# \[Need Help\] Logstash start failed when use 3rd party gem in customized plugin

**URL:** <https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084>\
**Category:** Logstash\
**Created:** [September 11, 2015, 3:47am UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084 "2015-09-11T03:47:32Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ttys000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ttys000/32/5754_2.png) [@ttys000](https://discuss.elastic.co/u/ttys000)\
**Post date:** [September 11, 2015, 3:47am UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/1 "2015-09-11T03:47:32Z")

</div>

I used mail gem in customized codec plugin to handle some email related data, the plugin gem run bundle exec rspec and gem build is successful. The problem is when the plugin installed, it will lead Logstash start process failed.I tried to add --debug option to check the debug log when starting, it's weird:

```
The error reported is:
  Couldn't find any output plugin named 'stdout'. Are you sure this is correct? Trying to load the stdout output plugin resulted in this error: undefined method `on_load' for ActiveSupport:Module
/Users/lipy/elk/logstash-1.5.4/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/plugin.rb:142:in `lookup'
/Users/lipy/elk/logstash-1.5.4/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/pipeline.rb:293:in `plugin'
(eval):59:in `initialize'
org/jruby/RubyKernel.java:1111:in `eval'
/Users/lipy/elk/logstash-1.5.4/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/pipeline.rb:31:in `initialize'
/Users/lipy/elk/logstash-1.5.4/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/agent.rb:114:in `execute'
/Users/lipy/elk/logstash-1.5.4/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/runner.rb:90:in `run'
org/jruby/RubyProc.java:271:in `call'
/Users/lipy/elk/logstash-1.5.4/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.4-java/lib/logstash/runner.rb:95:in `run'
org/jruby/RubyProc.java:271:in `call'
/Users/lipy/elk/logstash-1.5.4/vendor/bundle/jruby/1.9/gems/stud-0.0.21/lib/stud/task.rb:12:in `initialize'

```

But stdout plugin is fine, OK?!

I does a lot of check and found perhaps the root cause is mail gem, because there is only one line code related to mail gem in my plugin's source code, just require "mail", when I comment out this code line and rebuild gem and re-install plugin, the Logstash start successful. I checked the vendor folder of Logstash, both mail gem and the customized codec plugin has exist.

I'm stuck!! Help, please!!

There is some code for reference:

My ruby version:

```
jruby 1.7.19 (1.9.3p551) 2015-01-29 20786bd on Java HotSpot(TM) 64-Bit Server VM 1.8.0_40-b26 +jit [darwin-x86_64]

```

Gemfile:

```
source 'https://rubygems.org'
gemspec

```

gemsepc:

```
Gem::Specification.new do |s|
  # Leave out some general gem info
  ........
  # Files
  s.files = `git ls-files`.split($\)

  # Tests
  s.test_files = s.files.grep(%r{^(test|spec|features)/})

  # Special flag to let us know this is actually a logstash plugin
  s.metadata = { 'logstash_plugin' => 'true', 'logstash_group' => 'codec' }

  # Gem dependencies
  s.add_runtime_dependency 'logstash-core', '>= 1.4.0', '< 2.0.0'
  s.add_runtime_dependency 'mail', '~>2.6', '>=2.6.3'
  s.add_development_dependency 'logstash-devutils', '~>0'
end
```

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 3, 2015, 3:03pm UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/2 "2015-11-03T15:03:29Z")

</div>

It might be helpful if we could review your configuration, and perhaps the code of your plugin (though we understand that you may be sensitive to sharing your private code).

---

<div class="post-metadata">

**Author:** ![ttys000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ttys000/32/5754_2.png) [@ttys000](https://discuss.elastic.co/u/ttys000)\
**Post date:** [November 5, 2015, 8:52am UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/3 "2015-11-05T08:52:23Z")

</div>

Hi theuntergeek,

I'm happy to share my code, there is no secret 😄

[https://github.com/ttys000/logstash-codec-emailsubject](https://github.com/ttys000/logstash-codec-emailsubject), this is the plugin code.

My Logstash version is 1.5.2, here is the config file: [https://gist.github.com/ttys000/439a20cde5662edd31b0](https://gist.github.com/ttys000/439a20cde5662edd31b0)

You need to import grok-patterns from this repo [https://github.com/logstash-plugins/logstash-patterns-core](https://github.com/logstash-plugins/logstash-patterns-core)

Thanks!

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 5, 2015, 6:52pm UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/4 "2015-11-05T18:52:47Z")

</div>

As an unrelated aside:

```
    "size" => "integer"
    "nrcpts" => "integer"
    "number_attachments" => "integer"
    "spamscore" => "integer"
    "spamthreshold" => "integer"
    "iascore" => "integer"
    "iathreshold" => "integer"
    "dlpfilesize" => "integer"
    "ts_reputation_score" => "integer"

```

Since you're not acting on any of these numerics inside Logstash, you can improve Logstash performance by coercing the types within an Elasticsearch template. Use the smallest numeric type available in Elasticsearch that suits the number. If the numbers are from 0-100, then a `byte` mapping even makes sense, otherwise a `short` might be better.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 5, 2015, 6:56pm UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/5 "2015-11-05T18:56:18Z")

</div>

What's in the `Gemfile.lock` in your directory?

---

<div class="post-metadata">

**Author:** ![ttys000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ttys000/32/5754_2.png) [@ttys000](https://discuss.elastic.co/u/ttys000)\
**Post date:** [November 6, 2015, 2:21am UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/6 "2015-11-06T02:21:19Z")

</div>

Thanks advice, I will check it out.

I uploaded the Gemfile.lock file into Github, you can pull it.

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 6, 2015, 3:16am UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/7 "2015-11-06T03:16:22Z")

</div>

How have you installed Logstash?

---

<div class="post-metadata">

**Author:** ![ttys000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ttys000/32/5754_2.png) [@ttys000](https://discuss.elastic.co/u/ttys000)\
**Post date:** [November 6, 2015, 3:34am UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/8 "2015-11-06T03:34:05Z")

</div>

I just unpack the .tar.gz file and run sudo ./logstash -f myconfig.conf &  
What's matter?

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [November 6, 2015, 5:19pm UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/9 "2015-11-06T17:19:43Z")

</div>

How did you install your plugin into that installation?

---

<div class="post-metadata">

**Author:** ![ttys000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ttys000/32/5754_2.png) [@ttys000](https://discuss.elastic.co/u/ttys000)\
**Post date:** [November 9, 2015, 1:56am UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/10 "2015-11-09T01:56:07Z")

</div>

Use this instruction:  
./plugin install logstash-codec-emailsubject-0.1.0.gem

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:23am UTC](https://discuss.elastic.co/t/need-help-logstash-start-failed-when-use-3rd-party-gem-in-customized-plugin/29084/11 "2017-07-06T05:23:26Z")

</div>


