# Logstash input error

**URL:** <https://discuss.elastic.co/t/logstash-input-error/113847>\
**Category:** Logstash\
**Created:** [January 2, 2018, 11:56pm UTC](https://discuss.elastic.co/t/logstash-input-error/113847 "2018-01-02T23:56:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![agonex](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@agonex](https://discuss.elastic.co/u/agonex)\
**Post date:** [January 2, 2018, 11:56pm UTC](https://discuss.elastic.co/t/logstash-input-error/113847/1 "2018-01-02T23:56:32Z")

</div>

Hi I need help with a issue in logstash...

I am testing a version 6 ELK and i have problems with inputs, i triying add another input type multiline and logs say me that:

2018-01-02T21:09:28.628326533Z [2018-01-02T21:09:28,627][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.  
2018-01-02T21:09:28.628390469Z Pipeline\_id:main  
2018-01-02T21:09:28.628398379Z Plugin: \<LogStash::Inputs::Tcp type=\>"was", port=\>9600, codec=\>\<LogStash::Codecs::Multiline pattern=\>"^(?%{MONTHDAY}[-]%{MONTHNUM}[-]%{YEAR})", negate=\>true, what=\>"previous", id=\>"447f483e-0e3b-41cf-96f0-b16d1b874311", enable\_metric=\>true, charset=\>"UTF-8", multiline\_tag=\>"multiline", max\_lines=\>500, max\_bytes=\>10485760\>, id=\>"07609f794bfeb61aefd210cc70219f7d4ac2ccfff30195be338a2f1162290f58", enable\_metric=\>true, host=\>"0.0.0.0", mode=\>"server", proxy\_protocol=\>false, ssl\_enable=\>false, ssl\_verify=\>true, ssl\_key\_passphrase=\>\>  
2018-01-02T21:09:28.628415582Z Error: Address already in use  
2018-01-02T21:09:28.628421205Z Exception: Java::JavaNet::BindException  
2018-01-02T21:09:28.628427222Z Stack: sun.nio.ch.Net.bind0(Native Method)  
2018-01-02T21:09:28.628433353Z sun.nio.ch.Net.bind(sun/nio/ch/Net.java:433)  
2018-01-02T21:09:28.628439652Z sun.nio.ch.Net.bind(sun/nio/ch/Net.java:425)  
2018-01-02T21:09:28.628445743Z sun.nio.ch.ServerSocketChannelImpl.bind(sun/nio/ch/ServerSocketChannelImpl.java:223)  
2018-01-02T21:09:28.628476785Z sun.nio.ch.ServerSocketAdaptor.bind(sun/nio/ch/ServerSocketAdaptor.java:74)

I configure a new input type: "was":

input{  
tcp {  
type =\> "microservices"  
port =\> 9500  
codec =\> multiline{  
pattern =\> "^(?%{MONTHDAY}[-]%{MONTHNUM}[-]%{YEAR})|"  
negate =\> true  
what =\> "previous"  
}  
}  
tcp {  
type =\> "was"  
port =\> 9600  
codec =\> multiline{  
pattern =\> "^(?%{MONTHDAY}[-]%{MONTHNUM}[-]%{YEAR})"  
negate =\> true  
what =\> "previous"  
}  
}  
tcp {  
type =\> "monitoring"  
port =\> 18080  
}

```
tcp {
type => "atla_services"
port => 9800
codec => "json"

```

}  
}  
filter {  
if [type] == "microservices"{  
grok {  
match =\> { "message" =\> "(?%{MONTHDAY}[-]%{MONTHNUM}[-]%{YEAR})?|(?%{HOUR}:%{MINUTE}:%{SECOND})?|(%{NONNEGINT:sss})?|(%{GREEDYDATA:cic})?|(%{GREEDYDATA:idc})?|(%{UUID:sesUID})?|(%{UUID:trnUID})?|(%{NONNEGINT:opnNro})?|(%{NONNEGINT:opnNroHost})?|(%{IP:servIp})?|(%{HOSTNAME:servNom})?|(%{GREEDYDATA:class})?|(%{NONNEGINT:idClass})?|(%{LOGLEVEL:loglevel})?|(%{GREEDYDATA:namespace}) ?|(%{WORD:method})?|(%{GREEDYDATA:msgMicroservices})?"}  
}  
}  
if [type] == "was"{  
grok {  
match =\> { "message" =\> "%{DATE:fecha\_was}? %{TIME:hora\_was}? [(%{GREEDYDATA:cic})?] [(%{GREEDYDATA:session})?] : [%{LOGLEVEL:loglevel}] (%{GREEDYDATA:namespace}) ? - %{GREEDYDATA:msgWas}?" }  
}  
}  
date {  
match =\> ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]  
}  
}  
output {  
if [type] == "atla\_services"{  
elasticsearch {  
hosts =\> ["host01:9200","host01:9203", "host01:9204"]  
user =\> elastic  
password =\> changeme  
index =\> "microservices-%{+YYYY.MM.dd}"

```
        }

```

}  
else {  
elasticsearch {  
hosts =\> ["host01:9200","host01:9203", "host01:9204"]  
user =\> elastic  
password =\> changeme  
}  
stdout {  
codec =\> rubydebug  
}  
}  
}

this configuration without "was" input and filter works fine.. What i do bad?

I Have only 1 logstash instance, the port 9600 in free to use logstash input...

suggestions?

I sorry for my bad english.. =)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 3, 2018, 9:14pm UTC](https://discuss.elastic.co/t/logstash-input-error/113847/2 "2018-01-03T21:14:51Z")

</div>

Logstash's monitoring API is already listening on port 9600. Either disable the monitoring API or pick another port.

---

<div class="post-metadata">

**Author:** ![agonex](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@agonex](https://discuss.elastic.co/u/agonex)\
**Post date:** [January 4, 2018, 3:43pm UTC](https://discuss.elastic.co/t/logstash-input-error/113847/3 "2018-01-04T15:43:10Z")

</div>

Thanks Magnus...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2018, 3:43pm UTC](https://discuss.elastic.co/t/logstash-input-error/113847/4 "2018-02-01T15:43:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
