# Unexpected character ('\<' (code 60)) - different behavior - ES cloud

**URL:** <https://discuss.elastic.co/t/unexpected-character-code-60-different-behavior-es-cloud/197535>\
**Category:** Logstash\
**Created:** [August 30, 2019, 2:31pm UTC](https://discuss.elastic.co/t/unexpected-character-code-60-different-behavior-es-cloud/197535 "2019-08-30T14:31:18Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hborda](https://avatars.discourse-cdn.com/v4/letter/h/90ced4/32.png) [@hborda](https://discuss.elastic.co/u/hborda)\
**Post date:** [August 30, 2019, 2:31pm UTC](https://discuss.elastic.co/t/unexpected-character-code-60-different-behavior-es-cloud/197535/1 "2019-08-30T14:31:18Z")

</div>

We read most of what have been written about the topic, we tried many permutations and we can't successfully make logstash to work:

Here is the console output  
start -----------------  
C:\Deleteme\es\_logstash\>C:\Software\ES\logstash-7.3.1\bin\logstash -f "/Deleteme/data.conf"  
Thread.exclusive is deprecated, use Thread::Mutex  
Sending Logstash logs to C:/Software/ES/logstash-7.3.1/logs which is now configured via log4j2.properties  
[2019-08-30T09:36:25,271][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-08-30T09:36:25,302][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"7.3.1"}  
[2019-08-30T09:36:27,548][INFO][org.reflections.Reflections] Reflections took 63 ms to scan 1 urls, producing 19 keys and 39 values  
[2019-08-30T09:36:31,235][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[https://elastic:xxxxxx@fb48cb04fcd4b33e24075e0b3773c89b.us-east-1.aws.found.io:9243/](https://elastic:xxxxxx@fb48cb04fcd4b33e24075e0b3773c89b.us-east-1.aws.found.io:9243/)]}}  
[2019-08-30T09:36:32,024][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"https://:9243/"}  
[2019-08-30T09:36:32,412][ERROR][logstash.javapipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<LogStash::Json::ParserError: Unexpected character ('\<' (code 60)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')  
at [Source: (byte)"Kibana/\* INTER UI FONT _/  
/_ INTER UI FONT _/  
/_ INTER UI FONT _/  
/_ INTER UI FONT \*/  
@font-face {  
font-family: 'Inter UI';  
font-style: normal;  
font-weight: 100;  
src: url("/ui/fonts/inter\_ui/Inter-UI-Thin-BETA.woff2") format("woff2"),  
url("/ui/fonts/inter\_ui/Inter-UI-Thin-BETA.woff") format"[truncated 79642 bytes]; line: 1, column: 2]\>, :backtrace  
end ------------------

We also tried port 9200  
We also tried without https://

Here is the sample data  
start -----------------  
badge,firstname,lastname  
1,john,smith  
2,mary,cooper  
end ------------------

Here is the configuration file  
start -----------------  
input {  
file {  
path =\> "/Deleteme/data.csv"  
sincedb\_path =\> "/Deleteme/null"  
start\_position =\> "beginning"  
}  
}  
filter {  
csv {  
separator =\> ","  
skip\_header =\> "true"  
columns =\> ["badge","firstname","lastname"]  
}  
mutate {convert =\> ["badge", "integer"]}  
}  
output {  
elasticsearch{  
hosts =\> ["https://:9243"]  
user =\> "elastic"  
password =\> ""  
index =\> "mytest"  
}  
stdout {}  
}  
end ------------------

Here is how do we run it (in windows)  
start -----------------  
C:\Software\ES\logstash-7.3.1\bin\logstash -f "/Deleteme/data.conf"  
end ------------------

We also tried running from some Mac laptops and we got the same behavior/error, which make us believe we are doing something wrong.

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 30, 2019, 3:10pm UTC](https://discuss.elastic.co/t/unexpected-character-code-60-different-behavior-es-cloud/197535/2 "2019-08-30T15:10:31Z")

</div>

> [@hborda](#):
>
> Unexpected character ('\<' (code 60)): expected a valid value (number, String, array, object, 'true', 'false' or 'null')  
> at [Source: (byte)"Kibana/\* INTER UI FONT _/  
> /_ INTER UI FONT _/  
> /_ INTER UI FONT _/  
> /_ INTER UI FONT \*/  
> @font-face {  
> font-family: 'Inter UI';  
> font-style: normal;  
> font-weight: 100;

That looks to me as though you have pointed the elasticsearch output at a Kibana instance rather than an elasticsearch instance.

---

<div class="post-metadata">

**Author:** ![hborda](https://avatars.discourse-cdn.com/v4/letter/h/90ced4/32.png) [@hborda](https://discuss.elastic.co/u/hborda)\
**Post date:** [August 30, 2019, 3:24pm UTC](https://discuss.elastic.co/t/unexpected-character-code-60-different-behavior-es-cloud/197535/3 "2019-08-30T15:24:03Z")

</div>

You were 100% correct I was using the wrong instance id, thanks for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 3:24pm UTC](https://discuss.elastic.co/t/unexpected-character-code-60-different-behavior-es-cloud/197535/4 "2019-09-27T15:24:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
