# Upgraded to 1.5.0, config check throwing errors

**URL:** <https://discuss.elastic.co/t/upgraded-to-1-5-0-config-check-throwing-errors/820>\
**Category:** Logstash\
**Created:** [May 18, 2015, 6:21am UTC](https://discuss.elastic.co/t/upgraded-to-1-5-0-config-check-throwing-errors/820 "2015-05-18T06:21:42Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![matejzero](https://avatars.discourse-cdn.com/v4/letter/m/e9bcb4/32.png) [@matejzero](https://discuss.elastic.co/u/matejzero)\
**Post date:** [May 18, 2015, 6:21am UTC](https://discuss.elastic.co/t/upgraded-to-1-5-0-config-check-throwing-errors/820/1 "2015-05-18T06:21:42Z")

</div>

Hello!

Today I tried to upgrade from 1.4.2 to 1.5.0 on one of my nodes, but config check throws error right away:  
SyntaxError: (eval):4072: syntax error, unexpected kNOT  
"\_grok\_postfix\_success" not in [tags] and  
^  
eval at org/jruby/RubyKernel.java:1107  
initialize at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.0-java/lib/logstash/pipeline.rb:30  
execute at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.0-java/lib/logstash/agent.rb:109  
run at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.0-java/lib/logstash/runner.rb:87  
call at org/jruby/RubyProc.java:271  
run at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-1.5.0-java/lib/logstash/runner.rb:92  
call at org/jruby/RubyProc.java:271  
initialize at /opt/logstash/vendor/bundle/jruby/1.9/gems/stud-0.0.19/lib/stud/task.rb:12

In config file, I have the following:  
### Mark not parsed logs with 'drop' tag  
if "\_grok\_postfix\_success" not in [tags] {  
mutate {  
add\_tag =\> ['drop']  
}  
}

All this works normally on 1.4.2. What am I not seeing?

Matej

---

<div class="post-metadata">

**Author:** ![matejzero](https://avatars.discourse-cdn.com/v4/letter/m/e9bcb4/32.png) [@matejzero](https://discuss.elastic.co/u/matejzero)\
**Post date:** [May 18, 2015, 11:36am UTC](https://discuss.elastic.co/t/upgraded-to-1-5-0-config-check-throwing-errors/820/2 "2015-05-18T11:36:19Z")

</div>

It looks like it was a mistake on my end.  
I had an 'if' statement written in multi-line instead of one.

Example:

```
  if "parsed" not in [tags] and 
  "_grok_postfix_success" not in [tags] and
  "_grok_dovecot_success" not in [tags] {
    file {
      codec => json
      path => "/var/log/logstash/drop-%{type}.log"
    }
  }

```

instead of whole 'if' sentence in one line:

```
  if "parsed" not in [tags] and "_grok_postfix_success" not in [tags] and "_grok_dovecot_success" not in [tags] {
    file {
      codec => json
      path => "/var/log/logstash/drop-%{type}.log"
    }
  }

```

After fixing that, there was no more errors about 'not in'.

Matej

---

<div class="post-metadata">

**Author:** ![jordansissel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordansissel/32/44957_2.png) [@jordansissel](https://discuss.elastic.co/u/jordansissel)\
**Post date:** [May 19, 2015, 7:15pm UTC](https://discuss.elastic.co/t/upgraded-to-1-5-0-config-check-throwing-errors/820/3 "2015-05-19T19:15:43Z")

</div>

This is reported here:

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/upgraded-to-1-5-0-config-check-throwing-errors/820/4 "2017-07-06T05:39:39Z")

</div>


