# Logstash on Windows - Multiple Pipeline Problem

**URL:** <https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846>\
**Category:** Logstash\
**Created:** [March 20, 2018, 7:00pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846 "2018-03-20T19:00:46Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 20, 2018, 7:00pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/1 "2018-03-20T19:00:47Z")

</div>

Is it possible to run multiple pipelines on the Windows version of Logstash? I can’t seem to get this to work for the life of me.

I have installed Logstash on Windows, and placed a pipelines.yml file in C:\Program Files\Logstash\config.

Here are the contents of the pipelines.yml

- pipeline.id: pipelinedmarcxml  
path.config: "c:\Program Files\Logstash\config\pipelines\dmarcxml.d"  
pipeline.workers: 3

When I launch logstash.bat from C:\Program Files\Logstash\bin, I see this message logged:

• [WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified

Then at the end of the startup process the pipeline terminates – assuming because it can’t load the needed configuration data specified in path.config from pipelines.yml file.

Is it possible to use multiple pipelines in the Windows variant of Logstash? If so, how is it done? Would someone please instruct me on what I am doing wrong?

For what it is worth, when I start Logstash with the -f flag the pipelines.yml file is not loaded as expected, but Logstash does indeed start with the config that the pipelines file points to.

Here is that command line:

logstash.bat -f "C:\Program Files\Logstash\config\pipelines\dmarcxml.d\logstash.conf"

-Tony

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 20, 2018, 7:14pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/2 "2018-03-20T19:14:29Z")

</div>

You can't use drive letters in the path and I BELIEVE you have to use forward slashes....though backslashes may work too. Try the below instead.

`path.config: "/Program Files/Logstash/config/pipelines/dmarcxml.d"`

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 20, 2018, 7:39pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/3 "2018-03-20T19:39:11Z")

</div>

I implemented your suggestion, and modified the path.config line. We now look look like this.

- pipeline.id: pipelinedmarcxml  
path.config: "/program files/logstash/config/pipelines/dmarcxml.d"  
pipeline.workers: 3

However, there was no change in behavior. I included the entire output.

[INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"C:/Program Files/Logstash/modules/fb\_apache/configuration"}  
[INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"C:/Program Files/Logstash/modules/netflow/configuration"}  
[INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"arcsight", :directory=\>"C:/Program Files/Logstash/vendor/bundle/jruby/2.3.0/gems/x-pack-6.2.2-java/modules/arcsight/configuration"}  
[WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.2.2"}  
[INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[WARN][logstash.outputs.elasticsearch] You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch hosts=\>[http://my\_server:9200], bulk\_path=\>"/\_xpack/monitoring/\_bulk?system\_id=logstash&system\_api\_version=2&interval=1s", manage\_template=\>false, document\_type=\>"%{[@metadata][document\_type]}", sniffing=\>false, id=\>"aadba5fcef4344a86d4ff81526835dbfa6bac63c4889322245f69daf37dec289", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_1b63ba34-4400-4423-8ed9-0d7328eee692", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, template\_name=\>"logstash", template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, action=\>"index", ssl\_certificate\_verification=\>true, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}  
[INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>".monitoring-logstash", "pipeline.workers"=\>1, "pipeline.batch.size"=\>2, "pipeline.batch.delay"=\>50}  
[INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[http://my\_server:9200/]}}  
[INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>http://my\_server:9200/, :path=\>"/"}  
[WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"http://my\_server:9200/"}  
[INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>nil}  
[WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["http://my\_server:9200"]}  
[INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[http://my\_server:9200/]}}  
[INFO][logstash.licensechecker.licensereader] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>http://my\_server:9200/, :path=\>"/"}  
[WARN][logstash.licensechecker.licensereader] Restored connection to ES instance {:url=\>"http://my\_server:9200/"}  
[INFO][logstash.licensechecker.licensereader] ES Output version determined {:es\_version=\>nil}  
[WARN][logstash.licensechecker.licensereader] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[INFO][logstash.pipeline] Pipeline started succesfully {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x18cc8a run\>"}  
[ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 6, column 1 (byte 132) after ## JVM configuration\n\n# Xms represents the initial size of total heap space\n# Xmx represents the maximum size of total heap space\n\n", :backtrace=\>["C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:90:in `execute'", "C:/Program Files/Logstash/logstash-core/lib/logstash/runner.rb:348:in`block in execute'", "C:/Program Files/Logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}  
[INFO][logstash.inputs.metrics] Monitoring License OK  
[INFO][logstash.pipeline] Pipeline has terminated {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x18cc8a run\>"}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 20, 2018, 7:51pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/4 "2018-03-20T19:51:48Z")

</div>

There are two interesting things in the log.

