# Logstash Error

**URL:** <https://discuss.elastic.co/t/logstash-error/303872>\
**Category:** Logstash\
**Created:** [May 3, 2022, 7:44pm UTC](https://discuss.elastic.co/t/logstash-error/303872 "2022-05-03T19:44:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Akhil2](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Post date:** [May 3, 2022, 7:44pm UTC](https://discuss.elastic.co/t/logstash-error/303872/1 "2022-05-03T19:44:58Z")

</div>

Hello there,

I am using Elasticsearch three node implementation cluster. I am using version 7.16.2. I have set up this cluster with basic settings. No security has been set up.

Here is the example of data I tried to Ingest.

```auto
Abraham	Jose	A	19551131
Aguilar	Drazenko	A	18911530
Aldaco	Frank	A	14511025
Alejandro	Bruce	A	13427703
Alshefski	Aaku	A	11234551
Alzer	Mason	A	80200418
Ancsanyi	Dennis	A	17465939
Anderson	Florenti	A	17485930
Anderson	Henner	A	16784032

```

Here is the config file I used

```auto
input {
	stdin { 
		codec => line {
			charset => "UTF-8"
		}
	}
}

filter {
	# The fingerprint filter creates a unique identifier that is used as the document id. 
	# This creates a hash key based on the content message that is used as a unique id/key for each elasticsearch entry. 
	 
	fingerprint { 
		source => "message"
		target => "[@metadata][fingerprint]"
		method => "SHA1"
		# For the key we use the name of the index followed by the unique string on the first line of the csv data file.  
		key => "traveller_no_dups"
		base64encode => true
	}
	
	# Defines all the field in the csv file in the order they are found. 
	
    csv {
        separator => ","
		columns => [
			"SURNAME", 
			"FIRST_NAME", 
			"MIDDLE_NAME", 
			"BIRTHDATE", 
		]
	}

	# Add new DOB field will hold the BIRTHDATE content. 
	mutate {
		add_field => { "DOB" => "%{BIRTHDATE}" }
	}
	
	#	Process the birthdate as DOB. Convert the birthdate into a date value. 
	date {
		match => ["DOB", "yyyyMMdd"]
		target => "DOB"
	}

	# remove all fields we dont need anymore. 
	mutate { 
		remove_field => ["BIRTHDATE"]
	}	
}

output { 
     elasticsearch {
            action => "index"
            hosts => "localhost:9200"
            index => "traveller_no_dups"
			document_id => "%{[@metadata][fingerprint]}"
       }
        stdout {codec => rubydebug}
# stdout {}
}

```

So, when I tried to Ingest data, it gave me following errors.  
This loop would load the first 9 million rows

I tried the same process with version 8.0.0 but it gave me same errors.  
The same script works on a single node implementation and the version is 7.5.

```auto
PS D:\APPS\ELK7.16.2\logstash-7.16.2> $Current_time = Get-Date
"Start run 1 - 9 @ " + $Current_time
$stopwatch_all = [System.Diagnostics.Stopwatch]::StartNew()
" "
For ($i = 1; $i -lt 10; $i++) {
   $Current_time = Get-Date
   "Start file $i @ " + $Current_time
   $stopwatch = [System.Diagnostics.Stopwatch]::StartNew()
   & type E:\No_Duplicates\Split_Files\PH_MODEL_NAMES_NO_DUPS_SPLIT_00$i.csv | .\bin\logstash.bat –f E:\Scripts\TRAV_NO_DUPS.conf > E:\No_Duplicates\Ingest_Runs\LOGSTASH_NO_DUPS_00$i.txt
   "File PH_MODEL_NAMES_NO_DUPS_SPLIT_00$i.csv"
   $Current_time = Get-Date
   "End file $i @ " + $Current_time
   "Elapsed time: " + $stopwatch.Elapsed.ToString()
   $stopwatch.Stop()
   " "
}
"Overall time 1 - 9: " + $stopwatch_all.Elapsed.ToString()
$stopwatch_all.Stop()
" "

Start run 1 - 9 @ 02/18/2022 14:46:54

Start file 1 @ 02/18/2022 14:46:54
.\bin\logstash.bat : OpenJDK 64-Bit Server VM warning: Option UseConcMarkSweepGC was deprecated in version 9.0 and will likely be 
removed in a future release.
At line:9 char:113
+ ... _00$i.csv | .\bin\logstash.bat –f E:\Scripts\TR ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo : NotSpecified: (OpenJDK 64-Bit ...future release.:String) [], RemoteException
    + FullyQualifiedErrorId : NativeCommandError

ERROR: Unknown command 'â€“f'
See: 'bin/logstash --help'
File PH_MODEL_NAMES_NO_DUPS_SPLIT_001.csv
End file 1 @ 02/18/2022 14:49:08
Elapsed time: 00:02:14.3544994

Start file 2 @ 02/18/2022 14:49:08

