# Can not get kibana logs

**URL:** <https://discuss.elastic.co/t/can-not-get-kibana-logs/80058>\
**Category:** Kibana\
**Created:** [March 27, 2017, 12:23am UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058 "2017-03-27T00:23:16Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![informatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/informatico/32/15065_2.png) [@informatico](https://discuss.elastic.co/u/informatico)\
**Post date:** [March 27, 2017, 12:23am UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/1 "2017-03-27T00:23:16Z")

</div>

I am unable to get kibana logs.

**/var/log/kibana/kibana.stdout** as well as **kibana.stderr** seem to have no logs being written to them (I am getting undefined errors in my Kibana)

In the kibana.yml file, I have then also set  
`logging.dest: /var/logs/kibana.log`  
while inserting a kibana.log file into this directory... but again nothing is being written to the file.

How do I obtain the Kibana logs?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 27, 2017, 5:16am UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/2 "2017-03-27T05:16:03Z")

</div>

Hi @informatico,

the default log file location depends on the package. Which package format did you use to install Kibana (deb, rpm, tgz)?

---

<div class="post-metadata">

**Author:** ![informatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/informatico/32/15065_2.png) [@informatico](https://discuss.elastic.co/u/informatico)\
**Post date:** [March 27, 2017, 9:21am UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/3 "2017-03-27T09:21:48Z")

</div>

I believe the RPMs were downloaded directly, so where would they be in this case?

Thanks

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 27, 2017, 10:55am UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/4 "2017-03-27T10:55:00Z")

</div>

The default log output destination depends on the init system your linux distribution uses:

For SysV stdout and stderr of Kibana would be written to `/var/log/kibana.{stdout,stderr}`. Changing `logging.dest` to something besides `stdout` will cause these files to be empty. One thing to keep in mind is that the Kibana process needs to have write access to these files or the file configured in `logging.dest`. The default init script should take care of that.

For systemd the output is captured by `journald` and can be inspected using `journalctl`.

---

<div class="post-metadata">

**Author:** ![informatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/informatico/32/15065_2.png) [@informatico](https://discuss.elastic.co/u/informatico)\
**Post date:** [March 27, 2017, 3:47pm UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/5 "2017-03-27T15:47:09Z")

</div>

I figured it must be permissions as it was `-rw-r--r--` for both files.

So I performed `chmod ugoa+rwx` on both files, to give all users all kinds of permissions, just to see what errors are being written.... however still nothing is being written to the file ☹

`logging.dest` is `stdout` in the kibana.yml file.

Any ideas?

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 27, 2017, 4:07pm UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/6 "2017-03-27T16:07:03Z")

</div>

How are you starting Kibana? Via SysV Init, systemd or a custom way?

---

<div class="post-metadata">

**Author:** ![informatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/informatico/32/15065_2.png) [@informatico](https://discuss.elastic.co/u/informatico)\
**Post date:** [March 27, 2017, 7:00pm UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/7 "2017-03-27T19:00:37Z")

</div>

Kibana is running in a Centos 7 VM.

systemd was used to start Kibana via systemctl command

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 28, 2017, 9:35am UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/8 "2017-03-28T09:35:13Z")

</div>

Under systemd with `logging.dest` on default or set to `stdout` you should be able to see the Kibana output using `journalctl -u kibana.service` (assuming the Kibana unit file is called `kibana.service`).

---

<div class="post-metadata">

**Author:** ![informatico](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/informatico/32/15065_2.png) [@informatico](https://discuss.elastic.co/u/informatico)\
**Post date:** [March 28, 2017, 11:58am UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/9 "2017-03-28T11:58:08Z")

</div>

When I invoke that I get :  
`No journal files were found.`  
`-- No entries --`  
kibana.service is located in ./etc/systemd/system/

I guess this is the problem? I have restarted systemd-jounald, but have had no luck.  
Am I supposed to create this file manually? If so.. how and where?

Sorry this thread is going on a little, I'm a really nooby. Ultimately I am trying to get to the bottom of a 404 error I am getting with the Kibana reporting plugin (thread: [https://discuss.elastic.co/t/reporting-error-404-and-kibana-unable-to-connect/](https://discuss.elastic.co/t/reporting-error-404-and-kibana-unable-to-connect/) ).

I really appreciate your help here Felix. Many thanks.

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [March 28, 2017, 2:15pm UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/10 "2017-03-28T14:15:53Z")

</div>

Don't worry, that's what this forum is here for. 🙂

I'm not very familiar with CentOS 7, but it seems that it is using `journald` only for transient logs and still forwards them to `rsyslogd`. So whether `rsyslogd` persists the log anywhere depends on your configuration.

To enable persistence of the `journald` journal a directory called `/var/log/journal` must be created (according to chapter 20.10.5. of the [RHEL7 System Admin Guide](https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System_Administrators_Guide/s1-Using_the_Journal.html)).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2017, 2:16pm UTC](https://discuss.elastic.co/t/can-not-get-kibana-logs/80058/11 "2017-04-25T14:16:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
