# Logstash filter error (Pipeline aborted due to error )

**URL:** <https://discuss.elastic.co/t/logstash-filter-error-pipeline-aborted-due-to-error/178062>\
**Category:** Logstash\
**Created:** [April 23, 2019, 3:26pm UTC](https://discuss.elastic.co/t/logstash-filter-error-pipeline-aborted-due-to-error/178062 "2019-04-23T15:26:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dhaoui\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhaoui_ahmed/32/42366_2.png) [@Dhaoui\_Ahmed](https://discuss.elastic.co/u/Dhaoui_Ahmed)\
**Post date:** [April 23, 2019, 3:26pm UTC](https://discuss.elastic.co/t/logstash-filter-error-pipeline-aborted-due-to-error/178062/1 "2019-04-23T15:26:48Z")

</div>

Hello am running ELK stack( forwarding netscreen firewall logs ) with logstash input and output config no filter ,, all good until i have added a filter and i got this error in logstash logfile

Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<Grok::PatternError: pattern %{FULLSYSLOGTIMESTAMP:syslog\_timestamp} not defined\>, :backtrace=\>["/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:123:in `block in compile'", "org/jruby/RubyKernel.java:1411:in`loop'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:93:in `compile'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:281:in`block in register'", "org/jruby/RubyArray.java:1792:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:275:in`block in register'", "org/jruby/RubyHash.java:1419:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:270:in`register'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:56:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:259:in`register\_plugin'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:270:in `block in register_plugins'", "org/jruby/RubyArray.java:1792:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:270:in `register_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:612:in`maybe\_setup\_out\_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:280:in `start_workers'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:217:in`run'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:176:in `block in start'"], :thread=\>"#\<Thread:0x67d574ba run\>"}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 23, 2019, 3:50pm UTC](https://discuss.elastic.co/t/logstash-filter-error-pipeline-aborted-due-to-error/178062/2 "2019-04-23T15:50:33Z")

</div>

> [@Dhaoui\_Ahmed](#):
>
> exception=\>#\<Grok::PatternError: pattern %{FULLSYSLOGTIMESTAMP:syslog\_timestamp} not defined

You have a grok filter that attempts to match a pattern that you have not defined.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2019, 3:50pm UTC](https://discuss.elastic.co/t/logstash-filter-error-pipeline-aborted-due-to-error/178062/3 "2019-05-21T15:50:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
