# Logstash Configuration Error: "Expected one of #,"

**URL:** <https://discuss.elastic.co/t/logstash-configuration-error-expected-one-of/150827>\
**Category:** Logstash\
**Created:** [October 3, 2018, 6:40am UTC](https://discuss.elastic.co/t/logstash-configuration-error-expected-one-of/150827 "2018-10-03T06:40:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rohini\_basu](https://avatars.discourse-cdn.com/v4/letter/r/57b2e6/32.png) [@rohini\_basu](https://discuss.elastic.co/u/rohini_basu)\
**Post date:** [October 3, 2018, 6:40am UTC](https://discuss.elastic.co/t/logstash-configuration-error-expected-one-of/150827/1 "2018-10-03T06:40:43Z")

</div>

Hello,

I am using Logstash to ingest CSV files into Elasticsearch. I am using a Linux Machine (CentOS7).

I have Latitude and Longitude information in my csv.

Hence I have created a mapping like below:  
PUT mks\_locdata/\_mapping/loc\_data  
{  
"loc\_data": {  
"properties": {  
"location": {  
"type": "geo\_point"  
}  
}  
}  
}

Then I am using the below logstash config file for data ingestion:

> input {  
> file {  
> path =\> "/opt/elastic/elasticsearch/Data/Locations.csv"  
> start\_position =\> "beginning"  
> sincedb\_path =\> "/dev/null"  
> }  
> }  
> filter {  
> csv {  
> separator =\> ","  
> columns =\> ["City", "State", "Lat", "Long"]  
> }
> 
> ```
> mutate {
> convert => { "Long" => "float" }
> convert => { "Lat" => "float" }
> }
> 
> mutate {
> rename => {
> "Long" => "[location][lon]"
> "Lat" => "[location][lat]"
> }
> 
> ```
> 
> }  
> output {  
> elasticsearch {  
> hosts =\> "localhost"  
> index =\> "mks\_locdata"  
> document\_type =\> "loc\_data"  
> }  
> stdout {}  
> }

I am getting the below error:  
Sending Logstash logs to /opt/elastic/elasticsearch/logstash-6.4.1/logs which is now configured via log4j2.properties  
[2018-10-03T06:17:42,756][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-10-03T06:17:43,710][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.4.1"}  
[2018-10-03T06:17:44,891]**[ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, =\> at line 26, column 23 (byte 575) after filter {\r\n csv {\r\n separator =\> ","\r\n columns =\> ["City", "State", "Lat", "Long"]\r\n }\r\n\r\n mutate {\r\n\t\t\tconvert =\> { "Long" =\> "float" }\r\n\t\t\tconvert =\> { "Lat" =\> "float" }\r\n\t\t}\r\n\r\n mutate {\r\n\t\t\trename =\> {\r\n\t\t\t\t"Long" =\> "[location][lon]"\r\n\t\t\t\t"Lat" =\> "[location][lat]"\r\n\t\t}\r\n}\r\noutput {\r\n elasticsearch ", :backtrace=\>["/opt/elastic/elasticsearch/logstash-6.4.1/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/opt/elastic/elasticsearch/logstash-6.4.1/logstash-core/lib/logstash/compiler.rb:49:in `compile\_graph'", "/opt/elastic/elasticsearch/logstash-6.4.1/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/opt/elastic/elasticsearch/logstash-6.4.1/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:149:in `initialize'", "/opt/elastic/elasticsearch/logstash-6.4.1/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "/opt/elastic/elasticsearch/logstash-6.4.1/logstash-core/lib/logstash/pipeline.rb:90:in `initialize'", "/opt/elastic/elasticsearch/logstash-6.4.1/logstash-core/lib/logstash/pipeline\_action/create.rb:38:in `execute'", "/opt/elastic/elasticsearch/logstash-6.4.1/logstash-core/lib/logstash/agent.rb:309:in `block in converge\_state'"]}**  
[2018-10-03T06:17:45,331][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

What am I missing here?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 3, 2018, 6:43am UTC](https://discuss.elastic.co/t/logstash-configuration-error-expected-one-of/150827/2 "2018-10-03T06:43:36Z")

</div>

Looks like you may be missing a closing `}` for the last mutate filter. This type of issues is usually a lot easier to spot if you indent and format your config properly.

---

<div class="post-metadata">

**Author:** ![rohini\_basu](https://avatars.discourse-cdn.com/v4/letter/r/57b2e6/32.png) [@rohini\_basu](https://discuss.elastic.co/u/rohini_basu)\
**Post date:** [October 3, 2018, 6:48am UTC](https://discuss.elastic.co/t/logstash-configuration-error-expected-one-of/150827/4 "2018-10-03T06:48:54Z")

</div>

Thanks. That is the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2018, 6:48am UTC](https://discuss.elastic.co/t/logstash-configuration-error-expected-one-of/150827/5 "2018-10-31T06:48:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
