# Cannot get any output

**URL:** <https://discuss.elastic.co/t/cannot-get-any-output/84531>\
**Category:** Logstash\
**Created:** [May 4, 2017, 10:29am UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531 "2017-05-04T10:29:19Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jagan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jagan/32/42200_2.png) [@jagan](https://discuss.elastic.co/u/jagan)\
**Post date:** [May 4, 2017, 10:29am UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531/1 "2017-05-04T10:29:19Z")

</div>

HI All,  
i recently upgraded to logstash-5.3.2.when i ran a 'x.conf' file in logstash i get the below message: INFO logstash.agent - Successfully started Logstash API endpoint {:port=\>96000} but i could not see the output without anything displayed for some time an nothing can be moving forward.  
could anybody suggest me how to resolve the issue.

Regards,  
Jagan

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2017, 10:34am UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531/2 "2017-05-04T10:34:43Z")

</div>

What's the entire config look like?

---

<div class="post-metadata">

**Author:** ![jagan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jagan/32/42200_2.png) [@jagan](https://discuss.elastic.co/u/jagan)\
**Post date:** [May 4, 2017, 11:14am UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531/3 "2017-05-04T11:14:19Z")

</div>

Thanks for the reply Mark,  
the config file looks like this:  
input {  
file {  
path =\> "/home/ubuntu/log/test.log-20170303"  
#port =\> 5044  
#ssl =\> false  
#client\_inactivity\_timeout =\> "86400"  
start\_position =\> "beginning"  
}

}

filter {  
if [type] == "log" {  
if "dev1" in [message] { drop{} }  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program} |%{NUMBER:epoch:int}|%{IP:ip}|%{GREEDYDATA:path}|%{GREEDYDATA:title}|%{GREEDYDATA:referrer}|%{NUMBER:uid}|%{GREEDYDATA:sid}|%{NUMBER:timer:int}|%{GREEDYDATA:cache}|%{GREEDYDATA:user\_agent}|%{NUMBER:peak\_memory:int}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
overwrite =\> ["message"]  
}

```
   mutate {
   convert => ["[geoip][coordinates]", "float"]
   }
   mutate {
   convert => { "timer" => "integer" }
   convert => { "epoch" => "integer" }
   convert => { "peak_memory" => "integer" }
   }
   useragent {
     source => "user_agent"
   }
   syslog_pri { }
   date {
     match => ["epoch", "UNIX"]
   }
 }

```

}

output {  
if [type] == "log" {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
timeout =\> 30000  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}  
}

This is the line where logstash is stuck:  
Sending Logstash's logs to /usr/share/logstash/logs which is now configured via log4j2.properties....nothing moving forward from here..

Thanks,  
jagan

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 4, 2017, 11:19am UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531/4 "2017-05-04T11:19:20Z")

</div>

It's likely a sincedb issue then, try checking the docs and previous threads 🙂

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 4, 2017, 11:20am UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531/5 "2017-05-04T11:20:42Z")

</div>

> [@jagan](#):
>
> document\_type =\> "%{[@metadata][type]}"

You appear to have changed from a beats input to a file input. I therefore suspect that the metadata variables are no longer defined and that you end up with an invalid type, preventing anything to be written to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![jagan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jagan/32/42200_2.png) [@jagan](https://discuss.elastic.co/u/jagan)\
**Post date:** [May 4, 2017, 11:36am UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531/6 "2017-05-04T11:36:11Z")

</div>

Yes Christian,  
Actually the setup is done to move the data from filebeat-\> Logstash-\> elasticSearch, but it is not working, so i want to see if i can load directly from logstash to Elasticsearch?

Before this issue an index which is building is terminated in between, so can that create any ripples in the data loading issues?  
Thanks once again!

---

<div class="post-metadata">

**Author:** ![elbesraoui\_imane](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elbesraoui_imane/32/17700_2.png) [@elbesraoui\_imane](https://discuss.elastic.co/u/elbesraoui_imane)\
**Post date:** [May 10, 2017, 3:07pm UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531/7 "2017-05-10T15:07:12Z")

</div>

Hi jagan,  
I have the same issue as you and it shows me the same thing :  
Sending Logstash's logs to /usr/share/logstash/logs which is now configured via log4j2.properties  
Could you suggest me how to resolve this if you have found any solutions.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2017, 3:07pm UTC](https://discuss.elastic.co/t/cannot-get-any-output/84531/8 "2017-06-07T15:07:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
