Docker部署Logstash 7.10.1时遭遇配置错误:Expected one of [ \t\r\n], "#", "input", "filter", "output"
Let's work through this frustrating error step by step—there are a couple of key issues likely causing this, and we'll fix them one by one.
First: The UTF-8 BOM is breaking the config parser
You mentioned converting the file to "带BOM的Unix(LF)格式" (UTF-8 with BOM) in Notepad++, but that's exactly one of the most common triggers for this error. Logstash's configuration parser doesn't recognize the hidden BOM character at the start of the file—it sees that character as invalid, so it throws an error saying it can't find a valid opening to the config (like input, filter, etc.).
Fix this first:
- Open your
logstash.confin Notepad++ - Go to the Encoding menu at the top
- Select Convert to UTF-8 without BOM
- Save the file, then re-mount it to your Docker container and try running Logstash again.
Second: Your input block has a syntax mistake
Looking at your config, I spotted another critical issue: your input parameters aren't wrapped in the mongodb plugin block. Logstash requires you to explicitly specify which input plugin you're using, and wrap its parameters inside that plugin's curly braces.
Your original input looks like this:
input { uri => "mongodb://admin:pass@localhost:27017/programs?ssl=true" # ... other parameters }
It should look like this (note the mongodb {} wrapper):
input { mongodb { uri => "mongodb://admin:pass@localhost:27017/programs?ssl=true" placeholder_db_dir => "/opt/logstash-mongodb/" placeholder_db_name => "logstash_sqlite.db" collection => "programs" batch_size => 5000 } }
Third: Ensure the MongoDB input plugin is installed
The MongoDB input plugin isn't included in the default Logstash 7.10.1 Docker image. You need to add it to your Dockerfile when building the image:
FROM docker.elastic.co/logstash/logstash:7.10.1 # Install the MongoDB input plugin RUN logstash-plugin install logstash-input-mongodb # Copy your custom config COPY logstash.conf /usr/share/logstash/pipeline/
Test your config before running
To avoid guesswork, test your config directly in the Docker container with this command:
docker exec -it <your-logstash-container-name> logstash -f /usr/share/logstash/pipeline/logstash.conf --config.test_and_exit
This will validate your config syntax and tell you exactly where any remaining issues are.
Putting all these steps together should resolve that "expected one of..." error and get your Logstash pipeline running.
内容的提问来源于stack exchange,提问作者Vincent Decaux

