# Pipeline error {:pipeline\_id=\>"main", :exception=\>#\<NoMethodError: undefined method \`close' for nil:NilClass\>

**URL:** <https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706>\
**Category:** Logstash\
**Created:** [February 9, 2022, 10:09am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706 "2022-02-09T10:09:21Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 9, 2022, 10:09am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/1 "2022-02-09T10:09:21Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/5/5/557fd3c5714b7ce8bd1abe1823dfc96bbcfa68cf.png)  
I have that error in logstash logs when logstash starting. Here my config file for logstash:

```auto
input {
  beats {
    port => 5044
  }
}
filter {
    grok {
      patterns_dir => ["/etc/logstash/pattern"]
      match => { "message" => "%{IPORHOST:clientip} %{NGUSER:ident} %{NGUSER:auth} \[%{HTTPDATE:timestamp}\] \"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}\" %{NUMBER:response}" }
    }
}
output {
  elasticsearch {
      hosts => ["127.0.0.1:9200"]
      index => "elk_fb_logstash-%{+YYYY.MM.dd}"
  }
}

```

Pls, can you help me to solve this problem.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 9, 2022, 6:02pm UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/2 "2022-02-09T18:02:39Z")

</div>

That exception occurs if the grok filter is unable to open a pattern file. Check the patterns\_dir option and the permissions on the files there.

---

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 10, 2022, 2:55am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/3 "2022-02-10T02:55:34Z")

</div>

I gave the permission to the pattern file by command chmod -R 777, but this error doesn't dissapear. And where can I check the patterns\_dir option?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2022, 3:00am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/4 "2022-02-10T03:00:40Z")

</div>

> [@Dark\_Man](#):
>
> `"/etc/logstash/pattern"`

I am saying to check that this is the correct directory. It is a directory, right?

---

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 10, 2022, 3:01am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/5 "2022-02-10T03:01:18Z")

</div>

Yes, this is my pattern directory.

---

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 10, 2022, 3:08am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/6 "2022-02-10T03:08:16Z")

</div>

By the way also I used such command as chown logstash: /etc/logstash/pattern to to my pattern file in this directory.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2022, 3:13am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/7 "2022-02-10T03:13:14Z")

</div>

Set the log.level to trace and grok will tell you which file it is trying to read.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2022, 4:23am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/9 "2022-02-10T04:23:50Z")

</div>

Please do not post pictures of text, they are hard to read, impossible to search, and some folk may not be able to see them at all.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2022, 4:43am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/11 "2022-02-10T04:43:01Z")

</div>

That is log.level INFO, not log.level TRACE.

---

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 10, 2022, 4:48am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/12 "2022-02-10T04:48:48Z")

</div>

But I changed it to trace here in logstash.yml:

```auto
# ------------ Debugging Settings --------------
#
# Options for log.level:
# * fatal
# * error
# * warn
# * info (default)
# * debug
# * trace
#
 log.level: trace
path.logs: /var/log/logstash
#

```

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [February 10, 2022, 8:41am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/13 "2022-02-10T08:41:11Z")

</div>

Hey Dark\_Man

try removing the space before log.level in your config, remember this is YAML configuration files they are sensible to spaces and tabulations.

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [February 10, 2022, 9:40am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/15 "2022-02-10T09:40:36Z")

</div>

How do you start logstash ?

---

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 10, 2022, 9:46am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/16 "2022-02-10T09:46:12Z")

</div>

I use such kind of commands:

```auto
systemctl restart logstash
systemctl status logstash
cat /var/log/logstash/logstash-plain.log

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2022, 5:20pm UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/17 "2022-02-10T17:20:27Z")

</div>

> [@Dark\_Man](#):
>
> I changed it, but seems that here no any additional information about pipeline error

If logstash started without an exception when you had a single space in front of that logstash.yml entry then it seems to me unlikely that it was reading the file you edited, and was in fact using a different copy.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 10, 2022, 7:00pm UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/18 "2022-02-10T19:00:56Z")

</div>

What do you have inside of `/etc/logstash/patterns`, one file? multiple files?

Can you share the content of the files inside the pattern dir?

---

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 11, 2022, 3:53am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/19 "2022-02-11T03:53:03Z")

</div>

@leandrojmp at pattern directory I've created one file named as nginx, here is content of this file:

```auto
NGUSERNAME [a-zA-Z\.\@\-\+_%]+
NGUSER %{NGUSERNAME}

```

---

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 11, 2022, 4:11am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/20 "2022-02-11T04:11:54Z")

</div>

@Badger Do you mean that I need to put a single space before `log.level: trace` at logstash.yml?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 11, 2022, 4:15am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/21 "2022-02-11T04:15:53Z")

</div>

No, I am saying that if you edited the logstash.yml in that way and it had no effect on logstash then it seems likely that logstash is not using the logstash.yml that you think it is.

---

<div class="post-metadata">

**Author:** ![Dark\_Man](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dark_man/32/99119_2.png) [@Dark\_Man](https://discuss.elastic.co/u/Dark_Man)\
**Post date:** [February 11, 2022, 4:20am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/22 "2022-02-11T04:20:27Z")

</div>

@Badger Ok, I understand what you mean, but then what file is logstash using instead of logstash.yml? Maybe you know, how can I check it?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 11, 2022, 4:36am UTC](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706/23 "2022-02-11T04:36:15Z")

</div>

logstash.yml is loaded from path.settings, which could use the default, could be set on the command line using --path.settings, or could be set in the environment using $LS\_PATH\_SETTINGS.

If I remember correctly then `--config.debug` will print the value of path.settings that logstash is using.

[Next page](https://discuss.elastic.co/t/pipeline-error-pipeline-id-main-exception-nomethoderror-undefined-method-close-for-nil-nilclass/296706.md?page=2)
