# Logstash works well with an error

**URL:** https://discuss.elastic.co/t/logstash-works-well-with-an-error/145841
**Category:** Logstash
**Created:** [August 24, 2018, 6:06am UTC](https://discuss.elastic.co/t/logstash-works-well-with-an-error/145841 "2018-08-24T06:06:28Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![Chunbo\_Liao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chunbo_liao/32/48172_2.png) [@Chunbo\_Liao](https://discuss.elastic.co/u/Chunbo_Liao)
#### Post date: [August 24, 2018, 6:06am UTC](https://discuss.elastic.co/t/logstash-works-well-with-an-error/145841/1 "2018-08-24T06:06:28Z")

</div>

I used the logstash with the version of 5.6.3, after a few time later. there is an error message in logs/logstash-plain.log. the error is :[ERROR][logstash.filters.ruby] Ruby exception occurred: Regexp Interrupted. but my logstash is still work. does this a matter?

the whole logs is:  
[2018-08-24T13:19:46,193][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"/home/Miracle/elk/logstash-5.6.3/modules/fb\_apache/configuration"}  
[2018-08-24T13:19:46,198][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"/home/Miracle/elk/logstash-5.6.3/modules/netflow/configuration"}  
[2018-08-24T13:19:51,806][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://192.168.2.10:9200/](http://192.168.2.10:9200/)]}}  
[2018-08-24T13:19:51,808][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://192.168.2.10:9200/](http://192.168.2.10:9200/), :path=\>"/"}  
[2018-08-24T13:19:51,919][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://10.56.233.182:9200/](http://10.56.233.182:9200/)"}  
[2018-08-24T13:19:52,001][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-08-24T13:19:52,006][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>50001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=\>false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-08-24T13:19:52,020][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//192.168.2.10:9200](https://192.168.2.10:9200)"]}  
[2018-08-24T13:19:52,440][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>16, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>2000}  
[2018-08-24T13:19:52,664][INFO][logstash.pipeline] Pipeline main started  
[2018-08-24T13:19:52,811][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-08-24T13:45:15,014][ERROR][logstash.filters.ruby] Ruby exception occurred: Regexp Interrupted  
[2018-08-24T14:09:31,460][ERROR][logstash.filters.ruby] Ruby exception occurred: Regexp Interrupted

due to no other error messages, how can I debug this error?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 24, 2018, 6:18am UTC](https://discuss.elastic.co/t/logstash-works-well-with-an-error/145841/2 "2018-08-24T06:18:39Z")

</div>

It looks like you have a ruby filter that's taking too long to filter events. Without knowing anything about your configuration that's really all I can say.

---

<div class="post-metadata">

### Author: ![Chunbo\_Liao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chunbo_liao/32/48172_2.png) [@Chunbo\_Liao](https://discuss.elastic.co/u/Chunbo_Liao)
#### Post date: [August 24, 2018, 6:38am UTC](https://discuss.elastic.co/t/logstash-works-well-with-an-error/145841/3 "2018-08-24T06:38:09Z")

</div>

you mean that there are some low efficiency ruby code in my conf files?

there are 5 ruby code in my conf files .  
1:  
ruby{  
code =\>"  
if !(event.get('MessageType').nil?)  
event.set('MessageType',event.get('MessageType').gsub(' ',''))  
end  
if !(event.get('MessageName').nil?)  
event.set('MessageName',event.get('MessageName').gsub(' ',''))  
end  
if !((event.get('message').split('ticket:')[1]).nil?)  
prioString = event.get('message').split('ticket:')[1]  
prioArray = prioString.split(',')  
if !(prioArray.nil?)  
for prio in prioArray do  
prioName='undefined'  
if !((prio.split(':')[0]).nil?)  
prioName=prio.split(':')[0].gsub(' ','')  
end  
if !((prio.split(':')[1]).nil?)  
prioLateCount=prio.split(':')[1].to\_i  
event.set(prioName, prioLateCount)  
end  
end  
end  
end"  
}  
2:  
ruby{  
code =\>"  
if !(event.get('MessageType').nil?)  
event.set('MessageType',event.get('MessageType').gsub(' ',''))  
end  
if !((event.get('message').split('-')[-1]).nil?)  
gcString = event.get('message').split('-')[-1].gsub(' ','')  
gcArray = gcString.split(',')  
if !(gcArray.nil?)  
for gcItem in gcArray  
if !((gcItem .split(':')[1]).nil?) and !((gcItem .split(':')[0]).nil?)  
gcName=gcItem.split(':')[0]  
gcCount=gcItem.split(':')[1].to\_i  
event.set(gcName, gcCount)  
end  
end  
end  
end"  
}

