# Multipipeline Issues

**URL:** <https://discuss.elastic.co/t/multipipeline-issues/117347>\
**Category:** Logstash\
**Created:** [January 28, 2018, 5:46am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347 "2018-01-28T05:46:07Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [January 28, 2018, 5:46am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/1 "2018-01-28T05:46:07Z")

</div>

ELK 6.1.1 stack running on Windows Server 2012R2  
.\logstash -f path\pipelines.yml

pipelines.yml

- [pipeline.id](http://pipeline.id): Beats  
path.config: "D:/ELKStack/LogStash/config/pipeline\_beats.config"
- [pipeline.id](http://pipeline.id): NMap  
path.config: "D:/ELKStack/LogStash/config/pipeline\_nmap.config"  
queue.type: memory

I get the following error logged:

[2018-01-27T23:38:37,700][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, input, filter, output at line 1, column 1 (byte 1) after ", :backtrace=\>["D:/ELKStack/LogStash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/pipeline.rb:171:in `initialize'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:335:in `block in converge_state'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:332:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:319:in `converge_state'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:105:in `block in execute'", "D:/ELKStack/LogStash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:18:in`interval'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/agent.rb:94:in `execute'", "D:/ELKStack/LogStash/logstash-core/lib/logstash/runner.rb:343:in`block in execute'", "D:/ELKStack/LogStash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

If I copy and paste what is in my beats pipeline config file into the pipelines.yml, I get no errors and everything is fine. What is the error message pointing to that is wrong in my configs?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 30, 2018, 6:48am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/2 "2018-01-30T06:48:20Z")

</div>

Either pipeline\_beat.config or pipeline\_nmap.config has a syntax error. By the looks of it the problem is at the very beginning. Perhaps you've edited the files with an editor that adds a byte-order mark? You can check this with a hex editor.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 30, 2018, 6:57am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/3 "2018-01-30T06:57:53Z")

</div>

The `pipelines.yml` file should [be placed in the settings folder](https://www.elastic.co/guide/en/logstash/6.1/multiple-pipelines.html), and can as far as I know not be passed through the `-f` flag. Place the file in the correct location and then try starting Logstash without the `-f` flag.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [January 30, 2018, 1:33pm UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/4 "2018-01-30T13:33:51Z")

</div>

Gentlemen, thank you for your responses. The pipeline.yml is in the config folder, I should have made my example more clear. As for the editor, I used Notepad++, I'll look into the byte mark ordering. I could see the error was telling me it didn't like the first instruction it saw in the file, but the syntax makes it seem like it's not compatible with multi-pipelining.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [January 30, 2018, 7:22pm UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/5 "2018-01-30T19:22:08Z")

</div>

Did some Googlin' and Notepad++ has two encoding settings, UTF-8 and UTF-8-BOM. All my config files are using UTF-8 encoding, so that doesn't appear to be the issue either. I also verified that UTF-8-BOM does not mean UTF-8 without BOM.

Any other ideas? Anything else about my setup you need to help me with the issue?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [January 30, 2018, 7:27pm UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/6 "2018-01-30T19:27:46Z")

</div>

The `path.settings` directory where the `pipelines.yml` file should be located is the generally the same one as where the `logstash.yml` file is located. Is that where you have stored it?

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [January 30, 2018, 7:51pm UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/7 "2018-01-30T19:51:36Z")

</div>

I am not using a modified path.settings configuration, everything resides in the \logstash\config folder. I have tried running with the custom pipeline config files in logstash\config\pipelines folder and with them in the \logstash\config folder, both have the same behavior.

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [February 1, 2018, 9:48pm UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/8 "2018-02-01T21:48:34Z")

</div>

Bump

---

<div class="post-metadata">

**Author:** ![ld57](https://avatars.discourse-cdn.com/v4/letter/l/85f322/32.png) [@ld57](https://discuss.elastic.co/u/ld57)\
**Post date:** [February 22, 2018, 6:22pm UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/9 "2018-02-22T18:22:36Z")

</div>

> [@wwalker](#):
>
> path.config: "D:/ELKStack/LogStash/config/pipeline\_beats.config"

Hi @wwalker , I met the same issue.

we resolved by arranging the line ( I guess it is a kind of bug). It is related to windows environnement

change your line to :

` path.config: D:\ELKStack\LogStash\config\pipeline_beats.config`

in fact ,it seems that double quotes are our problem. also, keep your backslash as on windows.

