# Command line works, service does not

**URL:** <https://discuss.elastic.co/t/command-line-works-service-does-not/102857>\
**Category:** Logstash\
**Created:** [October 5, 2017, 3:05pm UTC](https://discuss.elastic.co/t/command-line-works-service-does-not/102857 "2017-10-05T15:05:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Frizz\_Supertramp](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@Frizz\_Supertramp](https://discuss.elastic.co/u/Frizz_Supertramp)\
**Post date:** [October 5, 2017, 3:05pm UTC](https://discuss.elastic.co/t/command-line-works-service-does-not/102857/1 "2017-10-05T15:05:54Z")

</div>

I have a very simple config that should produce tons of output:

```
input {
  file {
    path => "/var/log/glusterfs/*.log"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}
output {
	stdout { codec => rubydebug }
}

```

When running from command line it does, when running as a service it does not.

I've enabled debugging in the conf file, but all I get is this:

```
[2017-10-05T17:03:17,276][DEBUG][logstash.pipeline] Pushing flush onto pipeline
[2017-10-05T17:03:21,386][DEBUG][logstash.inputs.file] _globbed_files: /var/log/glusterfs/*.log: glob is: ["/var/log/glusterfs/glustershd.log", "/var/log/glusterfs/test.log", "/var/log/glusterfs/cli.log", "/var/log/glusterfs/glusterd.log", "/var/log/glusterfs/events.log", "/var/log/glusterfs/cmd_history.log"]
[2017-10-05T17:03:22,276][DEBUG][logstash.pipeline] Pushing flush onto pipeline
[2017-10-05T17:03:27,275][DEBUG][logstash.pipeline] Pushing flush onto pipeline

```

But no output to stdout (same for file or gelf or any other output).

**Edit:** I narrowed it down a little bit more: When running this line

`/usr/share/logstash/bin/logstash -f glusterfs.conf --path.settings etc/logstash`

.... as root it works. When running the same line as user logstash it does not work. I have set "log.level: trace" in logstash.yml, but no errors or warnings show in the logfile.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2017, 7:42pm UTC](https://discuss.elastic.co/t/command-line-works-service-does-not/102857/2 "2017-10-05T19:42:51Z")

</div>

Does the logstash user have read access to the log files?

---

<div class="post-metadata">

**Author:** ![Frizz\_Supertramp](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@Frizz\_Supertramp](https://discuss.elastic.co/u/Frizz_Supertramp)\
**Post date:** [October 6, 2017, 9:27am UTC](https://discuss.elastic.co/t/command-line-works-service-does-not/102857/3 "2017-10-06T09:27:46Z")

</div>

Yes. Out of desperation I even changed it to 777 - still not working.

I'd be happy if Logstash would give me a hint why it's not working 😉

What can I do to get more information (log.level is already at "trace")?

[Edit] What I don't understand is why the files are not discovered. I mean I see lines like this:

```
_globbed_files: /var/log/glusterfs/*.log: glob is: ["/var/log/glusterfs/glustershd.log", "...

```

But no lines like this:

```
_discover_file: /var/log/glusterfs/*.log: new: /var/log/glusterfs/glustershd.log
_discover_file: /var/log/glusterfs/*.log: new: /var/log/glusterfs/cli.log
```

---

<div class="post-metadata">

**Author:** ![jakelandis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jakelandis/32/36163_2.png) [@jakelandis](https://discuss.elastic.co/u/jakelandis)\
**Post date:** [October 6, 2017, 3:36pm UTC](https://discuss.elastic.co/t/command-line-works-service-does-not/102857/4 "2017-10-06T15:36:38Z")

</div>

When using stdout with a service, you will need to find where the stdout gets logged. For example for systemD based Linux distro's you can find it via journalctl.

```auto
journalctl -r -u logstash

```

or to tail it:

```auto
journalctl -f -u logstash

```

---

<div class="post-metadata">

**Author:** ![Frizz\_Supertramp](https://avatars.discourse-cdn.com/v4/letter/f/3bc359/32.png) [@Frizz\_Supertramp](https://discuss.elastic.co/u/Frizz_Supertramp)\
**Post date:** [October 6, 2017, 8:06pm UTC](https://discuss.elastic.co/t/command-line-works-service-does-not/102857/5 "2017-10-06T20:06:54Z")

</div>

I am not using a service with stdout. I run logstash from a command line (at least for testing). One time as user root (working), one time as user logstash (not working)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2017, 8:07pm UTC](https://discuss.elastic.co/t/command-line-works-service-does-not/102857/6 "2017-11-03T20:07:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