3:  
ruby{  
code =\>"  
if !(event.get('MessageType').nil?)  
event.set('MessageType',event.get('MessageType').gsub(' ',''))  
end  
if !(event.get('MessageName').nil?)  
event.set('MessageName',event.get('MessageName').gsub(' ',''))  
end  
if !((event.get('message').split('SYSTEM INFO - ')[1]).nil?)  
tempString = event.get('message').split('SYSTEM INFO - ')[1]  
if !((tempString.split(':')[1]).nil?)  
loadString=(tempString.split(':')[1]).gsub(' ','')  
loadArray = loadString.split(',')  
if !(loadArray.nil?)  
for load in loadArray do  
if !((load.split('-')[0]).nil?) and !((load.split('-')[1]).nil?)  
loadName=load.split('-')[0]  
loadNameCount=load.split('-')[1].to\_f  
event.set(loadName, loadNameCount)  
end  
end  
end  
end  
end"  
}

4:  
ruby{  
code =\>"  
if !(event.get('MessageType').nil?)  
event.set('MessageType',event.get('MessageType').gsub(' ',''))  
end  
if !(event.get('MessageName').nil?)  
event.set('MessageName',event.get('MessageName').gsub(' ',''))  
end  
if !((event.get('message').split('SYSTEM INFO - ')[1]).nil?)  
tempString = event.get('message').split('SYSTEM INFO - ')[1]  
if !((tempString.split('-')[1]).nil?)  
loadString=(tempString.split('-')[1]).gsub(' ','')  
loadArray = loadString.split(',')  
if !(loadArray.nil?)  
for load in loadArray do  
if !((load.split('-')[0]).nil?) and !((load.split('-')[1]).nil?)  
loadName=load.split('-')[0].gsub(' ','')  
loadNameCount=load.split('-')[1].to\_f  
event.set(loadName, loadNameCount)  
end  
end  
end  
end  
end"  
}

5:  
ruby{  
code =\>"  
if !(event.get('MessageType').nil?)  
event.set('MessageType',event.get('MessageType').gsub(' ',''))  
end  
if !(event.get('MessageName').nil?)  
event.set('MessageName',event.get('MessageName').gsub(' ',''))  
end  
if (event.get('MessageType') != 'DMXForwardedMessages') and !(event.get('message').split('Cause:')[1].nil?)  
causeString = event.get('message').split('Cause:')[1]  
causeArray = causeString.split(',')  
if !(causeArray.nil?)  
for i in causeArray do  
temp = i.split('-')  
causeID='undefined'  
if !(temp[0].nil?)  
causeID = temp[0]  
end  
if !(temp[1].nil?)  
causeValue = temp[1].to\_i  
event.set(causeID, causeValue)  
end  
end  
end  
elsif (event.get('MessageType') == 'ProcedureStatistics')  
procLateArray=event.get('message').split(',')  
if !(procLateArray.nil?)  
for proc in procLateArray do  
if proc.include?'Latency'  
procLate='undefined'  
if !((proc.split(':')[0]).nil?)  
procLate=proc.split(':')[0].gsub(' ','')  
end  
if !((proc.split(':')[1]).nil?)  
procLateCount=proc.split(':')[1].to\_i  
event.set(procLate, procLateCount)  
end  
end  
end  
end  
end"  
}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [August 24, 2018, 7:45am UTC](https://discuss.elastic.co/t/logstash-works-well-with-an-error/145841/4 "2018-08-24T07:45:27Z")

</div>

> you mean that there are some low efficiency ruby code in my conf files?

