# Logstash stops with error: can't convert Array into String

**URL:** <https://discuss.elastic.co/t/logstash-stops-with-error-cant-convert-array-into-string/92974>\
**Category:** Logstash\
**Created:** [July 13, 2017, 9:28am UTC](https://discuss.elastic.co/t/logstash-stops-with-error-cant-convert-array-into-string/92974 "2017-07-13T09:28:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![desai.amogh](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@desai.amogh](https://discuss.elastic.co/u/desai.amogh)\
**Post date:** [July 13, 2017, 9:28am UTC](https://discuss.elastic.co/t/logstash-stops-with-error-cant-convert-array-into-string/92974/1 "2017-07-13T09:28:40Z")

</div>

Logstast stops in few minutes with following error:

```
Sudo -u logstash /opt/logstash/bin/logstash -f /etc/logstash/conf.d/
    slack plugin is using the 'milestone' method to declare the version of the plugin this method is deprecated in favor of declaring the version inside the gemspec. {:level=>:warn}
    Settings: Default pipeline workers: 2
    Defaulting pipeline worker threads to 1 because there are some filters that might not work with multiple worker threads {:count_was=>2, :filters=>["multiline"], :level=>:warn}
    Logstash startup completed

 Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {"exception"=>#<TypeError: can't convert Array into String>, "backtrace"=>["org/jruby/RubyString.java:4462:in `include?'", "(eval):226:in `cond_func_6'", "org/jruby/RubyArray.jav`each'", "(eval):224:in `cond_func_6'", "(eval):241:in `cond_func_5'","org/jruby/RubyArray.java:1613:in `each'", "(eval):238:in `cond_func_5'", "(eval):147:in `filter_func'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:259:in `filter_batch'", "org/jruby/RubyArray.java:1613:in `each'","org/jruby/RubyEnumerable.java:852:in `inject'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:257:in `filter_batch'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:215:in `worker_loop'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:193:in `start_workers'"], :level=>:error}
TypeError: can't convert Array into String
       include? at org/jruby/RubyString.java:4462
    cond_func_6 at (eval):226
           each at org/jruby/RubyArray.java:1613
    cond_func_6 at (eval):224
    cond_func_5 at (eval):241
           each at org/jruby/RubyArray.java:1613
    cond_func_5 at (eval):238
    filter_func at (eval):147
   filter_batch at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2. 4-java/lib/logstash/pipeline.rb:259
           each at org/jruby/RubyArray.java:1613
         inject at org/jruby/RubyEnumerable.java:852
   filter_batch at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2. 4-java/lib/logstash/pipeline.rb:257
    worker_loop at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2. 4-java/lib/logstash/pipeline.rb:215
  start_workers at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2. 4-java/lib/logstash/pipeline.rb:193

