# Configtest Ok if started as process, fails if started as service

**URL:** <https://discuss.elastic.co/t/configtest-ok-if-started-as-process-fails-if-started-as-service/97245>\
**Category:** Logstash\
**Created:** [August 16, 2017, 11:17am UTC](https://discuss.elastic.co/t/configtest-ok-if-started-as-process-fails-if-started-as-service/97245 "2017-08-16T11:17:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![xupete](https://avatars.discourse-cdn.com/v4/letter/x/a183cd/32.png) [@xupete](https://discuss.elastic.co/u/xupete)\
**Post date:** [August 16, 2017, 11:17am UTC](https://discuss.elastic.co/t/configtest-ok-if-started-as-process-fails-if-started-as-service/97245/1 "2017-08-16T11:17:24Z")

</div>

First, I am new to Elastissearch and Logstash.

I am trying to run an example. Elasticsearch and Kibana start as services when my Ubuntu 14.04 starts, but Logstash fails. Seems a problem when Logstash is started as service and try to parse the configuration file.

> ubuntu@ubuntu:/etc/logstash/conf.d$ /opt/logstash/bin/logstash agent --configtest -f twitter\_search.conf  
> Configuration OK  
> ubuntu@ubuntu:/etc/logstash/conf.d$ sudo service logstash configtest  
> Error: Expected one of #, input, filter, output at line 28, column 1 (byte 730) after {:level=\>:error}

If I start Logstash as a normal process everything runs okey, but as service (with "sudo service logstash start") Logstash stops and I get the same error text in the log file ("/var/log/logstash/logstash.log").

Logstash 2.2.4 has been installed from official package repository with apt-get install.

There is only one configuration file with a template file:

> ubuntu@ubuntu:/etc/logstash/conf.d$ ls -l  
> total 8  
> -rw-r--r-- 1 root root 728 ago 15 13:03 twitter\_search.conf  
> -rw-r--r-- 1 root root 1489 ago 15 13:01 twitter\_template.json

Content of twitter\_search.conf:

> ubuntu@ubuntu:/etc/logstash/conf.d$ cat twitter\_search.conf  
> input {  
> twitter {  
> consumer\_key =\> "xxxxxxxxxxx"  
> consumer\_secret =\> "xxxxxxxxxxx"  
> oauth\_token =\> "xxxxxxxxxxx-xxxxxxxxxxx"  
> oauth\_token\_secret =\> "xxxxxxxxxxx"  
> keywords =\> ["test1","test2","test3"]  
> full\_tweet =\> true  
> }  
> }
> 
> filter { }
> 
> output {  
> stdout {  
> codec =\> dots  
> }  
> elasticsearch {  
> hosts =\> ["127.0.0.1:9200"]  
> index =\> "twitter\_elastic\_example"  
> document\_type =\> "tweets"  
> template =\> "./twitter\_template.json"  
> template\_name =\> "twitter\_elastic\_example"  
> template\_overwrite =\> true  
> }  
> }

If I edit the config file and delete for example three lines ("stdout { codec =\> dots }") I get a similar error, changing the line number and byte position of error:

> ubuntu@ubuntu:/etc/logstash/conf.d$ sudo service logstash configtest  
> Error: Expected one of #, input, filter, output at line 25, column 1 (byte 697) after {:level=\>:error}

I assumed that there is no problem with user permissions, as Logstash seems to read contents of configuration file. I have launched "hexdump -C" with the configuration file and there are no strange characters at the end of file.

Any clue?

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 17, 2017, 5:14am UTC](https://discuss.elastic.co/t/configtest-ok-if-started-as-process-fails-if-started-as-service/97245/2 "2017-08-17T05:14:05Z")

</div>

Logstash reads _all_ files in /etc/logstash/conf.d. You need to store the JSON file elsewhere so Logstash doesn't read it.

---

<div class="post-metadata">

**Author:** ![xupete](https://avatars.discourse-cdn.com/v4/letter/x/a183cd/32.png) [@xupete](https://discuss.elastic.co/u/xupete)\
**Post date:** [August 19, 2017, 1:54pm UTC](https://discuss.elastic.co/t/configtest-ok-if-started-as-process-fails-if-started-as-service/97245/3 "2017-08-19T13:54:32Z")

</div>

You're right. I supposed Logstash reads only \*.conf files 😅

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 16, 2017, 1:54pm UTC](https://discuss.elastic.co/t/configtest-ok-if-started-as-process-fails-if-started-as-service/97245/4 "2017-09-16T13:54:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
