# Logstash error {:reason=\>"Expected one of #, \\", ', }

**URL:** <https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752>\
**Category:** Logstash\
**Created:** [November 15, 2017, 1:26pm UTC](https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752 "2017-11-15T13:26:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gaoo\_Nin\_Rice](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@Gaoo\_Nin\_Rice](https://discuss.elastic.co/u/Gaoo_Nin_Rice)\
**Post date:** [November 15, 2017, 1:26pm UTC](https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752/1 "2017-11-15T13:26:46Z")

</div>

hi, I have a problem for my logstash config. Need to help what's happen from my config

**_my config_**

> input {  
> file {  
> ["host", "127.0.0.1"]  
> path =\> "/drives/d/logstash-5.6.3/bin/data/Topping/Trigger/\*.csv"  
> }  
> }  
> filter {  
> grok {  
> match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp},%{WORD:SERVICEID}|%{WORD:MSISDN}|%{WORD:RULEID}|%{WORD:AUDIENCEKEY}|%{WORD:treatment\_code}|%{WORD:NEXTWAVE}|%{WORD:CAMPCODE}|(%{WORD:CURRENT})?|%{NUMBER:EVNETVALUE}|%{WORD:EVNETDTTM}|%{GREEDYDATA:NAMEVALUEPAIR},%{WORD:STATUS}" }  
> }  
> }  
> date {  
> match =\> ["timestamp", "YYYY-MM-dd HH:mm:ss"]  
> locale =\> en  
> }  
> output {  
> stdout {  
> codec =\> dots {}  
> }

**_This error_**

> [2017-11-15T20:19:28,650][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"D:/logstash-5.6.3/modules/fb\_apache/configuration"}  
> [2017-11-15T20:19:28,654][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"D:/logstash-5.6.3/modules/netflow/configuration"}  
> [2017-11-15T20:19:28,765][ERROR][logstash.agent] Cannot create pipeline {:reason=\>"Expected one of #, ", ', } at line 3, column 3 (byte 19) after input {\n\tfile {\n\t\t"}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 15, 2017, 1:30pm UTC](https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752/2 "2017-11-15T13:30:51Z")

</div>

> ["host", "127.0.0.1"]

This line doesn't belong here. I don't even know what you're trying to do.

---

<div class="post-metadata">

**Author:** ![Gaoo\_Nin\_Rice](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@Gaoo\_Nin\_Rice](https://discuss.elastic.co/u/Gaoo_Nin_Rice)\
**Post date:** [November 15, 2017, 2:02pm UTC](https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752/3 "2017-11-15T14:02:11Z")

</div>

i need to test in my laptop. I'm a newbie.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 15, 2017, 2:08pm UTC](https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752/4 "2017-11-15T14:08:30Z")

</div>

Uh, sure. But you still need to remove that line.

---

<div class="post-metadata">

**Author:** ![Gaoo\_Nin\_Rice](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@Gaoo\_Nin\_Rice](https://discuss.elastic.co/u/Gaoo_Nin_Rice)\
**Post date:** [November 16, 2017, 10:18am UTC](https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752/5 "2017-11-16T10:18:36Z")

</div>

after remove it. and change output

> input {  
> file {  
> path =\> "d:\logstash-5.6.3\bin\data\Topping\Trigger\CMXTrigger\_170911105814\_0\_3.csv"  
> }  
> }  
> filter {  
> grok {  
> match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp},%{WORD:SERVICEID}|%{WORD:MSISDN}|%{WORD:RULEID}|%{WORD:AUDIENCEKEY}|%{WORD:treatment\_code}|%{WORD:NEXTWAVE}|%{WORD:CAMPCODE}|(%{WORD:CURRENT})?|%{NUMBER:EVNETVALUE}|%{WORD:EVNETDTTM}|%{GREEDYDATA:NAMEVALUEPAIR},%{WORD:STATUS}" }  
> }  
> }  
> date {  
> match =\> ["timestamp", "YYYY-MM-dd HH:mm:ss"]  
> locale =\> en  
> }  
> output {  
> codec =\> plain {  
> format =\> "%{[timestamp]} %{[SERVICEID]} %{[MSISDN]} %{[RULEID]} (%{[treatment\_code]}) %{[CAMPCODE]}"  
> }  
> file {  
> path =\> "D:\logstash-5.6.3\logs\topping\_trigger.log"  
> }  
> }

have new error

> 2560-11-15 20:59:43,642 main DEBUG Reconfiguration complete for context[name=1d81eb93] at URI D:\logstash-5.6.3\config\log4j2.properties (org.apache.logging.log4j.core.LoggerContext@228b4210) with optional ClassLoader: null  
> [2017-11-15T20:59:43,698][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"D:/logstash-5.6.3/modules/fb\_apache/configuration"}  
> [2017-11-15T20:59:43,703][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"D:/logstash-5.6.3/modules/netflow/configuration"}  
> [2017-11-15T20:59:43,850][ERROR][logstash.agent] Cannot create pipeline {:reason=\>"Expected one of #, input, filter, output at line 13, column 1 (byte 439) after "}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 16, 2017, 10:51am UTC](https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752/6 "2017-11-16T10:51:47Z")

</div>

You're closing the filter block before the date filter instead of after.

If you indent your configuration file this mistake is very easy to spot.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2017, 10:52am UTC](https://discuss.elastic.co/t/logstash-error-reason-expected-one-of/107752/7 "2017-12-14T10:52:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
