# Logstash se apaga después de estar ejecutándose unos segundos

**URL:** <https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529>\
**Category:** Logstash\
**Created:** [August 30, 2019, 1:03pm UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529 "2019-08-30T13:03:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![auzin](https://avatars.discourse-cdn.com/v4/letter/a/ac8455/32.png) [@auzin](https://discuss.elastic.co/u/auzin)\
**Post date:** [August 30, 2019, 1:03pm UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/1 "2019-08-30T13:03:39Z")

</div>

Hi,

Every time I try to run logstash with my config file, it shuts down a few seconds after de service is started.

This is my config file:

input{

```
file {
    	path => "E:\DATA\test\*log"
	start_position => "beginning"
  	}

```

}  
#fin de input

filter{

```
if [path] == "E:\DATA\test\bluecoat.log"{
	grok{

	patterns_dir => [".\Pattern\Pattern.txt"]

		match => { "message" => "%{SPACE:date} %{SPACE:time} %{SPACE:time_taken} %{SPACE:c_ip} %{SPACE:cs_username} %{SPACE:cs_auth_group} %{SPACE:x_exception_id} %{SPACE:sc_filter_result} %{QUOTE:cs_categories} %{SPACE:cs_referer} %{SPACE:sc_status} %{SPACE:s_action} %{SPACE:cs_method} %{SPACE:rs_Content_Type} %{SPACE:cs_uri_scheme} %{SPACE:cs_host} %{SPACE:cs_uri_port} %{SPACE:cs_uri_path} %{SPACE:cs-uri-query} %{SPACE:cs_uri_extension} %{SPACE:cs_User_Agent} %{SPACE:s_ip} %{SPACE:sc_bytes} %{SPACE:cs_bytes} %{SPACE:x_virus_id} %{QUOTE:x_bluecoat_application_name} %{QUOTE:x_bluecoat_application_operation} %{SPACE:cs_auth_type} %{SPACE:x_auth_credential_type} %{SPACE:r_ip}" }

	}
	#Fin de grok

	geoip {
  		 source => "s_ip"
		}

}
#Fin de if BC

else if [path] == "E:\DATA\test\q"{

	grok{

	patterns_dir => [".\Pattern\Pattern.txt"]

		match => { "message" => "%{COLUMN:email}:%{SPACE:pass}" }

	}

}
#Fin de if data

if "_grokparsefailure" in [tags] {
drop { }
}

```

}  
#Fin de filter

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

The custom patterns are as follows:

SPACE ([A-Za-z0-9]\S\*|-\S\*|/\S\*)  
QUOTE "[^"]_"  
COLUMN ^[^:]_\s\*

I've tried the --config.test\_and\_exit with the config file, ant it says it is OK.

Could someone help me please?

Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 30, 2019, 1:26pm UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/2 "2019-08-30T13:26:07Z")

</div>

> [@auzin](#):
>
> path =\> "E:\DATA\test\*log"

Use forward slash (or \\) in the path option of a file input.

What do you see in the logstash log when it shuts down?

---

<div class="post-metadata">

**Author:** ![auzin](https://avatars.discourse-cdn.com/v4/letter/a/ac8455/32.png) [@auzin](https://discuss.elastic.co/u/auzin)\
**Post date:** [September 1, 2019, 11:43pm UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/3 "2019-09-01T23:43:10Z")

</div>

I've tried the config file using (, \ and /)but none of those worked. Since I'm on a Windows, I guess it should be either () or (\)

The output of stdout doesn't give me much informatio, right after starting it, the shut down log appears as follows:

[2019-09-02T01:33:08,770][INFO][logstash.agent] Successfully started  
Logstash API endpoint {:port=\>9600}  
[2019-09-02T01:33:14,374][INFO][logstash.runner] Logstash shut down.

---

<div class="post-metadata">

**Author:** ![auzin](https://avatars.discourse-cdn.com/v4/letter/a/ac8455/32.png) [@auzin](https://discuss.elastic.co/u/auzin)\
**Post date:** [September 1, 2019, 11:46pm UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/4 "2019-09-01T23:46:36Z")

</div>

This is what the stdout shows:

