# \[SOLVED\] Failed to execute PipelineAction::Create

**URL:** <https://discuss.elastic.co/t/solved-failed-to-execute-pipelineaction-create/222782>\
**Category:** Logstash\
**Created:** [March 9, 2020, 6:45pm UTC](https://discuss.elastic.co/t/solved-failed-to-execute-pipelineaction-create/222782 "2020-03-09T18:45:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alesabat](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@alesabat](https://discuss.elastic.co/u/alesabat)\
**Post date:** [March 9, 2020, 6:45pm UTC](https://discuss.elastic.co/t/solved-failed-to-execute-pipelineaction-create/222782/1 "2020-03-09T18:45:56Z")

</div>

Hi everyone!

I'm running ELK on docker. Everything works fine, but, since I added some grok patterns to my pipeline, logstash never start again.

This is the error message:

> [2020-03-09T18:10:36,634][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "{", ",", "]" at line 57, column 103 (byte 752) after filter {\n\tgrok {\n\t\tmatch =\> { "message" =\> ["(?%{MONTH:Mes} %{MONTHDAY:Dia}, %{YEAR:Anio} @ %{TIME:Hora}),"", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:41:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:49:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `block in compile_sources'", "org/jruby/RubyArray.java:2584:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:10:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:156:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:27:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:326:in `block in converge\_state'"]}

And this is my pipeline configuration file

> input {  
> beats {  
> port =\> 5046  
> }  
> }
> 
> filter {  
> grok {  
> match =\> { "message" =\> ["(?%{MONTH:Mes} %{MONTHDAY:Dia}, %{YEAR:Anio} @ %{TIME:Hora}),""%{WORD:Id}"",""%{USERNAME:Index}"",(?%{NUMBER}|),""%{WORD:Type}"",""%{UUID:AgentEphemeralID}"",""%{USERNAME:AgentHostname}"",""%{UUID:AgentId}"",%{WORD:AgentType},""(?%{INT}.%{INT}.%{INT})"",""(?%{INT}.%{INT}.%{INT})"",""%{HOSTNAME:HostName}"",%{WORD:InputType},""%{PATH:LogFilePath}"",""(?%{INT},%{INT},%{INT})"","%{QUOTEDSTRING:Message}",""(?%{MONTH:Mes} %{MONTHDAY:Dia}, %{YEAR:Anio} @ %{TIME:Hora})""";] }  
> }  
> }
> 
> output {  
> if "app" in [tags] {  
> elasticsearch {  
> hosts =\> ["elasticsearch:9200"]  
> user =\> "elastic"  
> password =\> "changeme"  
> action =\> "index"  
> index =\> "app"  
> }  
> }  
> }

I understand there's some syntax error, but can't find it. I guess is a very tricky grok patterk because all of the ", but this is how messages are.

I'll very appreciate any help.

---

<div class="post-metadata">

**Author:** ![alesabat](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@alesabat](https://discuss.elastic.co/u/alesabat)\
**Post date:** [March 9, 2020, 6:47pm UTC](https://discuss.elastic.co/t/solved-failed-to-execute-pipelineaction-create/222782/2 "2020-03-09T18:47:21Z")

</div>

I tried wrapping pattern with " ", , but none of those worked.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 9, 2020, 9:31pm UTC](https://discuss.elastic.co/t/solved-failed-to-execute-pipelineaction-create/222782/3 "2020-03-09T21:31:21Z")

</div>

You need to either escape the double quotes within the pattern, or use single quotes to surround the pattern rather than double quotes.

---

<div class="post-metadata">

**Author:** ![alesabat](https://avatars.discourse-cdn.com/v4/letter/a/d2c977/32.png) [@alesabat](https://discuss.elastic.co/u/alesabat)\
**Post date:** [March 10, 2020, 11:40am UTC](https://discuss.elastic.co/t/solved-failed-to-execute-pipelineaction-create/222782/4 "2020-03-10T11:40:54Z")

</div>

It worked! I just wrapped the grok pattern with single quotes and worked.

Thanks a lot!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2020, 11:40am UTC](https://discuss.elastic.co/t/solved-failed-to-execute-pipelineaction-create/222782/5 "2020-04-07T11:40:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
