstractPipelineExt.java:151:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:90:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:43:in `block in execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:96:in `block in exclusive'", "org/jruby/ext/thread/Mutex.java:165:in `synchronize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:96:in `exclusive'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:39:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:334:in `block in converge_state'"]}`

Is there a way around it to slam comments into mutate section when I am using following data structure [Y][Z] ?

Seems that I am hitting some strange exception.  
Any ideas?  
Regards

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2019, 1:35pm UTC](https://discuss.elastic.co/t/logstash-configuration-comment-breaks-the-logstash-configuration/180802/2 "2019-05-13T13:35:24Z")

</div>

> [@pastechecker](#):
>
> Seems that I am hitting some strange exception.

Indeed. It doesn't mind a comment at the end of the hash,

```
        add_field => {
            "@timestamp" => "%{timestamp}"
            "[event][logsource][host]" => "%{myfield}" # This is OK!
        }

```

but it appears you cannot have a comment inbetween hash entries

```
        add_field => {
            "@timestamp" => "%{timestamp}" # This is not OK!
            "[event][logsource][host]" => "%{myfield}"
        }

```

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [May 13, 2019, 1:40pm UTC](https://discuss.elastic.co/t/logstash-configuration-comment-breaks-the-logstash-configuration/180802/3 "2019-05-13T13:40:03Z")

</div>

Should I move this issue to the logstash github as a bug?  
Would you classifiy this as a bug to begin with?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 13, 2019, 2:06pm UTC](https://discuss.elastic.co/t/logstash-configuration-comment-breaks-the-logstash-configuration/180802/4 "2019-05-13T14:06:24Z")

</div>

There is already an issue for it - [10053](https://github.com/elastic/logstash/issues/10053)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2019, 2:17pm UTC](https://discuss.elastic.co/t/logstash-configuration-comment-breaks-the-logstash-configuration/180802/5 "2019-06-10T14:17:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
