# Logstash: Weblogic: Filebeat : Issues while starting the Logstash

**URL:** <https://discuss.elastic.co/t/logstash-weblogic-filebeat-issues-while-starting-the-logstash/154041>\
**Category:** Logstash\
**Created:** [October 25, 2018, 4:06pm UTC](https://discuss.elastic.co/t/logstash-weblogic-filebeat-issues-while-starting-the-logstash/154041 "2018-10-25T16:06:39Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shashidhar\_Wl](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Shashidhar\_Wl](https://discuss.elastic.co/u/Shashidhar_Wl)\
**Post date:** [October 25, 2018, 4:06pm UTC](https://discuss.elastic.co/t/logstash-weblogic-filebeat-issues-while-starting-the-logstash/154041/1 "2018-10-25T16:06:39Z")

</div>

Hi,

I am trying to configure ELK with Weblogic logs. where i am getting the plug in registering issues. when i do config test it returns configuration looks good but when i start it is not starting.

./logstash --config.test\_and\_exit -f weblogic-logstash-pipeline.conf  
Sending Logstash logs to /u01/logstash/logs which is now configured via log4j2.properties  
[2018-10-25T12:00:21,724][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
Configuration OK  
[2018-10-25T12:00:31,875][INFO][logstash.runner] Using config.test\_and\_exit mode. Config Validation Result: OK. Exiting Logstash

Error :

./logstash -f weblogic-logstash-pipeline.conf --config.reload.automatic

Sending Logstash logs to /u01/logstash/logs which is now configured via log4j2.properties  
[2018-10-25T12:05:36,732][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-10-25T12:05:37,432][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.4.2"}  
[2018-10-25T12:05:48,513][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2018-10-25T12:05:49,148][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-10-25T12:05:49,164][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-10-25T12:05:49,401][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2018-10-25T12:05:49,464][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-10-25T12:05:49,474][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-10-25T12:05:49,515][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost:9200](https://localhost:9200)"]}  
[2018-10-25T12:05:49,547][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-10-25T12:05:49,587][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-10-25T12:05:49,771][ERROR][logstash.pipeline] Error registering plugin {:pipeline\_id=\>"main", :plugin=\>"#\<LogStash::FilterDelegator:0x5752e034 @metric\_events\_out=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: out value:0, @metric\_events\_in=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: in value:0, @metric\_events\_time=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: duration\_in\_millis value:0, @id="4f5f2bd9cdf0a0a1e22d07068c0299b6e3979ed0b8c38b53ea1baf82bad2d9a3", @klass=LogStash::Filters::Grok, @metric\_events=#LogStash::Instrument::NamespacedMetric:0x358cd7cd, @filter=\<LogStash::Filters::Grok patterns\_dir=\>["./patterns"], match=\>{"message"=\>"####\<%{WLS\_SERVERLOG\_DATE:wls\_timestamp}%{SPACE}%{DATA:wls\_timezone}\>%{SPACE}\<%{LOGLEVEL:wls\_level}\>%{SPACE}\<%{DATA:wls\_subsystem}\>%{SPACE}\<%{DATA:wls\_host}\>%{SPACE}\<%{DATA:wls\_server}\>%{SPACE}\<%{DATA:wls\_thread}\>%{SPACE}\<([\<\>a-zA-Z]_)\>%{SPACE}\<%{DATA:wls\_transactionid}\>%{SPACE}\<%{DATA:wls\_diagcontid}\>%{SPACE}\<%{DATA:wls\_rawtime}\>%{SPACE}\<%{DATA:wls\_code}\>%{SPACE}\<%{GREEDYDATA:wls\_message}"}, id=\>"4f5f2bd9cdf0a0a1e22d07068c0299b6e3979ed0b8c38b53ea1baf82bad2d9a3", enable\_metric=\>true, periodic\_flush=\>false, patterns\_files\_glob=\>"_", break\_on\_match=\>true, named\_captures\_only=\>true, keep\_empty\_captures=\>false, tag\_on\_failure=\>["\_grokparsefailure"], timeout\_millis=\>30000, tag\_on\_timeout=\>"\_groktimeout"\>\>", :error=\>"pattern %{WLS\_SERVERLOG\_DATE:wls\_timestamp} not defined", :thread=\>"#\<Thread:0x52ac15d2 run\>"}  
[2018-10-25T12:05:49,777][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<Grok::PatternError: pattern %{WLS\_SERVERLOG\_DATE:wls\_timestamp} not defined\>, :backtrace=\>["/u01/logstash/vendor/bundle/jruby/2.3.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:123:in `block in compile'", "org/jruby/RubyKernel.java:1292:in`loop'", "/u01/logstash/vendor/bundle/jruby/2.3.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:93:in `compile'", "/u01/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.3/lib/logstash/filters/grok.rb:281:in`block in register'", "org/jruby/RubyArray.java:1734:in `each'", "/u01/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.3/lib/logstash/filters/grok.rb:275:in`block in register'", "org/jruby/RubyHash.java:1343:in `each'", "/u01/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.3/lib/logstash/filters/grok.rb:270:in`register'", "/u01/logstash/logstash-core/lib/logstash/pipeline.rb:242:in `register_plugin'", "/u01/logstash/logstash-core/lib/logstash/pipeline.rb:253:in`block in register\_plugins'", "org/jruby/RubyArray.java:1734:in `each'", "/u01/logstash/logstash-core/lib/logstash/pipeline.rb:253:in`register\_plugins'", "/u01/logstash/logstash-core/lib/logstash/pipeline.rb:595:in `maybe_setup_out_plugins'", "/u01/logstash/logstash-core/lib/logstash/pipeline.rb:263:in`start\_workers'", "/u01/logstash/logstash-core/lib/logstash/pipeline.rb:200:in `run'", "/u01/logstash/logstash-core/lib/logstash/pipeline.rb:160:in`block in start'"], :thread=\>"#\<Thread:0x52ac15d2 run\>"}  
[2018-10-25T12:05:49,797][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}  
[2018-10-25T12:05:50,129][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![Shashidhar\_Wl](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Shashidhar\_Wl](https://discuss.elastic.co/u/Shashidhar_Wl)\
**Post date:** [October 25, 2018, 4:07pm UTC](https://discuss.elastic.co/t/logstash-weblogic-filebeat-issues-while-starting-the-logstash/154041/2 "2018-10-25T16:07:30Z")

