# Logstash startup issue

**URL:** <https://discuss.elastic.co/t/logstash-startup-issue/128635>\
**Category:** Logstash\
**Created:** [April 19, 2018, 6:35am UTC](https://discuss.elastic.co/t/logstash-startup-issue/128635 "2018-04-19T06:35:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Monica1](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Monica1](https://discuss.elastic.co/u/Monica1)\
**Post date:** [April 19, 2018, 6:35am UTC](https://discuss.elastic.co/t/logstash-startup-issue/128635/1 "2018-04-19T06:35:28Z")

</div>

we are having issue in starting up logstash stating Couldn't find any filter plugin 'grok'..Please find the error logs below.  
[2018-04-18T13:06:32,281][ERROR][logstash.plugins.registry] Tried to load a plugin's code, but failed. {:exception=\>#\<LoadError: no such file to load -- logstash/filters/Grok\>, :path=\>"logstash/filters/Grok", :type=\>"filter", :name=\>"Grok"}  
[2018-04-18T13:06:32,287][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::PluginLoadingError", :message=\>"Couldn't find any filter plugin named 'Grok'. Are you sure this is correct? Trying to load the Grok filter plugin resulted in this error: no such file to load -- logstash/filters/Grok", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/plugins/registry.rb:192:in `lookup_pipeline_plugin'", "/usr/share/logstash/logstash-core/lib/logstash/plugin.rb:140:in`lookup'", "/usr/share/logstash/logstash-core/lib/logstash/plugins/plugin\_factory.rb:81:in `plugin'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:112:in`plugin'", "(eval):636:in `<eval>'", "org/jruby/RubyKernel.java:994:in`eval'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:84:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:169:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:40:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:315:in`block in converge\_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:312:in`block in converge\_state'", "org/jruby/RubyArray.java:1734:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:299:in`converge\_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:166:in `block in converge_state_and_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:164:in `converge_state_and_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:90:in`execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:348:in `block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in`block in initialize'"]}

Can you please help me in resolving this error

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 19, 2018, 6:54am UTC](https://discuss.elastic.co/t/logstash-startup-issue/128635/2 "2018-04-19T06:54:56Z")

</div>

Logstash plugin names are case-sensitive. Does your pipeline configuration reference `Grok`? The correct form is `grok`.

---

<div class="post-metadata">

**Author:** ![Monica1](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Monica1](https://discuss.elastic.co/u/Monica1)\
**Post date:** [April 19, 2018, 7:03am UTC](https://discuss.elastic.co/t/logstash-startup-issue/128635/3 "2018-04-19T07:03:07Z")

</div>

how can i check the pipeline configuration ? is it the one available under /etc/logstash/conf.d/logstash.conf file filter section?

or i have to refer to any plugin directory?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 19, 2018, 7:04am UTC](https://discuss.elastic.co/t/logstash-startup-issue/128635/4 "2018-04-19T07:04:21Z")

</div>

The pipeline configuration is the file in which you define your pipeline, with inputs, filters, and outputs.

---

<div class="post-metadata">

**Author:** ![Monica1](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@Monica1](https://discuss.elastic.co/u/Monica1)\
**Post date:** [April 19, 2018, 7:13am UTC](https://discuss.elastic.co/t/logstash-startup-issue/128635/5 "2018-04-19T07:13:50Z")

</div>

ok got it.this is the place /etc/logstash/conf.d/logstash.conf where i have defined inputs, filters and output block.

I will try to check in this file,But incase if i have used only lower case grok pattern here, then what could be the issue ?any idea?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 19, 2018, 4:07pm UTC](https://discuss.elastic.co/t/logstash-startup-issue/128635/6 "2018-04-19T16:07:04Z")

</div>

Please paste your pipeline configuration if you are able.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 17, 2018, 4:07pm UTC](https://discuss.elastic.co/t/logstash-startup-issue/128635/7 "2018-05-17T16:07:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
