# Read log from local file

**URL:** <https://discuss.elastic.co/t/read-log-from-local-file/117628>\
**Category:** Logstash\
**Created:** [January 30, 2018, 1:41pm UTC](https://discuss.elastic.co/t/read-log-from-local-file/117628 "2018-01-30T13:41:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vigneshprasanna](https://avatars.discourse-cdn.com/v4/letter/v/a3d4f5/32.png) [@Vigneshprasanna](https://discuss.elastic.co/u/Vigneshprasanna)\
**Post date:** [January 30, 2018, 1:41pm UTC](https://discuss.elastic.co/t/read-log-from-local-file/117628/1 "2018-01-30T13:41:52Z")

</div>

Im trying to read logs from a local folder in my system. I get the following error

D:\Personal\logstash-6.1.2\bin\>logstash.bat -f ..\config\logstash.confSending Logstash's logs to D:/Personal/logstash-6.1.2/logs which is now configured via log4j2.properties  
[2018-01-30T18:28:39,944][INFO][logstash.modules.scaffold] Initializing module{:module\_name=\>"fb\_apache", :directory=\>"D:/Personal/logstash-6.1.2/modules/fb\_apache/configuration"}  
[2018-01-30T18:28:39,975][INFO][logstash.modules.scaffold] Initializing module{:module\_name=\>"netflow", :directory=\>"D:/Personal/logstash-6.1.2/modules/netflow/configuration"}  
[2018-01-30T18:28:40,427][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-01-30T18:28:41,285][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.1.2"}  
[2018-01-30T18:28:42,006][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-01-30T18:28:42,399][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, =\> at line 8, column  
8 (byte 101) after input {\n file {\n path =\> "D:/Personal/Test\_log\_files"\n type =\> "file"\n }\n\n filter {\n grok ", :backtrace=\>["D:/Personal/  
logstash-6.1.2/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/compiler.rb:50:in`com  
pile\_graph'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'",  
"D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/pipeline.rb:171:in `initialize'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/ pipeline_action/create.rb:40:in`execute'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/agent.rb:335:in `block in converge_state'", "D:/Personal/ logstash-6.1.2/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/agent.rb:332:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/agent.rb:319:in `converge_state'", "D:/Personal /logstash-6.1.2/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/agent.r  
b:141:in `with_pipelines'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "D:/Personal/logstash-6.1.2/  
logstash-core/lib/logstash/agent.rb:90:in `execute'", "D:/Personal/logstash-6.1.2/logstash-core/lib/logstash/runner.rb:343:in`block in execute'", "D:/Personal/  
logstash-6.1.2/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

the conf file im using is

input {  
file {  
path =\> "D:/Personal/Test\_log\_files"  
type =\> "file"  
}  
}  
filter {  
grok {  
match =\> [  
"message",  
"%{TIME:time} %{LOGLEVEL:level} [(?[^]]+)] ((?[^)]+)) %{GREEDYDATA:message}"  
]  
overwrite =\> ["message"]  
}  
date {  
match =\> ["time", "MMM dd YYYY HH:mm:ss,SSS"]  
remove\_field =\> ["time"]  
}  
}  
output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

can someone help me in understanding this

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 30, 2018, 2:12pm UTC](https://discuss.elastic.co/t/read-log-from-local-file/117628/2 "2018-01-30T14:12:07Z")

</div>

I suspect you have some kind of garbage (i.e. a non-printable character) after "grok" (or thereabouts). The configuration looks fine and when I copy/paste it to a local fine it passes the syntax check.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 27, 2018, 2:12pm UTC](https://discuss.elastic.co/t/read-log-from-local-file/117628/3 "2018-02-27T14:12:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