</div>

config file :  
input {  
beats {  
port =\> "5400"  
ssl =\> true  
ssl\_certificate\_authorities =\> ["/u01/SSL/elk-ssl.crt"]  
ssl\_certificate =\> "/u01/SSL/elk-ssl.crt"  
ssl\_key =\> "/u01/SSL/elk-ssl.key"  
ssl\_verify\_mode =\> "force\_peer"  
}  
}

filter {

if "weblogic-server-log" in [tags] {  
grok {  
patterns\_dir =\> "./patterns"  
match =\> ["message", "####\<%{WLS\_SERVERLOG\_DATE:wls\_timestamp}%{SPACE}%{DATA:wls\_timezone}\>%{SPACE}\<%{LOGLEVEL:wls\_level}\>%{SPACE}\<%{DATA:wls\_subsystem}\>%{SPACE}\<%{DATA:wls\_host}\>%{SPACE}\<%{DATA:wls\_server}\>%{SPACE}\<%{DATA:wls\_thread}\>%{SPACE}\<([\<\>a-zA-Z]\*)\>%{SPACE}\<%{DATA:wls\_transactionid}\>%{SPACE}\<%{DATA:wls\_diagcontid}\>%{SPACE}\<%{DATA:wls\_rawtime}\>%{SPACE}\<%{DATA:wls\_code}\>%{SPACE}\<%{GREEDYDATA:wls\_message}" ]  
}  
# CEST does not exist in JODA-TIME, changed to CET  
translate {  
field =\> 'wls\_timezone'  
destination =\> 'wls\_timezone'  
fallback =\> '%{wls\_timezone}'  
override =\> "true"  
dictionary =\> [  
'CEST', 'CET'  
]  
}  
date {  
match =\> ["wls\_timestamp", "dd-MMM-yyyy HH'H'mm'''"]  
locale =\> "es-ES"  
timezone =\> "%{wls\_timezone}"  
target =\> "wls\_timestamp"  
}  
mutate {  
remove\_field =\> ['wls\_timezone' , 'message']  
}  
}