> [WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified

So, if you want Logstash to pay any attention to your pipelines.yml you shouldn't pass the path to a configuration file with `-f`.

> LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 6, column 1 (byte 132) after ## JVM configuration\n\n# Xms represents the initial size of total heap space\n# Xmx represents the maximum size of total heap space\n\n

This indicates that Logstash somehow picks up your jvm.options file (or whatever file the JVM-related text comes from). Where is that file? What other files are there in that directory?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 20, 2018, 7:53pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/5 "2018-03-20T19:53:53Z")

</div>

> [ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 6, column 1 (byte 132) after ## JVM configuration\n\n# Xms represents the initial size of total heap space\n# Xmx represents the maximum size of total heap space\n\n", :backtrace=\>["C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:42:in compile\_imperative'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:50:incompile\_graph'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:12:in block in compile\_sources'", "org/jruby/RubyArray.java:2486:inmap'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:11:in compile\_sources'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline.rb:51:ininitialize'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline.rb:169:in initialize'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:40:inexecute'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:315:in block in converge\_state'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:141:inwith\_pipelines'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:312:in block in converge\_state'", "org/jruby/RubyArray.java:1734:ineach'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:299:in converge\_state'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:166:inblock in converge\_state\_and\_update'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:141:in with\_pipelines'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:164:inconverge\_state\_and\_update'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:90:in execute'", "C:/Program Files/Logstash/logstash-core/lib/logstash/runner.rb:348:inblock in execute'", "C:/Program Files/Logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

No sir, it's working now. It's a new problem with a config file on line 6, column 1. Did you set an incorrect value in your jvm.options file or are you trying to set JVM head sizes in your pipeline?

Edit: As Magnus initially caught, need to remove -f, which bypasses any pipeline config files when set. Just run logstash without any arguments.

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 20, 2018, 8:19pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/6 "2018-03-20T20:19:25Z")

</div>

Hey Magnus,

Yeah, I know that -f makes logstash ignore the pipelines.yml file.

If I use -f or not, I still get the message: [WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified.

For example I get that message with: logstash.bat or even logstash.bat -f "C:\Program Files\Logstash\config\pipelines\dmarcxml.d\logstash.conf".

I just mentioned the -f line in the original post to show that this command did in fact load Logstash even though pipelines was intentionally bypassed in that instance.

My goal is to get logstash to run without the -f, that way multiple pipelines can be used.

In regards to the jvm.options file, it is the out of box file with no changes. It is located here: C:\Program Files\Logstash\config.

These are the other files in the directory:  
jvm.options  
log42j.properties  
logstash.yml  
pipelines.yml  
startup.options

Thanks for the sanity check!

-Tony

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 20, 2018, 8:29pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/7 "2018-03-20T20:29:29Z")

</div>

Hey wwalker,

The jvm.options has not been changed. It is what shipped with Windows logstash variant.

Yep, I want to run Logstash without the -f so, pipelines.yml is not ignored. I was just trying to point out that when I used the -f I could get Logstash to run. Did not mean to introduce confusion.

Here is want shows in the top of jvm.options file. I will admit, I have no clue what lines 6 and 7 do.

