# Custom filter plugin logging configuration through log4j

**URL:** <https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389>\
**Category:** Logstash\
**Created:** [March 10, 2018, 2:07pm UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389 "2018-03-10T14:07:57Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![srikanth\_muddu](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@srikanth\_muddu](https://discuss.elastic.co/u/srikanth_muddu)\
**Post date:** [March 10, 2018, 2:07pm UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389/1 "2018-03-10T14:07:57Z")

</div>

I have installed new filter plugin with jar dependencies.I kept log4j2.properties for a java project and was able to create logging with a java project.But after installing plugin logs are not appending in the logstash-plain.log file.can you help, please

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 11, 2018, 4:03am UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389/2 "2018-03-11T04:03:32Z")

</div>

- What is your logging configuration, and at what level is Logstash configured to log at?
- Does the plugin in question call out to the logger (some don't), and if so, does it log at or above the currently-configured log level?
- Are you running a pipeline that uses the plugin in question?
- Does the user who owns the Logstash process have permission to write to the directory it's configured to write to?

---

<div class="post-metadata">

**Author:** ![srikanth\_muddu](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@srikanth\_muddu](https://discuss.elastic.co/u/srikanth_muddu)\
**Post date:** [March 12, 2018, 7:01am UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389/3 "2018-03-12T07:01:25Z")

</div>

> [@yaauie](#):
>
> - What is your logging configuration, and at what level is Logstash configured to log at?

"warn" is the loglevel i'm logging at

> [@yaauie](#):
>
> - Does the plugin in question call out to the logger (some don't), and if so, does it log at or above the currently-configured log level?

Can you please elaborate this question, I didn't get completely.

> [@yaauie](#):
>
> - Are you running a pipeline that uses the plugin in question?

yes, I am running pipeline.

> [@yaauie](#):
>
> - Does the user who owns the Logstash process have permission to write to the directory it's configured to write to?

yes user has read and write permission. you can see here  
-rw-r--r-- 1 xxxx xxxx 47942 Mar 12 12:20 ../../../logs/logstash-plain.log  
[/quote]

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 12, 2018, 7:57am UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389/4 "2018-03-12T07:57:35Z")

</div>

Let me try again:

- what filter plugin did you install?
- do you have evidence that the plugin logs at `warn` or above? Not all plugins are equally good about emitting log messages, and even the ones that do tend to emit logs at `debug` or `trace`, which are too low to be included in your configured output.
- you say that you are running a pipeline, but is that pipeline configured to use the filter plugin that you are having trouble with? Are events flowing through your pipeline?

---

<div class="post-metadata">

**Author:** ![srikanth\_muddu](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@srikanth\_muddu](https://discuss.elastic.co/u/srikanth_muddu)\
**Post date:** [March 12, 2018, 9:55am UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389/5 "2018-03-12T09:55:16Z")

</div>

> [@yaauie](#):
>
> Let me try again:
> 
> - what filter plugin did you install?

Instead of grok plugin to parse events i have implemented custom filter plugin which parses events without regex.

> [@yaauie](#):
>
> - do you have evidence that the plugin logs at `warn` or above? Not all plugins are equally good about emitting log messages, and even the ones that do tend to emit logs at `debug` or `trace`, which are too low to be included in your configured output.

 ![logss](https://us1.discourse-cdn.com/elastic/original/3X/6/8/68fe1f618209175ef93d3fcce16c59563cdb986c.png)

> [@yaauie](#):
>
> - you say that you are running a pipeline, but is that pipeline configured to use the filter plugin that you are having trouble with? Are events flowing through your pipeline?

pipeline is configured with the plugin what i have installed and events are also parsing properly.But logs are not appending into log file.  
"date" =\> "2018-02-22",  
"useragent" =\> "-",  
"httpmethod" =\> "GET",  
"type" =\> "accesslog",  
"time" =\> "11:47:14",  
"username" =\> "-"

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 12, 2018, 3:56pm UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389/6 "2018-03-12T15:56:23Z")

</div>

Without seeing the plugin code and configuration, I'm having a hard time understanding what you expect to happen; is the plugin open-source, or would you be willing to share a tarball of it privately?

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 13, 2018, 8:57pm UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389/7 "2018-03-13T20:57:50Z")

</div>

@srikanth_muddu I received a DM from you with a log4j configuration, information about where you placed JARS, and text from a `myplugin.rb`, containing approximately 5 lines of code referencing an object that I presume is defined in one of those JARs.

It still is very unclear what you want to get out of this; the `myplugin.rb` doesn't include a valid Logstash filter definition (did you use `bin/logstash-plugin generate --type filter --name "${FILTER_NAME}"` to generate it? This is a super helpful tool to scaffold a new plugin for you).

An example of a filter plugin with JAR dependencies is [`logstash-filter-dissect`](https://github.com/logstash-plugins/logstash-filter-dissect); perhaps you can learn from it?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2018, 8:57pm UTC](https://discuss.elastic.co/t/custom-filter-plugin-logging-configuration-through-log4j/123389/8 "2018-04-10T20:57:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
