# Logstash + pfsense issues

**URL:** <https://discuss.elastic.co/t/logstash-pfsense-issues/220723>\
**Category:** Logstash\
**Created:** [February 24, 2020, 8:46pm UTC](https://discuss.elastic.co/t/logstash-pfsense-issues/220723 "2020-02-24T20:46:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![artson](https://avatars.discourse-cdn.com/v4/letter/a/ac8455/32.png) [@artson](https://discuss.elastic.co/u/artson)\
**Post date:** [February 24, 2020, 8:46pm UTC](https://discuss.elastic.co/t/logstash-pfsense-issues/220723/1 "2020-02-24T20:46:23Z")

</div>

hi everyone i try to see the logs from pfsense in kibana but i think i miss something with the configuration files, i cant find the index logstash-\* on kibana maybe someone can help with that?  
this is the first file :

#tcp syslog stream via 5140  
input {  
tcp {  
type =\> "syslog"  
port =\> 5140  
}  
}  
#udp syslogs stream via 5044  
input {  
udp {  
type =\> "syslog"  
port =\> 5044  
}  
}

the second file :  
output {  
elasticsearch {  
hosts =\> localhost  
index =\> "logstash -% {+ YYYY.MM.dd}"}

# stdout {codec =\> rubydebug}

```
          } 
   }

```

the third file :  
filter {  
if [type] == "syslog" {  
#change to pfSense ip address  
if [host] =~ /192.168.1.1/ {  
mutate {  
add\_tag =\> ["PFSense", "Ready"]  
}  
}  
if "Ready" not in [tags] {  
mutate {  
add\_tag =\> ["syslog"]  
}  
}  
}  
}  
filter {  
if [type] == "syslog" {  
mutate {  
remove\_tag =\> "Ready"  
}  
}  
}  
filter {  
if "syslog" in [tags] {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
locale =\> "en"  
}  
if !("\_grokparsefailure" in [tags]) {  
mutate {  
replace =\> ["@source\_host", "%{syslog\_hostname}"]  
replace =\> ["@message", "%{syslog\_message}"]  
}  
}  
mutate {  
remove\_field =\> ["syslog\_hostname", "syslog\_message", "syslog\_timestamp"]  
}

# if "\_grokparsefailure" in [tags] {

# drop { }

# }

}  
}

when i try look at logstash-plain.log this what i got :

[2020-02-24T15:43:21,988][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.5.0"}  
[2020-02-24T15:43:24,041][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 129, column 8 (byte 3213) after ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:149:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:90:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:42:in `block in execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:92:in `block in exclusive'", "org/jruby/ext/thread/Mutex.java:148:in `synchronize'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:92:in `exclusive'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:38:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:317:in `block in converge\_state'"]}  
[2020-02-24T15:43:24,358][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

sorry for the long topic appreciate for help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2020, 8:46pm UTC](https://discuss.elastic.co/t/logstash-pfsense-issues/220723/2 "2020-03-23T20:46:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
