# Something is wrong with you config

**URL:** <https://discuss.elastic.co/t/something-is-wrong-with-you-config/184972>\
**Category:** Logstash\
**Created:** [June 10, 2019, 11:00am UTC](https://discuss.elastic.co/t/something-is-wrong-with-you-config/184972 "2019-06-10T11:00:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![AtulxD123](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@AtulxD123](https://discuss.elastic.co/u/AtulxD123)\
**Post date:** [June 10, 2019, 11:00am UTC](https://discuss.elastic.co/t/something-is-wrong-with-you-config/184972/1 "2019-06-10T11:00:11Z")

</div>

Following is my config file for the following log file.

input :

input {  
file {  
path =\> "/Users/atul.maurya/Desktop/Data1/squery1.txt"  
start\_position =\> "beginning"  
since\_db =\> "NUL"

```
codec => multiline {
  pattern => "^# User@Host:"
  negate => true
  what => previous
}

```

}  
}  
filter {  
grok {  
match =\> {  
message =\> [  
"# User@Host: %{USER:user}[[^]+]] @ %{HOST:host} [%{IP:ip}?\ \s_Id: %{NUMBER:id:int}]",  
"# Query\_time: %{NUMBER:duration:float} \s_Lock\_time: %{NUMBER:lock\_wait:float} \s_Rows\_sent: %{NUMBER:results:int} \s_Rows\_examined: %{NUMBER:scanned:int}",  
"use channelplay\_%{:client};",  
"SET timestamp=%{NUMBER:timestamp};",  
"%{GREEDYDATA}"  
]  
}  
}  
date {  
match =\> ["timestamp" , "UNIX"]  
}  
mutate {  
remove\_field =\> "timestamp"  
}  
}

output {  
stdout {  
codec =\> dots {}  
}

elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "slow1"  
}  
}

and following is the log

# Time: 190606 9:23:13

# User@Host: db\_usr\_retaility[db\_usr\_retaility] @ [10.0.2.8] Id: 448634

# Query\_time: 10.587880 Lock\_time: 0.000429 Rows\_sent: 81 Rows\_examined: 17762397

use channelplay\_pernorica;  
SET timestamp=1559793193;  
SELECT MMP.master\_id, P.project\_id, P.parent\_outlet,  
UM.user\_revision\_id, PM.project\_revision\_id FROM  
`cp_cm_user_prj_role_owner_assign` PA INNER JOIN cp\_cm\_project P ON  
PA.project\_id = P.project\_id INNER JOIN cp\_project\_role PR ON  
PA.project\_id = PR.project\_id AND PA.role\_id = PR.role\_id INNER JOIN  
cp\_cm\_roles\_mobile\_access R ON PR.prj\_role\_id = R.prj\_role\_id INNER  
JOIN cp\_cm\_menu\_mobile MM ON R.menu\_id = MM.menu\_id INNER JOIN  
cp\_inbound\_menu\_mapping MMP ON MM.menu\_id = MMP.menu\_id LEFT JOIN  
(SELECT MAX(id) AS user\_revision\_id, master\_id, project\_id FROM  
`cp_cm_revision_user_master` GROUP BY master\_id, project\_id ) UM ON  
P.project\_id = UM.project\_id AND MMP.master\_id = UM.master\_id LEFT JOIN  
(SELECT MAX(id) AS project\_revision\_id, master\_id, project\_id FROM  
`cp_cm_revision_project_master` GROUP BY master\_id, project\_id ) PM ON  
P.project\_id = PM.project\_id AND MMP.master\_id = PM.master\_id WHERE  
PA.user\_id = 1995 AND R.access IN (1) AND P.is\_active = 1 AND PA.active  
= 1 GROUP BY MMP.master\_id, P.project\_id;

# Time: 190606 9:25:06

# User@Host: db\_usr\_retaility[db\_usr\_retaility] @ [10.0.2.7] Id: 452567

# Query\_time: 10.557897 Lock\_time: 0.000501 Rows\_sent: 41 Rows\_examined: 17762035

use channelplay\_pernorica;  
SET timestamp=1559793306;  
SELECT MMP.master\_id, P.project\_id, P.parent\_outlet,  
UM.user\_revision\_id, PM.project\_revision\_id FROM  
`cp_cm_user_prj_role_owner_assign` PA INNER JOIN cp\_cm\_project P ON  
PA.project\_id = P.project\_id INNER JOIN cp\_project\_role PR ON  
PA.project\_id = PR.project\_id AND PA.role\_id = PR.role\_id INNER JOIN  
cp\_cm\_roles\_mobile\_access R ON PR.prj\_role\_id = R.prj\_role\_id INNER  
JOIN cp\_cm\_menu\_mobile MM ON R.menu\_id = MM.menu\_id INNER JOIN  
cp\_inbound\_menu\_mapping MMP ON MM.menu\_id = MMP.menu\_id LEFT JOIN  
(SELECT MAX(id) AS user\_revision\_id, master\_id, project\_id FROM  
`cp_cm_revision_user_master` GROUP BY master\_id, project\_id ) UM ON  
P.project\_id = UM.project\_id AND MMP.master\_id = UM.master\_id LEFT JOIN  
(SELECT MAX(id) AS project\_revision\_id, master\_id, project\_id FROM  
`cp_cm_revision_project_master` GROUP BY master\_id, project\_id ) PM ON  
P.project\_id = PM.project\_id AND MMP.master\_id = PM.master\_id WHERE  
PA.user\_id = 2088 AND R.access IN (1) AND P.is\_active = 1 AND PA.active  
= 1 GROUP BY MMP.master\_id, P.project\_id;