KR

ld

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [February 22, 2018, 9:40pm UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/10 "2018-02-22T21:40:28Z")

</div>

I just discovered a way to make it work last night on an unrelated ElasticStack by omitting the drive letter, though I don't recall if I included double quotes or not.

path.config: /ELKStack/LogStash/config/pipeline\_beats.config

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [February 23, 2018, 4:06am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/11 "2018-02-23T04:06:30Z")

</div>

> [@wwalker](#):
>
> path.config: /ELKStack/LogStash/config/pipeline\_beats.config

path.config: /ELKStack/LogStash/config/pipeline\_beats.config

there is a space ': /ELK' please remove it and try.

Please read below solution also for your reference.

> [@Migration issues from Logstash 2.4 to 5.6](https://discuss.elastic.co/t/migration-issues-from-logstash-2-4-to-5-6/119888/4):
>
> path.settings: /etc/logstash/conf.d it seems there is space b/w ': /etc/' pls check the same in your conf file and remove it. OR 5.0 forces you to have the settings file. But the default settings file has a row: path.config: /etc/logstash/conf.d This becomes a problem if you run the application and use -f to point it to a custom configuration file like this. sudo /usr/share/logstash/bin/logstash -f /home/ec2-user/logstashfileinput.yaml --path.settings /etc/logstash/ Whatever file you poi…

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [February 23, 2018, 4:15am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/12 "2018-02-23T04:15:17Z")

</div>

> [@harshbajaj16](#):
>
> > [@wwalker](#):
> >
> > path.config: /ELKStack/LogStash/config/pipeline\_beats.config
> 
> path.config: /ELKStack/LogStash/config/pipeline\_beats.config
> 
> there is a space ': /ELK' please remove it and try.
> 
> Please read below solution also for your reference.  
> [Migration issues from Logstash 2.4 to 5.6 - #4 by harshbajaj16](https://discuss.elastic.co/t/migration-issues-from-logstash-2-4-to-5-6/119888/4)

I'm sorry....what?

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [February 23, 2018, 4:30am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/13 "2018-02-23T04:30:34Z")

</div>

in your file there is a space in below line

path.config: /ELKStack/LogStash/config/pipeline\_beats.config ---space  
path.config:/ELKStack/LogStash/config/pipeline\_beats.config ---without space try this

---

<div class="post-metadata">

**Author:** ![wwalker](https://avatars.discourse-cdn.com/v4/letter/w/43a26b/32.png) [@wwalker](https://discuss.elastic.co/u/wwalker)\
**Post date:** [February 23, 2018, 4:33am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/14 "2018-02-23T04:33:10Z")

</div>

> [@harshbajaj16](#):
>
> in your file there is a space in below line
> 
> path.config: /ELKStack/LogStash/config/pipeline\_beats.config ---space  
> path.config:/ELKStack/LogStash/config/pipeline\_beats.config ---without space try this

Ah, I see what you're saying....which is odd because, as I said in the post you are quoting, by removing the drive letter, the issue was resolved. This thread is specifically about Windows installations, where full paths have drive letters so I could see where you could be confused if you thought I was talking about Linux.

---

<div class="post-metadata">

**Author:** ![harshbajaj16](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshbajaj16/32/44970_2.png) [@harshbajaj16](https://discuss.elastic.co/u/harshbajaj16)\
**Post date:** [February 23, 2018, 4:36am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/15 "2018-02-23T04:36:20Z")

</div>

yes i was talking about linux. bcoz earlier we faced same issue and got resolved by this.

and also provide this solution to others and it works so i thought u might have same issue.

> [@Migration issues from Logstash 2.4 to 5.6](https://discuss.elastic.co/t/migration-issues-from-logstash-2-4-to-5-6/119888/4):
>
> path.settings: /etc/logstash/conf.d it seems there is space b/w ': /etc/' pls check the same in your conf file and remove it. OR 5.0 forces you to have the settings file. But the default settings file has a row: path.config: /etc/logstash/conf.d This becomes a problem if you run the application and use -f to point it to a custom configuration file like this. sudo /usr/share/logstash/bin/logstash -f /home/ec2-user/logstashfileinput.yaml --path.settings /etc/logstash/ Whatever file you poi…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 23, 2018, 4:36am UTC](https://discuss.elastic.co/t/multipipeline-issues/117347/16 "2018-03-23T04:36:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
