# Logstash start error!

**URL:** <https://discuss.elastic.co/t/logstash-start-error/168973>\
**Category:** Logstash\
**Created:** [February 19, 2019, 9:16am UTC](https://discuss.elastic.co/t/logstash-start-error/168973 "2019-02-19T09:16:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![9129b75705fb87ec814a](https://avatars.discourse-cdn.com/v4/letter/9/eb8c5e/32.png) [@9129b75705fb87ec814a](https://discuss.elastic.co/u/9129b75705fb87ec814a)\
**Post date:** [February 19, 2019, 9:16am UTC](https://discuss.elastic.co/t/logstash-start-error/168973/1 "2019-02-19T09:16:31Z")

</div>

i try to start logstash with config file but it can't work

ERROR:  
[2019-02-19T16:59:48,269][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError"  
, :message=\>"Expected one of #, input, filter, output at line 3, column 1 (byte 76) after ", :backtrace=\>["/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'" , "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/compiler.rb:49:in`compile\_graph'", "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'" , "org/jruby/RubyArray.java:2486:in`map'", "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:149:in`initialize'"  
, "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/pipeline.rb:22:in `initialize'", "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/pipeline.rb:90:in`initialize'"  
, "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/pipeline\_action/create.rb:42:in `block in execute'", "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/agent.rb:92:in`block in exclusive'"  
, "org/jruby/ext/thread/Mutex.java:148:in `synchronize'", "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/agent.rb:92:in`exclusive'"  
, "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/pipeline\_action/create.rb:38:in `execute'", "/home/zhenqinghe/elk/logstash-6.6.0/logstash-core/lib/logstash/agent.rb:317:in`block in converge\_state'"]}

my conf file :  
input {  
file {  
path =\> ["/home/zhenqinghe/elk/testlog/\*.log"]  
type =\> "kettle\_log"  
start\_position =\> "beginning"  
}  
}

filter {  
grok {  
patterns\_dir =\> ["/home/zhenqinghe/elk/logstash-6.6.0/config/patterns"]  
match =\> {  
"message" =\> ["%{KETTLE\_DATE}:kettle\_date"]  
}  
}

```
date {
    match => ["kettle_date", "dd/MMM/yyyy:HH:mm:ss Z"]
}

```

}

output {  
file {  
path =\> "/home/zhenqinghe/elk/resultlog/%{host}.log"  
message\_format =\> "%{message}"  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 19, 2019, 1:09pm UTC](https://discuss.elastic.co/t/logstash-start-error/168973/2 "2019-02-19T13:09:14Z")

</div>

That configuration would not generate that error. Do you have any other files in the directory that contains the configuration? If you point -f at a directory then logstash will concatenate all the files in the directory to create the configuration.

```
"message" => ["%{KETTLE_DATE}:kettle_date"]

```

If you want to capture the string that matches the KETTLE\_DATE pattern then that should be

```
"message" => ["%{KETTLE_DATE:kettle_date}"]

```

This is not valid either. If you want to specify the format you would use the codec option on the output.

```
message_format => "%{message}"
```

---

<div class="post-metadata">

**Author:** ![9129b75705fb87ec814a](https://avatars.discourse-cdn.com/v4/letter/9/eb8c5e/32.png) [@9129b75705fb87ec814a](https://discuss.elastic.co/u/9129b75705fb87ec814a)\
**Post date:** [February 21, 2019, 3:09am UTC](https://discuss.elastic.co/t/logstash-start-error/168973/4 "2019-02-21T03:09:03Z")

</div>

Thanks for you help!

if i have own patterns file , I just need to add patterns\_dir in configuration file ？  
like:

patterns\_dir =\> ["/home/zhenqinghe/elk/logstash-6.6.0/config/patterns"]

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2019, 1:12pm UTC](https://discuss.elastic.co/t/logstash-start-error/168973/5 "2019-02-21T13:12:22Z")

</div>

That is correct.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2019, 1:12pm UTC](https://discuss.elastic.co/t/logstash-start-error/168973/6 "2019-03-21T13:12:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
