# Problem in query in logstash

**URL:** <https://discuss.elastic.co/t/problem-in-query-in-logstash/337781>\
**Category:** Logstash\
**Created:** [July 6, 2023, 10:36am UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781 "2023-07-06T10:36:55Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hind\_Alla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hind_alla/32/123132_2.png) [@Hind\_Alla](https://discuss.elastic.co/u/Hind_Alla)\
**Post date:** [July 6, 2023, 10:36am UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781/1 "2023-07-06T10:36:56Z")

</div>

input {  
jdbc {  
jdbc\_driver\_library =\> "XXXX"  
jdbc\_driver\_class =\> "Java::oracle.jdbc.driver.OracleDriver"  
jdbc\_connection\_string =\> "XXXX"  
jdbc\_user =\> "XXXX"  
jdbc\_password =\> "XXXX"  
statement =\> "SELECT \* FROM MONITORING\_LOGS WHERE "time\_stamp" \>= SYSDATE - INTERVAL '5' MINUTE AND "module\_id" = '1'"  
jdbc\_paging\_enabled =\> true  
jdbc\_page\_size =\> 10000  
schedule =\> "\*/5 \* \* \* \*"

}  
}

i Have this query that I need to run in logstash but I get an sql error " bad statement"

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 6, 2023, 11:08am UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781/2 "2023-07-06T11:08:18Z")

</div>

Hi @Hind_Alla,

Welcome to the community! Have you checked your SQL against your DB first to validate the syntax? A SQL bad statement error is normally caused by an SQL syntax issue.

---

<div class="post-metadata">

**Author:** ![Hind\_Alla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hind_alla/32/123132_2.png) [@Hind\_Alla](https://discuss.elastic.co/u/Hind_Alla)\
**Post date:** [July 6, 2023, 1:48pm UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781/4 "2023-07-06T13:48:58Z")

</div>

@carly.richmond yes I checked the sql in my db and it worked fine . I think maybe because of double quotes but I skipped it with backslash and it still didn't work

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [July 6, 2023, 1:54pm UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781/5 "2023-07-06T13:54:21Z")

</div>

Thanks for confirming @Hind_Alla. I'm not sure if it's just the formatting here on discuss, but it could be the length of the query if it's overflowing onto another line in your file. Can you try the [`statement_filepath` property](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-jdbc.html#_configuring_sql_statement) and see if extracting the query to a separate file helps?

---

<div class="post-metadata">

**Author:** ![Hind\_Alla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hind_alla/32/123132_2.png) [@Hind\_Alla](https://discuss.elastic.co/u/Hind_Alla)\
**Post date:** [July 6, 2023, 2:00pm UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781/6 "2023-07-06T14:00:48Z")

</div>

okey I'll try the stamement\_filepath property and get back to you . Thank you @carly.richmond

---

<div class="post-metadata">

**Author:** ![Hind\_Alla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hind_alla/32/123132_2.png) [@Hind\_Alla](https://discuss.elastic.co/u/Hind_Alla)\
**Post date:** [July 6, 2023, 2:28pm UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781/7 "2023-07-06T14:28:23Z")

</div>

Thank you @carly.richmond !!! It works perfectly. 😃

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2023, 2:28pm UTC](https://discuss.elastic.co/t/problem-in-query-in-logstash/337781/8 "2023-08-03T14:28:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