1## JVM configuration  
2  
3# Xms represents the initial size of total heap space  
4# Xmx represents the maximum size of total heap space  
5  
6-Xms1g  
7-Xmx1g  
8  
9################################################################  
10## Expert settings  
11################################################################  
12##  
13## All settings below this section are considered  
14## expert settings. Don't tamper with them unless  
15## you understand what you are doing  
16##  
17################################################################

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 20, 2018, 8:30pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/8 "2018-03-20T20:30:13Z")

</div>

Alright, walk us through your startup process. Do you have Logstash installed as a service or just running from a CMD prompt? Regardless of method, are you using any arguments after logstash? What's your pipeline configuration look like?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 20, 2018, 8:46pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/9 "2018-03-20T20:46:10Z")

</div>

> [@Tony\_Chirillo](#):
>
> Hey wwalker,
> 
> The jvm.options has not been changed. It is what shipped with Windows logstash variant.
> 
> Yep, I want to run Logstash without the -f so, pipelines.yml is not ignored. I was just trying to point out that when I used the -f I could get Logstash to run. Did not mean to introduce confusion.
> 
> Here is want shows in the top of jvm.options file. I will admit, I have no clue what lines 6 and 7 do.
> 
> 1## JVM configuration  
> 2  
> 3# Xms represents the initial size of total heap space  
> 4# Xmx represents the maximum size of total heap space  
> 5  
> 6-Xms1g  
> 7-Xmx1g  
> 8  
> 9################################################################  
> 10## Expert settings  
> 11################################################################  
> 12##  
> 13## All settings below this section are considered  
> 14## expert settings. Don't tamper with them unless  
> 15## you understand what you are doing  
> 16##  
> 17################################################################

Does your jvm.optins file have the line numbering as well??

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 20, 2018, 8:46pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/10 "2018-03-20T20:46:36Z")

</div>

Logstash is running from a command prompt, but I will figure out how to install it as a service eventually. No arguments. From C:\Program Files\Logstash\Bin, I run: logstash.bat.

The pipeline.yml file is the default\shipped file with the exception of three lines.

- pipeline.id: pipelinedmarcxml  
path.config: "/Program Files/Logstash/config/pipelines/dmarcxml.d"  
pipeline.workers: 3

I hope it is readable. I attached a screen shot of the modified section of the file.

 ![pipelines](https://us1.discourse-cdn.com/elastic/original/3X/a/c/ac1b942af2a1b4c93e0a46bdaa8922cc392ce9cc.JPG)

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 20, 2018, 8:49pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/11 "2018-03-20T20:49:10Z")

</div>

Does the pipelines folder and dmacxml.d file exist? Looks like you are working off some of the things I did, lol.

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 20, 2018, 8:50pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/12 "2018-03-20T20:50:47Z")

</div>

No. I added them for sanity sake in the forum . Here is a screen shot of the beginning file.

![jvm_options](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f9754ebc97fc3e501e595de2a606f5cf8c0a8d0.JPG)

-Tony

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 20, 2018, 9:03pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/13 "2018-03-20T21:03:21Z")

</div>

Yes, the pipelines folder and dmacxml.d folder exist, with a logstash.conf file in the dmarcxml.d folder.

![pipelines_folder](https://us1.discourse-cdn.com/elastic/original/3X/0/7/07e384b0b5ab56e5e82543d94bbcde49c7d3bf22.JPG)

![dmarcxml](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f34c8dcda7f2fe0be8eac907bc084fe6e98d7e4.JPG)

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 20, 2018, 9:15pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/14 "2018-03-20T21:15:13Z")

</div>

There's our problem. Point config.path to the actual file, not just the directory that it sits in.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [March 20, 2018, 9:16pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/15 "2018-03-20T21:16:40Z")

</div>

Yea, testing it on Linux was much easier, but of course the data originates on windows 🙂

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 20, 2018, 9:47pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/16 "2018-03-20T21:47:19Z")

</div>

I was excited for a second. However, including the file in the path.config did work. I wonder what I am missing - it has to be something silly at this point.

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/8/c/8ce7232b271dd99cc7c1b9c2fade99ec8cbbc824.JPG)

Here are the results from when I execute logstash.bat.

[INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"C:/Program Files/Logstash/modules/fb\_apache/configuration"}  
[INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"C:/Program Files/Logstash/modules/netflow/configuration"}  
[INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"arcsight", :directory=\>"C:/Program Files/Logstash/vendor/bundle/jruby/2.3.0/gems/x-pack-6.2.2-java/modules/arcsight/configuration"}  
[WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.2.2"}  
[INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[WARN][logstash.outputs.elasticsearch] You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch hosts=\>[http://my\_server:9200], bulk\_path=\>"/\_xpack/monitoring/\_bulk?system\_id=logstash&system\_api\_version=2&interval=1s", manage\_template=\>false, document\_type=\>"%{[@metadata][document\_type]}", sniffing=\>false, id=\>"aadba5fcef4344a86d4ff81526835dbfa6bac63c4889322245f69daf37dec289", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_c3275017-4945-4b7d-a280-2783bed76535", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, template\_name=\>"logstash", template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, action=\>"index", ssl\_certificate\_verification=\>true, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}  
[INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>".monitoring-logstash", "pipeline.workers"=\>1, "pipeline.batch.size"=\>2, "pipeline.batch.delay"=\>50}  
[INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[http:/my\_server:9200/]}}  
[INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>http://my\_server:9200/, :path=\>"/"}  
[WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"http://my\_server:9200/"}  
[INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>nil}  
[WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["http://my\_server:9200"]}  
[INFO][logstash.licensechecker.licensereader] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[http://my\_server:9200/]}}  
[INFO][logstash.licensechecker.licensereader] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>http://my\_server:9200/, :path=\>"/"}  
[WARN][logstash.licensechecker.licensereader] Restored connection to ES instance {:url=\>"http://my\_server:9200/"}  
[INFO][logstash.licensechecker.licensereader] ES Output version determined {:es\_version=\>nil}  
[WARN][logstash.licensechecker.licensereader] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[INFO][logstash.pipeline] Pipeline started succesfully {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x15e4937 run\>"}  
[ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 6, column 1 (byte 132) after ## JVM configuration\n\n# Xms represents the initial size of total heap space\n# Xmx represents the maximum size of total heap space\n\n", :backtrace=\>["C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "C:/Program Files/Logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "C:/Program Files/Logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "C:/Program Files/Logstash/logstash-core/lib/logstash/agent.rb:90:in `execute'", "C:/Program Files/Logstash/logstash-core/lib/logstash/runner.rb:348:in`block in execute'", "C:/Program Files/Logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}  
[INFO][logstash.inputs.metrics] Monitoring License OK  
[INFO][logstash.pipeline] Pipeline has terminated {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x15e4937 run\>"}

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [March 20, 2018, 10:17pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/17 "2018-03-20T22:17:04Z")

</div>

The Java _JDK_ is installed?  
JAVA\_HOME system variable is set?  
Are you running from an administrative command prompt?  
Open your config files with Notepad++ and ensure the encoding is set to UTF-8 and NOT UTF-8-BOM.  
I'm kinda grasping at straws here...not really sure where your problem is.

---

<div class="post-metadata">

**Author:** ![Gambit](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gambit/32/26982_2.png) [@Gambit](https://discuss.elastic.co/u/Gambit)\
**Post date:** [March 20, 2018, 11:22pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/18 "2018-03-20T23:22:54Z")

</div>

Try to set the path.config only to /config/pipelines/dmarcxml.d/logstash.conf  
Now from the prompt cd to "program files/logstash" and try to start logstash with "bin/logstash"  
Had a similar problem and it worked for me.

---

<div class="post-metadata">

**Author:** ![Tony\_Chirillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tony_chirillo/32/22647_2.png) [@Tony\_Chirillo](https://discuss.elastic.co/u/Tony_Chirillo)\
**Post date:** [March 21, 2018, 3:12pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/19 "2018-03-21T15:12:22Z")

</div>

This morning, just tinkering with the files. I finally got Logstash to run with the logstash.bat command and use multiple pipelines. Unfortunately, I am not sure what the ah-ha fix was.

Here is the config in the pipelines.yml which is working:

- pipeline.id: pipelinedmarcxml  
path.config: "/program files/logstash/config/pipelines/dmarcxml.d/dmarcpipeline.yml"  
pipeline.workers: 3

The odd thing is that this config did not seem to work until remarked and unremarked this line in the logstash.yml - which does not make sense, at least to me.

xpack.monitoring.elasticsearch.url: "http://my\_server:9200"

Regardless, things work now. Yay!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2018, 3:12pm UTC](https://discuss.elastic.co/t/logstash-on-windows-multiple-pipeline-problem/124846/20 "2018-04-18T15:12:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
