# Logstash error when running .conf

**URL:** <https://discuss.elastic.co/t/logstash-error-when-running-conf/164079>\
**Category:** Logstash\
**Created:** [January 14, 2019, 3:18am UTC](https://discuss.elastic.co/t/logstash-error-when-running-conf/164079 "2019-01-14T03:18:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![OpSecMonkey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opsecmonkey/32/46110_2.png) [@OpSecMonkey](https://discuss.elastic.co/u/OpSecMonkey)\
**Post date:** [January 14, 2019, 3:18am UTC](https://discuss.elastic.co/t/logstash-error-when-running-conf/164079/1 "2019-01-14T03:18:02Z")

</div>

I get this error when running in centos 7

] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, { at line 15, column 11 (byte 289) after output {\n elasticsearch { host =\> ["[http://localhost:9200](http://localhost:9200)"] }\n index ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in`compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:149:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:90:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:42:in `block in execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:92:in`block in exclusive'", "org/jruby/ext/thread/Mutex.java:148:in `synchronize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:92:in`exclusive'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:38:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:317:in`block in converge\_state'"]}  
[2019-01-13T22:14:17,708][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Here is my config file

input {  
file {  
path =\> "/home/xxxxxxxx/Documents/conversion/\*.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}  
filter {  
csv {  
separator =\> ","  
}  
}  
output {  
elasticsearch { host =\> ["[http://localhost:9200](http://localhost:9200)"] }  
index =\> "xxxxx"  
}  
stdout {codec =\> rubydebug}  
}

Does anyone have any ideas that can help me?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 14, 2019, 3:20am UTC](https://discuss.elastic.co/t/logstash-error-when-running-conf/164079/2 "2019-01-14T03:20:05Z")

</div>

> [@OpSecMonkey](#):
>
> elasticsearch { host =\> ["[http://localhost:9200](http://localhost:9200)"] }

Remove the `}` in this line and you should be ok.

---

<div class="post-metadata">

**Author:** ![OpSecMonkey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opsecmonkey/32/46110_2.png) [@OpSecMonkey](https://discuss.elastic.co/u/OpSecMonkey)\
**Post date:** [January 14, 2019, 11:37am UTC](https://discuss.elastic.co/t/logstash-error-when-running-conf/164079/3 "2019-01-14T11:37:45Z")

</div>

Thanks. I knew it was going to be something like that. Thanks @warkolm.

* * *

Didnt work getting the same error as above.

---

<div class="post-metadata">

**Author:** ![OpSecMonkey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opsecmonkey/32/46110_2.png) [@OpSecMonkey](https://discuss.elastic.co/u/OpSecMonkey)\
**Post date:** [January 14, 2019, 9:54pm UTC](https://discuss.elastic.co/t/logstash-error-when-running-conf/164079/4 "2019-01-14T21:54:46Z")

</div>

Does anyone have any recommendations?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 14, 2019, 10:02pm UTC](https://discuss.elastic.co/t/logstash-error-when-running-conf/164079/5 "2019-01-14T22:02:16Z")

</div>

> [@OpSecMonkey](#):
>
> elasticsearch { host =\> ["[http://localhost:9200](http://localhost:9200)"] }

Remove the trailing ? _and_ change host to hosts.

---

<div class="post-metadata">

**Author:** ![OpSecMonkey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/opsecmonkey/32/46110_2.png) [@OpSecMonkey](https://discuss.elastic.co/u/OpSecMonkey)\
**Post date:** [January 14, 2019, 11:10pm UTC](https://discuss.elastic.co/t/logstash-error-when-running-conf/164079/6 "2019-01-14T23:10:00Z")

</div>

YAY!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2019, 11:11pm UTC](https://discuss.elastic.co/t/logstash-error-when-running-conf/164079/7 "2019-02-11T23:11:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