C:\Elastic\logstash-7.3.1\>.\bin\logstash -f .\log\_parser\log\_parse.conf  
Java HotSpot(TM) 64-Bit Server VM warning: Option UseConcMarkSweepGC was depreca  
ted in version 9.0 and will likely be removed in a future release.  
WARNING: An illegal reflective access operation has occurred  
WARNING: Illegal reflective access by org.jruby.runtime.encoding.EncodingService  
(file:/C:/Elastic/logstash-7.3.1/logstash-core/lib/jars/jruby-complete-9.2.7.0.  
jar) to field java.io.Console.cs  
WARNING: Please consider reporting this to the maintainers of org.jruby.runtime.  
encoding.EncodingService  
WARNING: Use --illegal-access=warn to enable warnings of further illegal reflect  
ive access operations  
WARNING: All illegal access operations will be denied in a future release  
Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to C:/Elastic/logstash-7.3.1/logs which is now configured  
via log4j2.properties  
[2019-09-02T01:32:55,053][WARN][logstash.config.source.multilocal] Ignoring the  
'pipelines.yml' file because modules or command line options are specified  
[2019-09-02T01:32:55,303][INFO][logstash.runner] Starting Logstash {"  
logstash.version"=\>"7.3.1"}  
[2019-09-02T01:33:05,156][INFO][org.reflections.Reflections] Reflections took 3  
21 ms to scan 1 urls, producing 19 keys and 39 values  
[2019-09-02T01:33:07,527][INFO][logstash.outputs.elasticsearch] Elasticsearch p  
ool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2019-09-02T01:33:07,807][WARN][logstash.outputs.elasticsearch] Restored connec  
tion to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-09-02T01:33:07,860][INFO][logstash.outputs.elasticsearch] ES Output versi  
on determined {:es\_version=\>7}  
[2019-09-02T01:33:07,864][WARN][logstash.outputs.elasticsearch] Detected a 6.x  
and above cluster: the `type` event field won't be used to determine the documen  
t \_type {:es\_version=\>7}  
[2019-09-02T01:33:07,903][INFO][logstash.outputs.elasticsearch] New Elasticsear  
ch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:920](https://localhost:920)  
0"]}  
[2019-09-02T01:33:07,974][INFO][logstash.filters.geoip] Using geoip database  
{:path=\>"C:/Elastic/logstash-7.3.1/vendor/bundle/jruby/2.5.0/gems/logstash-filt  
er-geoip-6.0.1-java/vendor/GeoLite2-City.mmdb"}  
[2019-09-02T01:33:08,264][ERROR][logstash.javapipeline] Pipeline aborted due  
to error {:pipeline\_id=\>"main", :exception=\>#\<Grok::PatternError: pattern %{COL  
UMN:email} not defined\>, :backtrace=\>["C:/Elastic/logstash-7.3.1/vendor/bundle/j  
ruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:123:in `block in compile'", "or g/jruby/RubyKernel.java:1425:in`loop'", "C:/Elastic/logstash-7.3.1/vendor/bundl  
e/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:93:in `compile'", "C:/Elasti c/logstash-7.3.1/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.1.1/lib/l ogstash/filters/grok.rb:274:in`block in register'", "org/jruby/RubyArray.java:1  
792:in `each'", "C:/Elastic/logstash-7.3.1/vendor/bundle/jruby/2.5.0/gems/logsta sh-filter-grok-4.1.1/lib/logstash/filters/grok.rb:268:in`block in register'", "  
org/jruby/RubyHash.java:1419:in `each'", "C:/Elastic/logstash-7.3.1/vendor/bundl e/jruby/2.5.0/gems/logstash-filter-grok-4.1.1/lib/logstash/filters/grok.rb:263:i n`register'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:  
56:in `register'", "C:/Elastic/logstash-7.3.1/logstash-core/lib/logstash/java_pi peline.rb:192:in`block in register\_plugins'", "org/jruby/RubyArray.java:1792:in  
`each'", "C:/Elastic/logstash-7.3.1/logstash-core/lib/logstash/java_pipeline.rb :191:in`register\_plugins'", "C:/Elastic/logstash-7.3.1/logstash-core/lib/logsta  
sh/java\_pipeline.rb:463:in `maybe_setup_out_plugins'", "C:/Elastic/logstash-7.3. 1/logstash-core/lib/logstash/java_pipeline.rb:204:in`start\_workers'", "C:/Elast  
ic/logstash-7.3.1/logstash-core/lib/logstash/java\_pipeline.rb:146:in `run'", "C: /Elastic/logstash-7.3.1/logstash-core/lib/logstash/java_pipeline.rb:105:in`bloc  
k in start'"], :thread=\>"#\<Thread:0x7ba0a10b run\>"}  
[2019-09-02T01:33:07,966][INFO][logstash.outputs.elasticsearch] Using default m  
apping template  
[2019-09-02T01:33:08,347][INFO][logstash.outputs.elasticsearch] Attempting to i  
nstall template {:manage\_template=\>{"index\_patterns"=\>"logstash-_", "version"=\>6  
0001, "settings"=\>{"index.refresh\_interval"=\>"5s", "number\_of\_shards"=\>1, "index  
.lifecycle.name"=\>"logstash-policy", "index.lifecycle.rollover\_alias"=\>"logstash  
"}, "mappings"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message  
", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}  
, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"  
type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore  
\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{  
"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip  
"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "long  
itude"=\>{"type"=\>"half\_float"}}}}}}}  
[2019-09-02T01:33:08,359][ERROR][logstash.agent] Failed to execute ac  
tion {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message  
=\>"Could not execute action: PipelineAction::Create, action\_result: false"  
, :backtrace=\>nil}  
[2019-09-02T01:33:08,770][INFO][logstash.agent] Successfully started  
Logstash API endpoint {:port=\>9600}  
[2019-09-02T01:33:14,374][INFO][logstash.runner] Logstash shut down.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 2, 2019, 12:18pm UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/5 "2019-09-02T12:18:32Z")

