# Logstash failing after upgrade into the version 2.x

**URL:** <https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537>\
**Category:** Logstash\
**Created:** [September 1, 2016, 10:58am UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537 "2016-09-01T10:58:53Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 1, 2016, 10:58am UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/1 "2016-09-01T10:58:53Z")

</div>

hi All, I recently upgraded logstash as per [https://www.elastic.co/guide/en/logstash/current/installing-logstash.html#package-repositories](https://www.elastic.co/guide/en/logstash/current/installing-logstash.html#package-repositories) and I'm unable to start the logstash service which is now failing with below error logged in logs:

{:timestamp=\>"2016-09-01T11:46:56.873000+0100", :message=\>"Pipeline aborted due to error", :exception=\>"LogStash::ConfigurationError", :backtrace=\>["/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/config/mixin.rb:88:in `config\_init'",

Any help will be much appreciated, cheers, Tomek

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 11:32am UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/2 "2016-09-01T11:32:48Z")

</div>

Is that really the only error message? What if you run `logstash --configtest` on your configuration files?

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 1, 2016, 12:23pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/3 "2016-09-01T12:23:59Z")

</div>

hi Magnus, thanks for the prompt response logstash --configtest results in the "Configuration OK", see the contents of my filter folders:

ls -l /etc/logstash/conf.d/  
total 20  
-rw-r--r-- 1 kibana4 kibana4 438 Sep 1 11:42 01-inputs.conf  
-rw-rw-r-- 1 kibana4 kibana4 1195 Jul 12 07:09 10-syslog.conf  
-rw-rw-r-- 1 kibana4 kibana4 1302 Jul 12 07:05 11-pfsense.conf  
-rw-rw-r-- 1 kibana4 kibana4 127 Jul 12 07:03 30-outputs.conf  
drwxr-xr-x 2 kibana4 kibana4 4096 Jul 12 07:10 patterns

Shall i try to run the configtest against those files or does the configtest goes through them automatically?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 1:30pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/4 "2016-09-01T13:30:10Z")

</div>

It does not use those files automatically. Run `logstash --configtest -f /etc/logstash/conf.d`.

I can tell you already that it's complaining about the patterns file which, I assume, is a grok pattern file. Logstash reads _all_ files in the configuration directory it's pointed to.

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 1, 2016, 2:23pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/5 "2016-09-01T14:23:06Z")

</div>

thanks Magnus, it does not show me any output regarding the grok patterns- do i need to update them separately?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 2:24pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/6 "2016-09-01T14:24:16Z")

</div>

You probably don't need to update them at all, but they can't be stored in /etc/logstash/conf.d since Logstash reads _all_ files in that directory as configuration files.

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 1, 2016, 2:28pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/7 "2016-09-01T14:28:15Z")

</div>

what will be your suggestion to move the patterns folder to?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 2:32pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/8 "2016-09-01T14:32:23Z")

</div>

/etc/logstash for example.

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 1, 2016, 3:21pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/9 "2016-09-01T15:21:09Z")

</div>

Still the same error (with the grok patterns in /etc/logstash). I'm pasting the error message from logstash.log:

{:timestamp=\>"2016-09-01T16:18:58.186000+0100", :message=\>"Pipeline aborted due to error", :exception=\>"LogStash::ConfigurationError", :backtrace=\>["/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/config/mixin.rb:88:in `config_init'", "org/jruby/RubyHash.java:1342:in`each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/config/mixin.rb:72:in `config_init'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/outputs/base.rb:79:in`initialize'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/output\_delegator.rb:74:in `register'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:181:in`start\_workers'", "org/jruby/RubyArray.java:1613:in `each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:181:in`start\_workers'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:136:in `run'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/agent.rb:491:in`start\_pipeline'"], :level=\>:error}  
{:timestamp=\>"2016-09-01T16:19:01.192000+0100", :message=\>"stopping pipeline", :id=\>"main"}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 4:32pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/10 "2016-09-01T16:32:30Z")

</div>

Is that really the only message in the log? The stacktrace indicates that you're using an obsolete configuration option for some plugin, but I'd expect there to be a message indicating _which_ option it's complaining about.

