# Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<RegexpError: empty char-class: /(?:Duplicate TCP SYN|Failed to locate egress interface|Invalid transport field|No matching connection|DNS Response|DNS Query

**URL:** <https://discuss.elastic.co/t/pipeline-aborted-due-to-error-pipeline-id-main-exception-regexperror-empty-char-class-duplicate-tcp-syn-failed-to-locate-egress-interface-invalid-transport-field-no-matching-connection-dns-response-dns-query/192000>\
**Category:** Logstash\
**Created:** [July 24, 2019, 10:09am UTC](https://discuss.elastic.co/t/pipeline-aborted-due-to-error-pipeline-id-main-exception-regexperror-empty-char-class-duplicate-tcp-syn-failed-to-locate-egress-interface-invalid-transport-field-no-matching-connection-dns-response-dns-query/192000 "2019-07-24T10:09:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![satyam2593](https://avatars.discourse-cdn.com/v4/letter/s/a88e4f/32.png) [@satyam2593](https://discuss.elastic.co/u/satyam2593)\
**Post date:** [July 24, 2019, 10:09am UTC](https://discuss.elastic.co/t/pipeline-aborted-due-to-error-pipeline-id-main-exception-regexperror-empty-char-class-duplicate-tcp-syn-failed-to-locate-egress-interface-invalid-transport-field-no-matching-connection-dns-response-dns-query/192000/1 "2019-07-24T10:09:44Z")

</div>

## [ERROR] 2019-07-24 10:52:19.002 [[main]-pipeline-manager] javapipeline - Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<RegexpError: empty char-class: /(?:Duplicate TCP SYN|Failed to locate egress interface|Invalid transport field|No matching connection|DNS Response|DNS Query|(?:(?:\b\w+\b)\s\*)\*):(?:(?:(?:(?:(?:[0-5]?[0-9]|60)(?:[:.,][0-9]+)?))|60)),436 | INFO | 970074601-765686 | (?:(?:[a-zA-Z0-9-]+.)+[A-Za-z0-9$]+) 276 | 38 - (?:(?:[a-zA-Z0-9-]+.)+[A-Za-z0-9$]+)-core - (?:(?:[a-zA-Z0-9-]+.)+[A-Za-z0-9$]+) | Inbound Message

ID: 714128  
Response-Code: 200  
Encoding: (?:[A-Z0-9]+-(?:(?:[+-]?(?:[0-9]+)))-(?:[A-Z0-9\_]+))  
Content-Type: application(?:(?:(?:/[A-Za-z0-9$.+!_'(){},~:;=@#%&\_-]_)+)(?:(?:?[A-Za-z0-9$.+!_'|(){},~@#%&/=:;\_?-[]\<\>]_))?)  
Headers: {connection=(?:[(?:._?)]+), Content-Length=(?:[(?NUMBER:nagios\_epoch(?:(?:(?\<![0-9.+-])(?\>[+-]?(?:(?:[0-9]+(?:.[0-9]+)?)|(?:.[0-9]+))))))]), content-type=(?:[(?:._?)]+), Date=(?:[(?:._?)]+), Keep-Alive=(?:[(?:._?)]+), Server=(?:[(?:._?)]+), X-Powered-By=(?:[(?:._?)]+)}  
Payload: {(?:(?:(?\>(?\<!\)(?\>"(?\>\.|[^\"]+)+"|""|(?\>'(?\>\.|[^\']+)+')|''|(?\>`(?>\\.|[^\\`]+)+`)|``)))):false,(?:(?:(?>(?<!\\)(?>"(?>\\.|[^\\"]+)+"|""|(?>'(?>\\.|[^\\']+)+')|''|(?>`(?\>\.|[^\`]+)+`)|`)))):(?:(?:(?>(?<!\\)(?>"(?>\\.|[^\\"]+)+"|""|(?>'(?>\\.|[^\\']+)+')|''|(?>`(?>\\.|[^\\`]+)+`)|`)))),(?:(?:(?\>(?\<!\)(?\>"(?\>\.|[^\"]+)+"|""|(?\>'(?\>\.|[^\']+)+')|''|(?\>`(?>\\.|[^\\`]+)+`)|``)))):[]} /m>, :backtrace=>["org/jruby/RubyRegexp.java:940:in`initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:127:in `compile'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:281:in`block in register'", "org/jruby/RubyArray.java:1792:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:275:in`block in register'", "org/jruby/RubyHash.java:1419:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:270:in`register'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:56:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:192:in`block in register\_plugins'", "org/jruby/RubyArray.java:1792:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:191:in`register\_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:463:in `maybe_setup_out_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:204:in`start\_workers'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:146:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:105:in`block in start'"], :thread=\>"#\<Thread:0x49dff0bf run\>"}