```

My Filter is here:

```
filter {
    multiline {
        pattern => "^%{TIMESTAMP_ISO8601}"
        negate => true
        what => previous
    }

    grok {
        match => ["message", "%{TIMESTAMP_ISO8601} Thread:'(?<thread>[^']+)' Level:'%{LOGLEVEL:log-level}' Message:%{GREEDYDATA:information}"]
        tag_on_failure => ["error_message_not_parsed"]
        remove_field => ["message"]
        break_on_match => false
    }

   if [type] == "SomeServer1-Prod" or [type] == "SomeServer1-Dev" or [type] == "SomeServer2-Dev" or [type] == "SomeServer2-Prod"
    {

        if ["ERROR", "error"] in [log-level]
         {
          mutate
           {
            add_tag => ["alert"]
           }
         }
    }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 13, 2017, 9:31am UTC](https://discuss.elastic.co/t/logstash-stops-with-error-cant-convert-array-into-string/92974/2 "2017-07-13T09:31:36Z")

</div>

Can you please copy/paste the whole lines from the log? Some of the lines are truncated.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 13, 2017, 9:33am UTC](https://discuss.elastic.co/t/logstash-stops-with-error-cant-convert-array-into-string/92974/3 "2017-07-13T09:33:12Z")

</div>

Do not use the multiline filter as it has been deprecated. Instead use the multiline codec plugin.

---

<div class="post-metadata">

**Author:** ![desai.amogh](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@desai.amogh](https://discuss.elastic.co/u/desai.amogh)\
**Post date:** [July 13, 2017, 9:40am UTC](https://discuss.elastic.co/t/logstash-stops-with-error-cant-convert-array-into-string/92974/4 "2017-07-13T09:40:35Z")

</div>

`:message=>"Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash.", "exception"=>#<TypeError: can't convert Array into String>, "backtrace"=>["org/jruby/RubyString.java:4462:in`include?'", "(eval):226:in `cond_func_6'", "org/jruby/RubyArray.java:1613:in`each'", "(eval):224:in `cond_func_6'", "(eval):241:in`cond\_func\_5'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):238:in`cond\_func\_5'", "(eval):147:in `filter_func'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:259:in`filter\_batch'", "org/jruby/RubyArray.java:1613:in `each'", "org/jruby/RubyEnumerable.java:852:in`inject'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:257:in `filter_batch'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:215:in`worker\_loop'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:193:in `start_workers'"], :level=>:error}`

---

<div class="post-metadata">

**Author:** ![desai.amogh](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@desai.amogh](https://discuss.elastic.co/u/desai.amogh)\
**Post date:** [July 13, 2017, 10:20am UTC](https://discuss.elastic.co/t/logstash-stops-with-error-cant-convert-array-into-string/92974/5 "2017-07-13T10:20:59Z")

</div>

I Disabled the multiline filter and it stopped shuttingdown with the above error. Now it stops on the below filter:  
Specifically on the if statement.  
If there is a log generated from "SomeServer1-Prod" with log-level "ERROR"

```
filter {
    grok {
        match => ["message", "%{TIMESTAMP_ISO8601} Thread:'(?<thread>[^']+)' Level:'%{LOGLEVEL:log-level}' Message:%{GREEDYDATA:information}"]
        tag_on_failure => ["error_message_not_parsed"]
        remove_field => ["message"]
        break_on_match => false
    }

   if [type] == "SomeServer1-Prod" or [type] == "SomeServer1-Dev" or [type] == "SomeServer2-Dev" or [type] == "SomeServer2-Prod"
    {

        if ["ERROR", "error"] in [log-level]
         {
          mutate
           {
            add_tag => ["alert"]
           }
         }
    }
}

```

Error is here:

```
> Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {"exception"=>#<TypeError: can't convert Array into String>, "backtrace"=>["org/jruby/RubyString.java:4462:in `include?'", "(eval):170:in `cond_func_4'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):168:in `cond_func_4'", "(eval):185:in `cond_func_3'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):182:in `cond_func_3'", "(eval):119:in `filter_func'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:259:in `filter_batch'", "org/jruby/RubyArray.java:1613:in `each'", "org/jruby/RubyEnumerable.java:852:in `inject'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:257:in `filter_batch'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:215:in `worker_loop'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:193:in `start_workers'"], :level=>:error}
> TypeError: can't convert Array into String
> include? at org/jruby/RubyString.java:4462
> cond_func_4 at (eval):170
> each at org/jruby/RubyArray.java:1613
> cond_func_4 at (eval):168
> cond_func_3 at (eval):185
> each at org/jruby/RubyArray.java:1613
> cond_func_3 at (eval):182
> filter_func at (eval):119
> filter_batch at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:259
> each at org/jruby/RubyArray.java:1613
> inject at org/jruby/RubyEnumerable.java:852
> filter_batch at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:257
> worker_loop at /opt/logPreformatted textstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:215
> start_workers at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.2.4-java/lib/logstash/pipeline.rb:193
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 10:21am UTC](https://discuss.elastic.co/t/logstash-stops-with-error-cant-convert-array-into-string/92974/6 "2017-08-10T10:21:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