```

The error in logfile is below.

```auto
"Using bundled JDK: ."
[FATAL] 2022-02-22 14:40:47.126 [main] Logstash - Logstash stopped processing because of an error: (SystemExit) exit
org.jruby.exceptions.SystemExit: (SystemExit) exit
	at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:747) ~[jruby-complete-9.2.20.1.jar:?]
	at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:710) ~[jruby-complete-9.2.20.1.jar:?]
	at D_3a_.APPS.ELK8_dot_0_dot_0.logstash_minus_8_dot_0_dot_0.vendor.bundle.jruby.$2_dot_5_dot_0.gems.clamp_minus_1_dot_0_dot_1.lib.clamp.command.run(D:/APPS/ELK8.0.0/logstash-8.0.0/vendor/bundle/jruby/2.5.0/gems/clamp-1.0.1/lib/clamp/command.rb:138) ~[?:?]
	at D_3a_.APPS.ELK8_dot_0_dot_0.logstash_minus_8_dot_0_dot_0.lib.bootstrap.environment.<main>(D:\APPS\ELK8.0.0\logstash-8.0.0\lib\bootstrap\environment.rb:93) ~[?:?]

```

```auto
•	Is it a code page issue
 	   ERROR: Unknown command 'â€“f'
•	It fails at the Logstash call
        At line:9 char:113
	    .\bin\logstash.bat –f E:\Scripts\TR ...
•	Is it a JDK error
	     + CategoryInfo : NotSpecified: (OpenJDK 64-Bit ...future release.:String) [], 
         RemoteException
	     + FullyQualifiedErrorId : NativeCommandError

```

Please let me know if someone can help!

Thank you,  
Akhil

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2022, 3:07am UTC](https://discuss.elastic.co/t/logstash-error/303872/2 "2022-05-04T03:07:24Z")

</div>

`ERROR: Unknown command 'â€“f'` looks very similar to [this](https://discuss.elastic.co/t/unable-to-start-logstash-error-unknown-command-i-f/198783/4). Do you have –f instead of -f?

> [@Akhil2](#):
>
> ```auto
> mutate {
> add_field => { "DOB" => "%{BIRTHDATE}" }
> }
> 	
> #	Process the birthdate as DOB. Convert the birthdate into a date value. 
> date {
> match => ["DOB", "yyyyMMdd"]
> target => "DOB"
> }
> 
> # remove all fields we dont need anymore. 
> mutate { 
> remove_field => ["BIRTHDATE"]
> }	
> 
> ```

That will work, but I would suggest

```
date {
	match => ["BIRTHDATE", "yyyyMMdd"]
	target => "DOB"
	remove_field => ["BIRTHDATE"]
}

```

That will leave the [BIRTHDATE] field intact if a date filter is unable to parse it. So if someone sends you dodgy data you will be able to see what is wrong with it.

---

<div class="post-metadata">

**Author:** ![Akhil2](https://avatars.discourse-cdn.com/v4/letter/a/8797f3/32.png) [@Akhil2](https://discuss.elastic.co/u/Akhil2)\
**Post date:** [May 4, 2022, 6:07pm UTC](https://discuss.elastic.co/t/logstash-error/303872/3 "2022-05-04T18:07:59Z")

</div>

Thanks Badger! This worked and my issue is resolved. 😀

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2022, 6:08pm UTC](https://discuss.elastic.co/t/logstash-error/303872/4 "2022-06-01T18:08:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
