# Unstructured Tomcat Logs

**URL:** <https://discuss.elastic.co/t/unstructured-tomcat-logs/282190>\
**Category:** Logstash\
**Created:** [August 23, 2021, 6:32am UTC](https://discuss.elastic.co/t/unstructured-tomcat-logs/282190 "2021-08-23T06:32:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dipinsugathan](https://avatars.discourse-cdn.com/v4/letter/d/ad7895/32.png) [@dipinsugathan](https://discuss.elastic.co/u/dipinsugathan)\
**Post date:** [August 23, 2021, 6:32am UTC](https://discuss.elastic.co/t/unstructured-tomcat-logs/282190/1 "2021-08-23T06:32:27Z")

</div>

Hi All,

Need help in ingesting tomcat unstructured logs to ELK. While ingesting via filebeat -\>logstash-\>elasticsearch -\> kibana

everything is coming in one message field. I was trying to split it with mutate filter plugin but getting exceptions. pasting my logstash.yml

![Screenshot from 2021-08-23 12-01-35](https://us1.discourse-cdn.com/elastic/original/3X/d/d/dd3c8b7d9f3b4cc2068041fc1da00b5f6f0d7873.png)

logstash/log.yml

input {  
beats {  
port =\> 5044  
}  
}

filter {  
mutate {  
split =\> { "message" =\> ":" }  
add\_field =\> {  
"Client\_IP" =\> "%{[message][0]}"  
"Method" =\> "%{[message][1]}"  
"URL" =\> "%{[message][2]}"  
"Bytes" =\> "%{[message][3]}"  
"Duration" =\> "%{[message][4]}"

```
    }

```

}

output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}"  
}  
}

while restarting logstash getting following exception. Pls help

[2021-08-23T11:51:01,479][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "=\>" at line 21, column 17 (byte 409) after filter {\n mutate {\n split =\> { "message" =\> ":" }\n add\_field =\> {\n "Client\_IP" =\> "%{[message][0]}"\n "Method" =\> "%{[message][1]}"\n "URL" =\> "%{[message][2]}"\n "Bytes" =\> "%{[message][3]}"\n "Duration" =\> "%{[message][4]}"\n \t\n }\n}\n\noutput {\n elasticsearch ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:187:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:72:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:52:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:391:in `block in converge\_state'"]}  
[2021-08-23T11:51:01,614][INFO][logstash.runner] Logstash shut down.  
[2021-08-23T11:51:01,623][FATAL][org.logstash.Logstash] Logstash stopped processing because of an error: (SystemExit) exit  
org.jruby.exceptions.SystemExit: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [August 23, 2021, 8:28am UTC](https://discuss.elastic.co/t/unstructured-tomcat-logs/282190/2 "2021-08-23T08:28:18Z")

</div>

Hi,

You don't close the filter.  
A closing curly bracket is missing before the output part.

Cad.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2021, 8:28am UTC](https://discuss.elastic.co/t/unstructured-tomcat-logs/282190/3 "2021-09-20T08:28:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