</div>

> [@auzin](#):
>
> Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<Grok::PatternError: pattern %{COLUMN:email} not defined\>

It is not finding the definition of COLUMN. Are you using a file or

```
 pattern_definitions => {
      "SPACE" => "([A-Za-z0-9]\S*|-\S*|/\S*)"
      "QUOTE" => '"[^"] "'
      "COLUMN" => "^[^:]\s*"
 }

```

---

<div class="post-metadata">

**Author:** ![auzin](https://avatars.discourse-cdn.com/v4/letter/a/ac8455/32.png) [@auzin](https://discuss.elastic.co/u/auzin)\
**Post date:** [September 4, 2019, 3:02am UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/6 "2019-09-04T03:02:04Z")

</div>

I was indeed using a file, but I tried with pattern\_definitions, and logstash does not shut down after starting it anymore.

But it looks like it doesn't read the logs from the files it should be reading.

This is my current config file:

input{

```
file {
    	path => "E:\\DATA\test\*.log"
	start_position => "beginning"
  	}

```

}

filter{

```
if [path] == "E:\\DATA\\test\\bluecoat.log"{
	grok{

		match => { "message" => "%{SPACE:date} %{SPACE:time} %{SPACE:time_taken} %{SPACE:c_ip} %{SPACE:cs_username} %{SPACE:cs_auth_group} %{SPACE:x_exception_id} %{SPACE:sc_filter_result} %{QUOTE:cs_categories} %{SPACE:cs_referer} %{SPACE:sc_status} %{SPACE:s_action} %{SPACE:cs_method} %{SPACE:rs_Content_Type} %{SPACE:cs_uri_scheme} %{SPACE:cs_host} %{SPACE:cs_uri_port} %{SPACE:cs_uri_path} %{SPACE:cs-uri-query} %{SPACE:cs_uri_extension} %{QUOTE:cs_User_Agent} %{SPACE:s_ip} %{SPACE:sc_bytes} %{SPACE:cs_bytes} %{SPACE:x_virus_id} %{QUOTE:x_bluecoat_application_name} %{QUOTE:x_bluecoat_application_operation} %{SPACE:cs_auth_type} %{SPACE:x_auth_credential_type} %{SPACE:r_ip}" }

		pattern_definitions => {
      			"SPACE" => "([A-Za-z0-9]\S*|-\S*|/\S*)"
  				"QUOTE" => '"[^"] "'
  				"COLUMN" => "^[^:]\s*"
    		}

	}

	geoip {
  		 source => "s_ip"
		}

}

else if [path] == "E:\\DATA\\test\\q"{

	grok{

		match => { "message" => "%{COLUMN:email}:%{SPACE:pass}" }

		pattern_definitions => {
      			"SPACE" => "([A-Za-z0-9]\S*|-\S*|/\S*)"
  				"QUOTE" => '("[^"] "|-\S*)'
  				"COLUMN" => "^[^:]\s*"
    		}

	}
}

if "_grokparsefailure" in [tags] {
drop { }
}

```

}

output {

```
elasticsearch { hosts => ["localhost:9200"] }
	stdout { codec => rubydebug }

```

}

I tried using (\) on the file paths, but then it gives me the following error.

Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<ArgumentError: File paths must be absolute, relative path specified: E:\DATA\test\bluecoat.log\>

Any suggestions?

Thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 4, 2019, 1:02pm UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/7 "2019-09-04T13:02:41Z")

</div>

Use forward slash, not backslash, in the path option of a file input on Windows.

---

<div class="post-metadata">

**Author:** ![auzin](https://avatars.discourse-cdn.com/v4/letter/a/ac8455/32.png) [@auzin](https://discuss.elastic.co/u/auzin)\
**Post date:** [September 5, 2019, 12:19am UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/8 "2019-09-05T00:19:38Z")

</div>

Yeah that fixed it.

Everithing is correct now.

Thanks for the support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2019, 12:19am UTC](https://discuss.elastic.co/t/logstash-se-apaga-despues-de-estar-ejecutandose-unos-segundos/197529/9 "2019-10-03T00:19:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
