# Logstash Stopping Pipeline

**URL:** <https://discuss.elastic.co/t/logstash-stopping-pipeline/62858>\
**Category:** Logstash\
**Created:** [October 12, 2016, 7:53pm UTC](https://discuss.elastic.co/t/logstash-stopping-pipeline/62858 "2016-10-12T19:53:20Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrognone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrognone/32/16034_2.png) [@mrognone](https://discuss.elastic.co/u/mrognone)\
**Post date:** [October 12, 2016, 7:53pm UTC](https://discuss.elastic.co/t/logstash-stopping-pipeline/62858/1 "2016-10-12T19:53:21Z")

</div>

Hi Guys ,

two days ago one of my logstash servers crash with Logstash service.  
the error recieved is `:message=>"stopping pipeline", :id=>"main"`

The configuration file is the following:

```
input {
    udp {
      port => 9933
        codec => netflow {
        versions => [9]
      }
    }
}

filter {

if [host] == "xxxxxx" {
  grok {
    match => { "host" => "xxxxxxxxx" }
  }

geoip {
 add_tag => ["geoip"]
 database => "/opt/logstash/vendor/geoip/GeoLiteCity.dat" ### Change me to location of GeoLiteCity.dat file
 source => "ipv4_dst_addr"
 }

 if [geoip][city_name] == "" { mutate { remove_field => "[geoip][city_name]" } }
 if [geoip][continent_code] == "" { mutate { remove_field => "[geoip][continent_code]" } }
 if [geoip][country_code2] == "" { mutate { remove_field => "[geoip][country_code2]" } }
 if [geoip][country_code3] == "" { mutate { remove_field => "[geoip][country_code3]" } }
 if [geoip][country_name] == "" { mutate { remove_field => "[geoip][country_name]" } }
 if [geoip][latitude] == "" { mutate { remove_field => "[geoip][latitude]" } }
 if [geoip][longitude] == "" { mutate { remove_field => "[geoip][longitude]" } }
 if [geoip][postal_code] == "" { mutate { remove_field => "[geoip][postal_code]" } }
 if [geoip][region_name] == "" { mutate { remove_field => "[geoip][region_name]" } }
 if [geoip][time_zone] == "" { mutate { remove_field => "[geoip][time_zone]" } }

}
}

output {
 if [host] == "xxxxxxxx" {
   stdout { codec => rubydebug }
   elasticsearch {
         manage_template => false
        index => "xxxxxxxa%{+YYYY.MM.dd}"
        hosts => "xxxxxxxxxxl:9200"
}
   }
}

```

I detected that if i take out Filter section in this conf logstash work ok. for that reason I checked the plugins installed and i saw that " grok " & " geoip " are installed.

I`m not a programmer, I googled the error but i not saw nothing about this specific plugins/filters.

Can someone help me with this ??

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Tim\_Archambault](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_archambault/32/14316_2.png) [@Tim\_Archambault](https://discuss.elastic.co/u/Tim_Archambault)\
**Post date:** [January 4, 2017, 8:37pm UTC](https://discuss.elastic.co/t/logstash-stopping-pipeline/62858/2 "2017-01-04T20:37:39Z")

</div>

DId you figure this out? Having the same issue. Thanks.

---

<div class="post-metadata">

**Author:** ![wenpos](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wenpos/32/15326_2.png) [@wenpos](https://discuss.elastic.co/u/wenpos)\
**Post date:** [January 5, 2017, 3:30am UTC](https://discuss.elastic.co/t/logstash-stopping-pipeline/62858/3 "2017-01-05T03:30:13Z")

</div>

Any eror logs available? Could you provide the message format to grok and regular expression used in grok？

---

<div class="post-metadata">

**Author:** ![mrognone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrognone/32/16034_2.png) [@mrognone](https://discuss.elastic.co/u/mrognone)\
**Post date:** [January 5, 2017, 12:52pm UTC](https://discuss.elastic.co/t/logstash-stopping-pipeline/62858/4 "2017-01-05T12:52:16Z")

</div>

Hi Tim, good morning.

Yes I did figure out this issue.  
In this particular case I found more logs about plugin erros, like grok, mutate, among others, all errors related about incompatibilities. So, I updated some plugins using [rubygems.org](http://rubygems.org). was difficult for me because I didn't know how to update the gems and never work with ruby. But after some shoots logstash came back from the dead.

---

<div class="post-metadata">

**Author:** ![Tim\_Archambault](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tim_archambault/32/14316_2.png) [@Tim\_Archambault](https://discuss.elastic.co/u/Tim_Archambault)\
**Post date:** [January 5, 2017, 5:58pm UTC](https://discuss.elastic.co/t/logstash-stopping-pipeline/62858/5 "2017-01-05T17:58:04Z")

</div>

Great. My logstash install somehow was missing a config folder and I finally figured it out. Like you, these tools are new to me so it was a process for sure. Best of luck. TIm

---

<div class="post-metadata">

**Author:** ![mrognone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrognone/32/16034_2.png) [@mrognone](https://discuss.elastic.co/u/mrognone)\
**Post date:** [January 5, 2017, 6:10pm UTC](https://discuss.elastic.co/t/logstash-stopping-pipeline/62858/6 "2017-01-05T18:10:42Z")

</div>

I'm glad to know that you can resolve the issue Tim.  
If i can help you with something more, please let me know. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:29am UTC](https://discuss.elastic.co/t/logstash-stopping-pipeline/62858/7 "2017-07-06T04:29:32Z")

</div>


