# Logstash Error - causing shutdown and restart

**URL:** <https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232>\
**Category:** Logstash\
**Created:** [November 25, 2019, 6:59am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232 "2019-11-25T06:59:11Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [November 25, 2019, 6:59am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/1 "2019-11-25T06:59:11Z")

</div>

Hi may I know how to resolve this? I am unable to identify which file is causing this error.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95acf868b82972c85a2b9cffe1c5713e5d9183da.png)

---

<div class="post-metadata">

**Author:** ![sam.cook](https://avatars.discourse-cdn.com/v4/letter/s/57b2e6/32.png) [@sam.cook](https://discuss.elastic.co/u/sam.cook)\
**Post date:** [November 25, 2019, 11:25am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/2 "2019-11-25T11:25:56Z")

</div>

Can you post your configuration file?

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [November 26, 2019, 1:14am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/3 "2019-11-26T01:14:51Z")

</div>

Hi Sam, below is the yml config file.

```
path.data: /usr/share/logstash/data/
path.config: /etc/logstash/conf.d/
path.logs: /var/log/logstash

pipeline.batch.size: 125
pipeline.batch.delay: 50

log.level: info
path.logs: /var/log/logstash

xpack.monitoring.enabled: true
xpack.monitoring.elasticsearch.username: "elastic"
xpack.monitoring.elasticsearch.password: " *************"
xpack.monitoring.elasticsearch.hosts: ["http://IP"]
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 26, 2019, 1:27am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/4 "2019-11-26T01:27:31Z")

</div>

The problem is in your logstash configuration file, not in logstash.yml. It will be one of the files in path.config (/etc/logstash/conf.d/). The hosts option on an elasticsearch output expects an array of strings. logstash is flexible (perhaps confusingly flexible) about allowing "barewords" where strings are expected (i.e. strings not enclosed in quotes), but the periods in an IP address will break that.

To put it more simply,

```
hosts => [127.1.2.3:9200]

```

will result in an error and has to be changed to