That would've been my guess, but your ruby filters seems pretty straight-forward so I don't know what's going on.

---

<div class="post-metadata">

### Author: ![Chunbo\_Liao](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chunbo_liao/32/48172_2.png) [@Chunbo\_Liao](https://discuss.elastic.co/u/Chunbo_Liao)
#### Post date: [August 24, 2018, 8:41am UTC](https://discuss.elastic.co/t/logstash-works-well-with-an-error/145841/5 "2018-08-24T08:41:51Z")

</div>

now, more errors comeout:  
Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash. {"exception"=\>"interrupted waiting for mutex: null", "backtrace"=\>["org/jruby/ext/thread/Mutex.java:94:in `lock'", "org/jruby/ext/thread/Mutex.java:147:in`synchronize'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/metric\_store.rb:58:in `fetch_or_store'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/collector.rb:51:in`get'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/collector.rb:36:in `push'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/metric.rb:22:in`increment'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/namespaced\_metric.rb:24:in `increment'", "/home/11thone/elk/logstash-5.6.3/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-3.4.3/lib/logstash/filters/grok.rb:313:in`filter'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/filters/base.rb:145:in `do_filter'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/filters/base.rb:164:in`multi\_filter'", "org/jruby/RubyArray.java:1613:in `each'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/filters/base.rb:161:in`multi\_filter'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/filter\_delegator.rb:46:in `multi_filter'", "(eval):12259:in`initialize'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):12253:in`initialize'", "org/jruby/RubyProc.java:281:in `call'", "(eval):12277:in`initialize'", "org/jruby/RubyArray.java:1613:in `each'", "(eval):12274:in`initialize'", "org/jruby/RubyProc.java:281:in `call'", "(eval):1978:in`filter\_func'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/pipeline.rb:398:in `filter_batch'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/pipeline.rb:379:in`worker\_loop'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/pipeline.rb:342:in `start_workers'"]} [2018-08-24T16:41:15,093][FATAL][logstash.runner] An unexpected error occurred! {:error=>#<ConcurrencyError: interrupted waiting for mutex: null>, :backtrace=>["org/jruby/ext/thread/Mutex.java:94:in`lock'", "org/jruby/ext/thread/Mutex.java:147:in `synchronize'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/metric_store.rb:58:in`fetch\_or\_store'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/collector.rb:51:in `get'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/collector.rb:36:in`push'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/metric.rb:22:in `increment'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/instrument/namespaced_metric.rb:24:in`increment'", "/home/11thone/elk/logstash-5.6.3/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-3.4.3/lib/logstash/filters/grok.rb:313:in `filter'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/filters/base.rb:145:in`do\_filter'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/filters/base.rb:164:in `multi_filter'", "org/jruby/RubyArray.java:1613:in`each'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/filters/base.rb:161:in `multi_filter'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/filter_delegator.rb:46:in`multi\_filter'", "(eval):12259:in `initialize'", "org/jruby/RubyArray.java:1613:in`each'", "(eval):12253:in `initialize'", "org/jruby/RubyProc.java:281:in`call'", "(eval):12277:in `initialize'", "org/jruby/RubyArray.java:1613:in`each'", "(eval):12274:in `initialize'", "org/jruby/RubyProc.java:281:in`call'", "(eval):1978:in `filter_func'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/pipeline.rb:398:in`filter\_batch'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/pipeline.rb:379:in `worker_loop'", "/home/11thone/elk/logstash-5.6.3/logstash-core/lib/logstash/pipeline.rb:342:in`start\_workers'"]}

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 21, 2018, 8:42am UTC](https://discuss.elastic.co/t/logstash-works-well-with-an-error/145841/6 "2018-09-21T08:42:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
