# "LogStash::ConfigurationError", :message=\>"Expected one of #

**URL:** <https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of/152367>\
**Category:** Logstash\
**Created:** [October 14, 2018, 4:43am UTC](https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of/152367 "2018-10-14T04:43:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![idrees](https://avatars.discourse-cdn.com/v4/letter/i/58956e/32.png) [@idrees](https://discuss.elastic.co/u/idrees)\
**Post date:** [October 14, 2018, 4:43am UTC](https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of/152367/1 "2018-10-14T04:43:36Z")

</div>

Dear all,  
i am using elasticsearch 6.4 with logstash and searchguard with ssl enabled on centos 7.  
my logstash configuration file is below

> input {  
> file {  
> path =\>"/root/logstashProjects/studentwithdraw/student\_withdraw.csv"  
> start\_position =\> "beginning"  
> sincedb\_path =\> "/dev/null"  
> }  
> }  
> filter {  
> csv {  
> separator =\> ","  
> columns =\> ["DEPT\_NAME" ,"CERT\_NAME", "SPEC\_NAME", "STUDENT\_NO", "STUD\_NAME", "GENDER", "ADVISORS\_NAME", "ACADEMIC\_YEAR", "REQUEST\_NO", "withdraw\_reason\_category", "STATUS", "WITHDRAW\_DATE", "LECTURER", "COURSE\_NO", "COURSE\_NAME", "SECTION\_NO", "TOTAL\_REG"]  
> }  
> mutate {convert =\> ["SECTION\_NO", "integer"] }  
> mutate {convert =\> ["TOTAL\_REG", "integer"] }  
> }  
> output {  
> elasticsearch {  
> user =\> admin  
> password =\> mypassword  
> hosts =\> "[https://myservername](https://myservername)"  
> index =\> "myindex"  
> ssl =\> true  
> ssl\_certificate\_verification =\> false  
> truststore =\> "/root/etc/elasticsearch/truststore.jks"  
> truststore\_password =\> mypassword  
> }  
> stdout { }  
> }

i run it with the following command

> bin/logstash -f /root/logstashProjects/studentwithdraw/logstash\_withdraw.config

it give the following error

> [root@bigdata logstash]# bin/logstash -f /root/logstashProjects/studentwithdraw/logstash\_withdraw.config  
> WARNING: Could not find logstash.yml which is typically located in $LS\_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults  
> Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console  
> [WARN] 2018-10-14 09:23:04.098 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified  
> [INFO] 2018-10-14 09:23:05.137 [LogStash::Runner] runner - Starting Logstash {"logstash.version"=\>"6.4.2"}  
> [ERROR] 2018-10-14 09:23:06.162 [Converge PipelineAction::Create] agent - Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, { at line 26, column 1 (byte 870) after output { \r\n elasticsearch {\r\n user =\> admin\r\n password =\> admin\r\n hosts =\> "[https://bigdata.hct.org](https://bigdata.hct.org)"\r\n index =\> "withdrawindex"\r\n ssl =\> true\r\n ssl\_certificate\_verification =\> false\r\n truststore =\> "/root/etc/elasticsearch/truststore.jks"\r\n truststore\_password =\> 8e204c774e79387f887e\r\n", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:149:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:90:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:38:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:309:in `block in converge\_state'"]}  
> [INFO] 2018-10-14 09:23:06.631 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=\>9600}

can somebody guide me with this issue please?

---

<div class="post-metadata">

**Author:** ![idrees](https://avatars.discourse-cdn.com/v4/letter/i/58956e/32.png) [@idrees](https://discuss.elastic.co/u/idrees)\
**Post date:** [October 14, 2018, 10:00am UTC](https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of/152367/2 "2018-10-14T10:00:53Z")

</div>

hi,  
i fixed it by puting the password in double quotations. please find the working file below

> input {  
> file {  
> path =\>"/root/logstashProjects/studentwithdraw/student\_withdraw.csv"  
> start\_position =\> "beginning"  
> sincedb\_path =\> "/dev/null"  
> }  
> }  
> filter {  
> csv {  
> separator =\> ","  
> columns =\> ["DEPT\_NAME" ,"CERT\_NAME", "SPEC\_NAME", "STUDENT\_NO", "STUD\_NAME", "GENDER", "ADVISORS\_NAME", "ACADEMIC\_YEAR", "REQUEST\_NO", "withdraw\_reason\_category", "STATUS", "WITHDRAW\_DATE", "LECTURER", "COURSE\_NO", "COURSE\_NAME", "SECTION\_NO", "TOTAL\_REG"]  
> }  
> mutate {convert =\> ["SECTION\_NO", "integer"] }  
> mutate {convert =\> ["TOTAL\_REG", "integer"] }  
> }  
> output {  
> elasticsearch {  
> user =\> admin  
> password =\> mypassword  
> hosts =\> "[https://myserver](https://myserver):myport"  
> index =\> "withdrawindex"  
> ssl =\> true  
> ssl\_certificate\_verification =\> false  
> truststore =\> "/etc/elasticsearch/truststore.jks"  
> truststore\_password =\> "mypassword"  
> document\_type =\> "withdrawdocument"  
> }  
> stdout { }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2018, 10:00am UTC](https://discuss.elastic.co/t/logstash-configurationerror-message-expected-one-of/152367/3 "2018-11-11T10:00:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
