# My logstash running sometime have \[Regexp Interrupted\] exception then it's dead

**URL:** <https://discuss.elastic.co/t/my-logstash-running-sometime-have-regexp-interrupted-exception-then-its-dead/113271>\
**Category:** Logstash\
**Created:** [December 27, 2017, 7:00am UTC](https://discuss.elastic.co/t/my-logstash-running-sometime-have-regexp-interrupted-exception-then-its-dead/113271 "2017-12-27T07:00:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Walter\_Xue](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/walter_xue/32/18475_2.png) [@Walter\_Xue](https://discuss.elastic.co/u/Walter_Xue)\
**Post date:** [December 27, 2017, 7:00am UTC](https://discuss.elastic.co/t/my-logstash-running-sometime-have-regexp-interrupted-exception-then-its-dead/113271/1 "2017-12-27T07:00:01Z")

</div>

Logstash Version 5.6.4  
Elasticsearch Version 5.6.4

Logstash Config  
filter{

if "beats\_input\_codec\_plain\_applied" in [tags] {  
mutate {  
remove\_tag =\> ["beats\_input\_codec\_plain\_applied"]  
}  
}  
if "\_geoip\_lookup\_failure" in [tags] {  
drop { }  
}

if "\_grokparsefailure" in [tags] {  
drop { }  
}  
if [xclientip] == "-" {  
mutate{  
replace =\> { "xclientip" =\> "0.0.0.0" }  
}  
}  
if [type] in ["aa", "bb"] {

grok{  
patterns\_dir =\> ["/usr/local/logstash/patterns"]  
match =\> ["message", "%{COMBINEDAPACHELOG2}", "message", "%{COMBINEDAPACHELOG}"]  
}  
geoip{  
source =\> "xclientip"  
target =\> "geoip"  
database =\> "/usr/local/logstash/GeoIP/GeoLite2-City.mmdb"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate{  
convert =\> ["[geoip][coordinates]", "float", "bytes", "integer", "elapsedmillis", "integer" ]  
}  
date {  
match =\> ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z" , "ISO8601"]  
target =\> "@timestamp"

}  
mutate {  
add\_field =\> { "path" =\> "%{request}" }  
}  
mutate {  
gsub =\> ["path", "?.\*", ""]  
}  
mutate {  
remove\_field =\> ["message", "source"]  
}

}  
}

My logstah log:

[FATAL][logstash.runner] An unexpected error occurred! {:error=\>#\<InterruptedRegexpError: Regexp Interrupted\>, :backtrace=\>["org/jruby/RubyString.java:3101:in `gsub'", "org/jruby/RubyString.java:3069:in`gsub'", "/usr/local/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-mutate-3.2.0/lib/logstash/filters/mutate.rb:336:in `gsub_dynamic_fields'", "/usr/local/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-mutate-3.2.0/lib/logstash/filters/mutate.rb:327:in`gsub'", "org/jruby/RubyArray.java:1613:in `each'", "/usr/local/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-mutate-3.2.0/lib/logstash/filters/mutate.rb:309:in`gsub'", "/usr/local/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-mutate-3.2.0/lib/logstash/filters/mutate.rb:223:in `filter'", "/usr/local/logstash/logstash-core/lib/logstash/filters/base.rb:145:in`do\_filter'", "/usr/local/logstash/logstash-core/lib/logstash/filters/base.rb:164:in `multi_filter'", "org/jruby/RubyArray.java:1613:in`each'", "/usr/local/logstash/logstash-core/lib/logstash/filters/base.rb:161:in `multi_filter'", "/usr/local/logstash/logstash-core/lib/logstash/filter_delegator.rb:46:in`multi\_filter'", "(eval):583:in `initialize'", "org/jruby/RubyArray.java:1613:in`each'", "(eval):575:in `initialize'", "org/jruby/RubyProc.java:281:in`call'", "(eval):338:in `filter_func'", "/usr/local/logstash/logstash-core/lib/logstash/pipeline.rb:398:in`filter\_batch'", "/usr/local/logstash/logstash-core/lib/logstash/pipeline.rb:379:in `worker_loop'", "/usr/local/logstash/logstash-core/lib/logstash/pipeline.rb:342:in`start\_workers'"]}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 31, 2017, 1:35pm UTC](https://discuss.elastic.co/t/my-logstash-running-sometime-have-regexp-interrupted-exception-then-its-dead/113271/2 "2017-12-31T13:35:59Z")

</div>

> InterruptedRegexpError: Regexp Interrupted

It looks like your gsub is taking too long to execute.

> gsub =\> ["path", "?.\*", ""]

What on earth is this supposed to accomplish?

---

<div class="post-metadata">

**Author:** ![Walter\_Xue](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/walter_xue/32/18475_2.png) [@Walter\_Xue](https://discuss.elastic.co/u/Walter_Xue)\
**Post date:** [January 2, 2018, 1:52am UTC](https://discuss.elastic.co/t/my-logstash-running-sometime-have-regexp-interrupted-exception-then-its-dead/113271/3 "2018-01-02T01:52:48Z")

</div>

That means reauest content is like /example/API/getIsCookieExist.jsp?txtTime=1514855035170 then request field copy new field (path).

path content after the ? to replace the blank.  
Content be like /example/API/getIsCookieExist.jsp

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 2, 2018, 8:41am UTC](https://discuss.elastic.co/t/my-logstash-running-sometime-have-regexp-interrupted-exception-then-its-dead/113271/4 "2018-01-02T08:41:09Z")

</div>

Oh, so your regexp is actually `\?.*`. **Always** post configuration as preformatted text so e.g. backslashes aren't stripped away.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 30, 2018, 8:41am UTC](https://discuss.elastic.co/t/my-logstash-running-sometime-have-regexp-interrupted-exception-then-its-dead/113271/5 "2018-01-30T08:41:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