[ERROR] 2019-07-24 10:52:19.022 [Converge PipelineAction::Create] agent - Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}

my config file:  
input {  
beats {  
port =\> "5044"  
}  
}

## filter { grok { match =\> { "message" =\> "%{CISCO\_REASON}:%{ISO8601\_SECOND},436 | INFO | 970074601-765686 | %{JAVACLASS} 276 | 38 - %{JAVACLASS}-core - %{JAVACLASS} | Inbound Message

ID: 714128  
Response-Code: 200  
Encoding: %{CISCOTAG}  
Content-Type: application%{URIPATHPARAM}  
Headers: {connection=%{SYSLOG5424SD}, Content-Length=%{NAGIOSTIME}, content-type=%{SYSLOG5424SD}, Date=%{SYSLOG5424SD}, Keep-Alive=%{SYSLOG5424SD}, Server=%{SYSLOG5424SD}, X-Powered-By=%{SYSLOG5424SD}}  
Payload: {%{QS}:false,%{QS}:%{QS},%{QS}:}  
"}  
}  
}

output {  
elasticsearch {  
hosts =\> ["xxxxx:9200"]  
index =\> "prod-%{+YYYY.MM.dd}"  
}  
stdout { codec =\> rubydebug }  
}

my input log file:

## 17 Jul 2019 00:03:33,436 | INFO | 970074601-765686 | eptor.AbstractLoggingInterceptor 276 | 38 - org.apache.cxf.cxf-core - 3.2.4 | Inbound Message

ID: 714128  
Response-Code: 200  
Encoding: ISO-8859-1  
Content-Type: application/json  
Headers: {connection=[Keep-Alive], Content-Length=[178], content-type=[application/json], Date=[Tue, 16 Jul 2019 23:03:27 GMT], Keep-Alive=[timeout=15, max=100], Server=[Apache], X-Powered-By=[PHP/5.4.45]}  
Payload: {"success":false,"message":"API memory limit reached

- /opt/monolith/www/ui/eventBase/model/Events.php\</li\>
  - Result set too large\</li\>\</ul\>\</ul\>","data":}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 24, 2019, 11:53am UTC](https://discuss.elastic.co/t/pipeline-aborted-due-to-error-pipeline-id-main-exception-regexperror-empty-char-class-duplicate-tcp-syn-failed-to-locate-egress-interface-invalid-transport-field-no-matching-connection-dns-response-dns-query/192000/2 "2019-07-24T11:53:57Z")

</div>

> [@satyam2593](#):
>
> #\<RegexpError: empty char-class

That would typically mean you are trying to match literal square brackets using square brackets without escaping them. To match a string like

```
Foo: []

```

You have to use

```
Foo: \[\]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2019, 11:53am UTC](https://discuss.elastic.co/t/pipeline-aborted-due-to-error-pipeline-id-main-exception-regexperror-empty-char-class-duplicate-tcp-syn-failed-to-locate-egress-interface-invalid-transport-field-no-matching-connection-dns-response-dns-query/192000/3 "2019-08-21T11:53:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