if "weblogic-access-log" in [tags] {  
grok {  
patterns\_dir=\>"./patterns"  
match =\> ["message", "%{ACCESSDATE:acc\_date}\s+%{TIME:acc\_time}\s+%{WORD:acc\_verb}\s+%{DATA:acc\_transactionid}\s+%{DATA:acc\_num}\s+%{URIPATHPARAM:acc\_uri}\s+%{NUMBER:acc\_status}\s+%{NUMBER:acc\_response\_time}"]  
}  
mutate {  
replace =\> ['acc\_timestamp', '%{acc\_date} %{acc\_time}']  
}  
date {  
match =\> ["acc\_timestamp" , "yyyy-MM-dd HH:mm:ss"]  
target =\> "acc\_timestamp"  
timezone =\> "UTC"  
}  
mutate {  
remove\_field =\> ['acc\_date', 'acc\_time', 'message']  
}  
}

if "weblogic-diagnostic-log" in [tags] {  
grok {  
patterns\_dir=\>"./patterns"  
match =\> ["message", "[%{TIMESTAMP\_ISO8601:diag\_timestamp}]%{SPACE}[%{WORDNOBRACKET:diag\_server}]%{SPACE}[%{WORDNOBRACKET:diag\_msgType}]%{SPACE}[%{WORDNOBRACKET:diag\_add}]%{SPACE}[%{WORDNOBRACKET:diag\_compId}]%{SPACE}[%{DATA:diag\_threadId}]%{SPACE}[%{WORDNOBRACKET:diag\_userId}]%{SPACE}[%{WORDNOBRACKET:diag\_ecid}]%{SPACE}[%{WORDNOBRACKET:diag\_suppleAttr}]%{SPACE}%{GREEDYDATA:diag\_msgText}" ]  
}  
date {  
match =\> ["diag\_timestamp" , "yyyy-MM-dd'T'HH:mm:ss.SSSZ"]  
target =\> "diag\_timestamp"  
}  
mutate {  
remove\_field =\> ['message']  
}  
}

if "weblogic-stdout-log" in [tags] {  
grok {  
patterns\_dir =\> "./patterns"  
match =\> ["message", "\<%{WLS\_SERVERLOG\_DATE:out\_timestamp}%{SPACE}%{DATA:out\_timezone}\>%{SPACE}\<%{LOGLEVEL:out\_level}\>%{SPACE}\<%{DATA:out\_subsystem}\>%{SPACE}\<%{DATA:wls\_code}\>%{SPACE}\<%{GREEDYDATA:out\_message}"]  
}  
# CEST id does not exist in JODA-TIME, changed to CET  
translate {  
field =\> 'out\_timezone'  
destination =\> 'out\_timezone'  
fallback =\> '%{out\_timezone}'  
override =\> "true"  
dictionary =\> [  
'CEST', 'CET'  
]  
}  
date {  
match =\> ["out\_timestamp", "dd-MMM-yyyy HH'H'mm'''"]  
locale =\> "es-ES"  
timezone =\> "%{out\_timezone}"  
target =\> "out\_timestamp"  
}  
mutate {  
remove\_field =\> ['out\_timezone' , 'message']  
}  
}

