# Config problem with logstash

**URL:** <https://discuss.elastic.co/t/config-problem-with-logstash/138194>\
**Category:** Logstash\
**Created:** [July 2, 2018, 11:44am UTC](https://discuss.elastic.co/t/config-problem-with-logstash/138194 "2018-07-02T11:44:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankit211](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@ankit211](https://discuss.elastic.co/u/ankit211)\
**Post date:** [July 2, 2018, 11:44am UTC](https://discuss.elastic.co/t/config-problem-with-logstash/138194/1 "2018-07-02T11:44:12Z")

</div>

in loagstash choosing correct path alougth it's not config properly.  
file given below.

input {  
file {  
path =\> "C:\Ankit\kibana\_files\Client\_4\_May\_2018\_16\_31.csv"  
start\_position =\> "beginning"  
sincedb\_path=\>"c:\Ankit\kibana\_files"  
}  
}  
filter {  
csv{  
separator =\> ","  
columns =\> ["log\_id","msg string","ID","Version","date"]  
}  
date {  
match =\> ["date", "MM/dd/yyyy hh:mm"]  
target =\> "date"  
}  
mutate {  
convert =\> {  
"log\_id" =\> "integer"  
"ID" =\> "integer"  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> "localhost"  
index =\> "error"  
}  
stdout {codec =\> rubydebug}  
}

In logstash:  
logstash -f c:\ankit\kibana\_files\test\_error\_1.conf

it's not working?  
i can not creat proper index pattern?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 2, 2018, 11:49am UTC](https://discuss.elastic.co/t/config-problem-with-logstash/138194/2 "2018-07-02T11:49:09Z")

</div>

Comment out your elasticsearch output. Are you getting anything from your stdout output? Have you tried deleting the sincedb file?

---

<div class="post-metadata">

**Author:** ![ankit211](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@ankit211](https://discuss.elastic.co/u/ankit211)\
**Post date:** [July 3, 2018, 6:47am UTC](https://discuss.elastic.co/t/config-problem-with-logstash/138194/3 "2018-07-03T06:47:15Z")

</div>

this kindof issue i face during logstash install  
confi file is above.

[2018-07-02T13:32:33,413][INFO][logstash.setting.writabledirectory] Creating directory {:setting=\>"path.queue", :path=\>"C:/Ankit/tools/logstash-6.3.0/data/queue"}  
[2018-07-02T13:32:33,413][INFO][logstash.setting.writabledirectory] Creating directory {:setting=\>"path.dead\_letter\_queue", :path=\>"C:/Ankit/tools/logstash-6.3.0/data/dead\_letter\_queue"}  
[2018-07-02T13:32:33,569][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-07-02T13:32:33,694][INFO][logstash.agent] No persistent UUID file found. Generating new UUID {:uuid=\>"04aac045-97eb-4a5c-80cc-f3318e2cad38", :path=\>"C:/Ankit/tools/logstash-6.3.0/data/uuid"}  
[2018-07-02T13:32:34,442][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.3.0"}  
[2018-07-02T13:32:39,559][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2018-07-02T13:32:40,636][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-07-02T13:32:40,651][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-07-02T13:32:41,213][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2018-07-02T13:32:41,759][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-07-02T13:32:41,774][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-07-02T13:32:41,790][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-07-02T13:32:41,852][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-07-02T13:32:42,102][INFO][logstash.outputs.elasticsearch] Installing elasticsearch template to \_template/logstash  
[2018-07-02T13:32:44,066][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost](https://localhost)"]}  
[2018-07-02T13:32:45,174][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x1628d06 sleep\>"}  
[2018-07-02T13:32:45,423][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>[]}  
[2018-07-02T13:32:45,891][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-07-02T13:34:20,813][WARN][logstash.runner] SIGINT received. Shutting down.

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [July 3, 2018, 7:03am UTC](https://discuss.elastic.co/t/config-problem-with-logstash/138194/4 "2018-07-03T07:03:41Z")

</div>

hey @ankit211,

You have installed x-pack in your Elastic Stack ?

try with following in elasticsearch output part 🙂

hosts =\> ["localhost:9200"]

and see that file has permission or not if its not their then give the permission to chmod 777.

and restart the logstash and run the config file tell me its working or not.

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

**Author:** ![ankit211](https://avatars.discourse-cdn.com/v4/letter/a/8baadc/32.png) [@ankit211](https://discuss.elastic.co/u/ankit211)\
**Post date:** [July 3, 2018, 7:45am UTC](https://discuss.elastic.co/t/config-problem-with-logstash/138194/5 "2018-07-03T07:45:00Z")

</div>

yes i have x-pack in elasticsearch.  
i try this elasticsearch output.  
restart logstash.

still not working. same thing happen with logstash.  
kibana-6.3.0  
logstash 6.3.0  
elasticsearch-6.3.0  
working on windows.

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [July 3, 2018, 8:34am UTC](https://discuss.elastic.co/t/config-problem-with-logstash/138194/6 "2018-07-03T08:34:30Z")

</div>

okk now add this following lines in your elasticsearch output

output  
{  
elasticsearch  
{  
hosts =\> ["localhost:9200"]  
index =\> "error"  
user =\> "elastic" #your elasticsearch username that you have mention while installed x-pack  
password =\> "elastic" #your elasticsearch password that you have mention while installed x-pack  
}  
stdout { codec =\> rubydebug }  
}

Note that your have to add the x-pack passwords of elasticsearch in your elasticsearch.yml file.

have you added that x-pack username and password of elasticsearch in your elasticsearch.yml file ?

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2018, 8:35am UTC](https://discuss.elastic.co/t/config-problem-with-logstash/138194/8 "2018-07-31T08:35:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