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 1, 2016, 4:38pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/11 "2016-09-01T16:38:59Z")

</div>

That is the only message logged into the log files- will you be able to point me into where can I look for the obsolete option. Let me know if you require any additional logs (elasticsearch, syslog)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 1, 2016, 4:49pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/12 "2016-09-01T16:49:51Z")

</div>

The documentation for the plugins you use should state if the option is obsolete (or if it's missing from the documentation; that would obviously be a clear indication), but if you post your configuration we might be able to spot the problem right away.

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 2, 2016, 10:32am UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/13 "2016-09-02T10:32:01Z")

</div>

Thanks Magnus and apologies for the delay in replying i will post the conf files shortly. Just to double check with you as plugin configuration you are referring to the contents of /etc/logstash/conf.d/

To let you know i dont have any additional plugins for elasticsearch. I had kopf and bigdesk, but removed them prior to upgrade.

Cheers, Tomek

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 2, 2016, 10:51am UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/14 "2016-09-02T10:51:27Z")

</div>

> Just to double check with you as plugin configuration you are referring to the contents of /etc/logstash/conf.d/

Yes.

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 2, 2016, 11:15am UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/15 "2016-09-02T11:15:56Z")

</div>

OK, see the files in my owncloud drive: [http://yourls.dyndns.biz/logstash](http://yourls.dyndns.biz/logstash)

I've included below as a single text file:

ls -l /etc/logstash/conf.d/  
-rw-r--r-- 1 kibana4 kibana4 438 Sep 1 11:42 01-inputs.conf  
-rw-rw-r-- 1 kibana4 kibana4 1195 Jul 12 07:09 10-syslog.conf  
-rw-rw-r-- 1 kibana4 kibana4 1295 Sep 1 16:18 11-pfsense.conf  
-rw-rw-r-- 1 kibana4 kibana4 125 Sep 2 11:57 30-outputs.conf

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 2, 2016, 11:36am UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/16 "2016-09-02T11:36:51Z")

</div>

In your elasticsearch output configuration, change

```
host => localhost

```

to

```
hosts => ["localhost"]

```

This is documented in the [2.0 breaking changes document](https://www.elastic.co/guide/en/logstash/2.0/breaking-changes.html).

---

<div class="post-metadata">

**Author:** ![napoleon182](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/napoleon182/32/11725_2.png) [@napoleon182](https://discuss.elastic.co/u/napoleon182)\
**Post date:** [September 2, 2016, 12:11pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/17 "2016-09-02T12:11:35Z")

</div>

Magnus, Fantastic! worked as a charm and many, many thanks as it was causing a massive pain for me to sort it.  
I can confirm that all is working fine now and both logstash and elasticsearch are working fine

---

<div class="post-metadata">

**Author:** ![Soren](https://avatars.discourse-cdn.com/v4/letter/s/f14d63/32.png) [@Soren](https://discuss.elastic.co/u/Soren)\
**Post date:** [September 21, 2016, 12:36pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/18 "2016-09-21T12:36:19Z")

</div>

I've tried the configuration above but I'm still getting this error:

{:timestamp=\>"2016-09-21T14:13:43.656000+0200", :message=\>"Pipeline aborted due to error", :exception=\>"Grok::PatternError", :backtrace=\>["/opt/logstash/vendor/bundle/jruby/1.9/gems/jls-grok-0.11.3/lib/grok-pure.rb:123:in `compile'", "org/jruby/RubyKernel.java:1479:in`loop'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/jls-grok-0.11.3/lib/grok-pure.rb:93:in `compile'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-2.0.5/lib/logstash/filters/grok.rb:264:in`register'", "org/jruby/RubyArray.java:1613:in `each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-2.0.5/lib/logstash/filters/grok.rb:259:in`register'", "org/jruby/RubyHash.java:1342:in `each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-2.0.5/lib/logstash/filters/grok.rb:255:in`register'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:182:in `start_workers'", "org/jruby/RubyArray.java:1613:in`each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:182:in `start_workers'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:136:in`run'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/agent.rb:491:in `start\_pipeline'"], :level=\>:error}  
{:timestamp=\>"2016-09-21T14:13:46.664000+0200", :message=\>"stopping pipeline", :id=\>"main"}

Any suggestions?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 21, 2016, 1:55pm UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/19 "2016-09-21T13:55:49Z")

</div>

@Soren, please start a new thread for your question.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:37am UTC](https://discuss.elastic.co/t/logstash-failing-after-upgrade-into-the-version-2-x/59537/20 "2017-07-06T04:37:34Z")

</div>