# Time: 190606 9:25:14

error faced at config

Something is wrong with your configuration.", :backtrace=\>["C:/Users/atul.maurya/Desktop/loger/logstash-core/lib/logstash/config/mixin.rb:86:in `config_init'", "C:/Users/atul.maurya/Desktop/loger/logstash-core/lib/logstash/inputs/base.rb:60:in`initialize'", "org/logstash/plugi

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 10, 2019, 12:51pm UTC](https://discuss.elastic.co/t/something-is-wrong-with-you-config/184972/2 "2019-06-10T12:51:23Z")

</div>

> [@AtulxD123](#):
>
> Something is wrong with your configuration

There should be another error message preceding this one.

---

<div class="post-metadata">

**Author:** ![AtulxD123](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@AtulxD123](https://discuss.elastic.co/u/AtulxD123)\
**Post date:** [June 10, 2019, 3:38pm UTC](https://discuss.elastic.co/t/something-is-wrong-with-you-config/184972/3 "2019-06-10T15:38:27Z")

</div>

# Query\_time: 10.587880 Lock\_time: 0.000429 Rows\_sent: 81 Rows\_examined: 17762397

grok {  
match =\> ["message" , "^# Query\_time: %{NUMBER:dur:float}",\s+Lock\_time: %{NUMBER:wait:float} Rows\_sent: %{NUMBER:rows:int} \s\*Rows\_examined: %{NUMBER:examined:int}"]  
}

Ran this in grokdebugger but it shows no match found.

---

<div class="post-metadata">

**Author:** ![AtulxD123](https://avatars.discourse-cdn.com/v4/letter/a/df788c/32.png) [@AtulxD123](https://discuss.elastic.co/u/AtulxD123)\
**Post date:** [June 10, 2019, 4:16pm UTC](https://discuss.elastic.co/t/something-is-wrong-with-you-config/184972/4 "2019-06-10T16:16:33Z")

</div>

input {  
file {  
type =\> "tomcat"  
path =\> "/Users/atul.maurya/Desktop/Data1/tom.txt"  
start\_position =\> "beginning"  
since\_db =\> "NUL"  
}  
}  
filter  
{  
multiline {  
patterns\_dir =\> "/Users/atul.maurya/Desktop/pattern"  
pattern =\> "(^%{TOMCAT\_DATESTAMP})|(^%{CATALINA\_DATESTAMP})"  
negate =\> true  
what =\> "previous"  
}  
if "\_grokparsefailure" in [tags] {  
drop { }  
}  
grok {  
patterns\_dir =\> "/Users/atul.maurya/Desktop/pattern"  
match =\> ["message", "%{TOMCATLOG}", "message", "%{CATALINALOG}"]  
}  
date {  
match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss,SSS Z", "MMM, dd, yyyy HH:mm:ss a"]  
}  
}

output {

stdout {  
codec =\> dots {}  
}  
elasticsearch {  
embedded =\> true  
index =\> "tom"  
}  
}

pattern list :

JAVACLASS (?:[a-zA-Z0-9-]+.)+[A-Za-z0-9$]+  
JAVALOGMESSAGE (.\*)  
CATALINA\_DATESTAMP %{MONTH} %{MONTHDAY}, 20%{YEAR} %{HOUR}:?%{MINUTE}(?::?%{SECOND}) (?:AM|PM)  
TOMCAT\_DATESTAMP 20%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{HOUR}:?%{MINUTE}(?::?%{SECOND}) %{ISO8601\_TIMEZONE}  
CATALINALOG %{CATALINA\_DATESTAMP:timestamp} %{JAVACLASS:class} %{JAVALOGMESSAGE:logmessage}  
TOMCATLOG %{TOMCAT\_DATESTAMP:timestamp} | %{LOGLEVEL:level} | %{JAVACLASS:class} - %{JAVALOGMESSAGE:logmessage}

still error : something wrong with your config. please help !

Getting same error on different log files

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 8, 2019, 4:21pm UTC](https://discuss.elastic.co/t/something-is-wrong-with-you-config/184972/5 "2019-07-08T16:21:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