if "weblogic-gc-log" in [tags] {  
grok {  
patterns\_dir=\>"./patterns"  
match =\> ["message", "%{TIMESTAMP\_ISO8601:gc\_timestamp}:%{SPACE}%{FLOAT:elapsed\_time}:.\*[%{WORDNOBRACKET:gc\_type}%{SPACE}(%{WORDNOBRACKET:cause})%{SPACE}[%{WORDNOBRACKET:gc\_name}:%{SPACE}%{MEM:young\_mem\_before\_gc}-\>%{MEM:young\_mem\_after\_gc}(%{MEM:young\_mem\_total})]%{SPACE}[%{WORDNOBRACKET:old\_gc\_name}:%{SPACE}%{MEM:old\_mem\_before\_gc}-\>%{MEM:old\_mem\_after\_gc}(%{MEM:old\_mem\_total})]%{SPACE}%{MEM:heap\_mem\_before\_gc}-\>%{MEM:heap\_mem\_after\_gc}(%{MEM:heap\_mem\_total}),%{SPACE}[%{WORDNOBRACKET:meta\_gc\_name}:%{SPACE}%{MEM:meta\_mem\_before\_gc}-\>%{MEM:meta\_mem\_after\_gc}(%{MEM:meta\_mem\_total})],%{SPACE}%{FLOAT:pause}%{SPACE}%{WORDNOBRACKET:pause\_time\_type}].\*user=%{FLOAT:user\_time}%{SPACE}sys=%{FLOAT:sys\_time},%{SPACE}real=%{FLOAT:real\_time}" ]

```
      match => ["message", "%{TIMESTAMP_ISO8601:gc_timestamp}:%{SPACE}%{FLOAT:elapsed_time}:.*\[%{WORDNOBRACKET:gc_type}%{SPACE}\(%{WORDNOBRACKET:cause}\)%{SPACE}\[%{WORDNOBRACKET:gc_name}:%{SPACE}%{MEM:young_mem_before_gc}->%{MEM:young_mem_after_gc}\(%{MEM:young_mem_total}\)\]%{SPACE}%{MEM:heap_mem_before_gc}->%{MEM:heap_mem_after_gc}\(%{MEM:heap_mem_total}\),%{SPACE}%{FLOAT:pause}%{SPACE}%{WORDNOBRACKET:pause_time_type}\].*user\=%{FLOAT:user_time}%{SPACE}sys\=%{FLOAT:sys_time},%{SPACE}real\=%{FLOAT:real_time}" ]
    }

date {
  match => ["gc_timestamp" , "yyyy-MM-dd'T'HH:mm:ss.SSSZ"]
  target => "gc_timestamp"
}
mutate {
   remove_field => ['message']
} 

```

}  
}  
output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Shashidhar\_Wl](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Shashidhar\_Wl](https://discuss.elastic.co/u/Shashidhar_Wl)\
**Post date:** [October 25, 2018, 4:09pm UTC](https://discuss.elastic.co/t/logstash-weblogic-filebeat-issues-while-starting-the-logstash/154041/3 "2018-10-25T16:09:34Z")

</div>

I installed plugin for filter translate as a prerequisite for filtering. please review and suggest me what i am doing wrong,

Install the plugin logstash-filter-translate

> logstash-plugin install logstash-filter-translate

---

<div class="post-metadata">

**Author:** ![Shashidhar\_Wl](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Shashidhar\_Wl](https://discuss.elastic.co/u/Shashidhar_Wl)\
**Post date:** [October 26, 2018, 1:12pm UTC](https://discuss.elastic.co/t/logstash-weblogic-filebeat-issues-while-starting-the-logstash/154041/4 "2018-10-26T13:12:35Z")

</div>

Please help.

---

<div class="post-metadata">

**Author:** ![Shashidhar\_Wl](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@Shashidhar\_Wl](https://discuss.elastic.co/u/Shashidhar_Wl)\
**Post date:** [October 30, 2018, 5:55pm UTC](https://discuss.elastic.co/t/logstash-weblogic-filebeat-issues-while-starting-the-logstash/154041/5 "2018-10-30T17:55:11Z")

</div>

Close this issues. i resolved my self.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 27, 2018, 5:55pm UTC](https://discuss.elastic.co/t/logstash-weblogic-filebeat-issues-while-starting-the-logstash/154041/6 "2018-11-27T17:55:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
