# Logstash restarts every 13 seconds

**URL:** <https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955>\
**Category:** Logstash\
**Created:** [June 12, 2022, 11:05am UTC](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955 "2022-06-12T11:05:59Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wang\_Yin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wang_yin/32/106901_2.png) [@Wang\_Yin](https://discuss.elastic.co/u/Wang_Yin)\
**Post date:** [June 12, 2022, 11:05am UTC](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955/1 "2022-06-12T11:05:59Z")

</div>

Hi,

I'm new to ELK, I noticed that the Logstash (version: 8.2.2) restarted every 13 seconds, the log I found in /var/log/logstash/logstash-plain.log suggested that there are some syntax error at line 26 of a certain file, which I couldn't find:

[2022-06-12T13:57:40,154][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "input", "filter", "output" at line 26, column 1 (byte 606) after ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:189:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:48:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:50:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:381:in `block in converge\_state'"]}

It would be greatly appreciated if anyone could shed light on it.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 12, 2022, 2:32pm UTC](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955/2 "2022-06-12T14:32:09Z")

</div>

The error tells that you have a configuration error in one of your configuration files, you need to find the configuration error and fix it.

Please share the contents of `logstash.yml`, `pipelines.yml` and the configuration files that you are using in `pipelines.yml`.

---

<div class="post-metadata">

**Author:** ![Wang\_Yin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wang_yin/32/106901_2.png) [@Wang\_Yin](https://discuss.elastic.co/u/Wang_Yin)\
**Post date:** [June 13, 2022, 1:37pm UTC](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955/3 "2022-06-13T13:37:11Z")

</div>

@leandrojmp Thank you very much for the hint.

I found the issue, there's an additional closing bracket "}" configured in line 26 of the configuration files that's being used in pipelines.yml.

After removing that, the issue is immediately fixed. I have no idea who created that configuration file though.

I'm new to ELK, I am curious about what does pipelines.yml do in logstash, what if I remove that configuration file in /etc/logstash/conf.d/\*.conf (the value of path.config specified in pipelines.yml), will there be any side effects?

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [June 13, 2022, 9:46pm UTC](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955/4 "2022-06-13T21:46:39Z")

</div>

I for one would vote for a feature that made these errors more readable and useful 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 13, 2022, 10:12pm UTC](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955/5 "2022-06-13T22:12:14Z")

</div>

I believe it is doable. See [this](https://github.com/elastic/logstash/issues/14243) issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2022, 10:12pm UTC](https://discuss.elastic.co/t/logstash-restarts-every-13-seconds/306955/6 "2022-07-11T22:12:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