```
hosts => ["127.1.2.3:9200"]
```

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [November 26, 2019, 2:07am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/5 "2019-11-26T02:07:22Z")

</div>

Hi, I have checked all the hosts are already properly formatted to this. But still having the issue. Other than that, what should I check as well?

---

<div class="post-metadata">

**Author:** ![st3inbeiss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/st3inbeiss/32/55332_2.png) [@st3inbeiss](https://discuss.elastic.co/u/st3inbeiss)\
**Post date:** [November 26, 2019, 8:55am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/6 "2019-11-26T08:55:35Z")

</div>

Do you have ANY file in the folder /etc/logstash/conf.d with the ending .conf which you haven't checked? Some old "disabled" dev-pipeline or something maybe?

As Badger said, this almost definitely is a config file without quotes around the address in a conf file in this specific location according to your screenshot (because of the pipeline being "main" and the error given). Please double check.

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [November 26, 2019, 9:01am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/7 "2019-11-26T09:01:39Z")

</div>

> [@st3inbeiss](#):
>
> As Badger said, this almost definitely is a config file without quotes around the address in a conf file in this specific location according to your screenshot (because of the pipeline being "main" and the error given). Please double check.

Hi yes, I have 3 files there. 01-wazuh.conf / 02-beats-input.conf / 30-elasticsearch-output.conf.

The rest I moved to a backup folder.

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [November 26, 2019, 9:18am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/8 "2019-11-26T09:18:34Z")

</div>

Error:

[ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, ,, ] at line 91, column 23 (byte 1978) after output {\n if [type] == "stdin-type" {\n elasticsearch {\n hosts =\> [10.162", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2577:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:151:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:23:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:325:in `block in converge\_state'"]}

[2019-11-26T15:15:40,998][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, ,, ] at line 91, column 23 (byte 1978) after output {\n if [type] == "stdin-type" {\n elasticsearch {\n hosts =\> [10.162", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2577:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:151:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:23:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:325:in `block in converge\_state'"]}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 26, 2019, 1:34pm UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/9 "2019-11-26T13:34:55Z")

</div>

Try running with --config.debug --log.level debug --config.test\_and\_exit on the command line. That will show you each file that it is loading as part of the configuration, and it will show you the merged configuration. You can then identify where line 91 is coming from.

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [November 27, 2019, 1:37am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/10 "2019-11-27T01:37:31Z")

</div>

Hi thanks for the suggestion. May I know how should I run it on the command line?

service logstash --config.debug ?  
service logstash --log.level debug  
service logstash --config.test\_and\_exit

Correct ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 27, 2019, 1:51am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/11 "2019-11-27T01:51:52Z")

</div>

It sounds like you are using a configuration manager. I can't help with that since I do not know which manager you are using.

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [November 27, 2019, 3:08am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/12 "2019-11-27T03:08:55Z")

</div>

Oh no, I am using command line. Not using any configuration manager

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 27, 2019, 4:53pm UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/13 "2019-11-27T16:53:26Z")

</div>

If you are running logstash on the command line then just add all three options to the command line.

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [November 28, 2019, 9:21am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/14 "2019-11-28T09:21:17Z")

</div>

Hi friend, please help to advise. Now all the filters and input/ output are ok. Now having pipeline patterns error and the following:

[2019-11-28T17:15:38,171][ERROR][logstash.javapipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<Grok::PatternError: pattern %{NGINXACCESS} not defined\>, :backtrace=\>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:123:in `block in compile'", "org/jruby/RubyKernel.java:1425:in `loop'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:93:in `compile'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:281:in `block in register'", "org/jruby/RubyArray.java:1792:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:275:in `block in register'", "org/jruby/RubyHash.java:1419:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:270:in `register'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:56:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:191:in `block in register\_plugins'", "org/jruby/RubyArray.java:1792:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:190:in `register\_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:446:in `maybe_setup_out_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:203:in `start\_workers'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:145:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:104:in `block in start'"], :thread=\>"#\<Thread:0x4d8c5e run\>"}  
-bash: syntax error near unexpected token `newline'  
root@eta10:/var/log/logstash# [2019-11-28T17:15:38,189][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}

---

<div class="post-metadata">

**Author:** ![st3inbeiss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/st3inbeiss/32/55332_2.png) [@st3inbeiss](https://discuss.elastic.co/u/st3inbeiss)\
**Post date:** [November 28, 2019, 3:22pm UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/15 "2019-11-28T15:22:19Z")

</div>

There is no GROK-Pattern with the name %{NGINXACCESS} defined. Either you need to define a custom Pattern with this name yourself or you have to replace it with some other pattern - testwise with %{GREEDYDATA} or something alike.

Please provide the config if this doesn't work for you.

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [December 3, 2019, 6:34am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/16 "2019-12-03T06:34:10Z")

</div>

Hi, do you know which file does it refers to? I am unable to find the file containing this word.

I was following this guide, its should be the official guideline, how come the patterns cannot be match? Any idea? Or how can I recreate those missing items?

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [December 5, 2019, 8:10am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/17 "2019-12-05T08:10:25Z")

</div>

Logstash.yml

**path.data** : /usr/share/logstash/data/  
**path.config** : /etc/logstash/conf.d/  
**path.logs** : /var/log/logstash  
http.port: 9610  
**xpack.monitoring.enabled** : true  
**xpack.monitoring.elasticsearch.username** : "elastic"  
**xpack.monitoring.elasticsearch.password** : "_changeme_"  
**xpack.monitoring.elasticsearch.hosts** : ["[http://ip:9200](http://ip:9200)"]

---

<div class="post-metadata">

**Author:** ![rameshkr1994](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rameshkr1994/32/59029_2.png) [@rameshkr1994](https://discuss.elastic.co/u/rameshkr1994)\
**Post date:** [December 9, 2019, 10:20am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/18 "2019-12-09T10:20:13Z")

</div>

Hi @skyluke.1987.

i think i am sure your issue is coming from logstash-metadb file.

just do one thing remove your old .logstash-metadb file from user home path:-

you need to re run logstash file from terminal as your previous.

`Note :- this kind of issue come when your are doing some import data from some other server or db into existing elastic search index but existing index is not matching with newly coming index pattern. or your privious metadata is not able to read/match`

Thanks  
HadoopHelp

---

<div class="post-metadata">

**Author:** ![skyluke.1987](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@skyluke.1987](https://discuss.elastic.co/u/skyluke.1987)\
**Post date:** [December 10, 2019, 8:30am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/19 "2019-12-10T08:30:15Z")

</div>

Hi thanks. My logstash now encounter frequent restart. Each time it will not last for long, only a few minutes.

---

<div class="post-metadata">

**Author:** ![rameshkr1994](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rameshkr1994/32/59029_2.png) [@rameshkr1994](https://discuss.elastic.co/u/rameshkr1994)\
**Post date:** [December 12, 2019, 8:51am UTC](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232/20 "2019-12-12T08:51:47Z")

</div>

Hi @skyluke.1987.

`so i think you collecting some data from some source to elastic search index using Logstash within logstash scheduler ?`

> if yes :::please try to increase your scheduler time interval ....  
> this can be resolved your issue?  
> and also try to check RAM Occupied from Elasticsearch machine ...

Note :- correct me if i am wrong 👏

Thanks  
HadoopHelp

[Next page](https://discuss.elastic.co/t/logstash-error-causing-shutdown-and-restart/209232.md?page=2)
