# Error regarding log4j: well worn topic

**URL:** <https://discuss.elastic.co/t/error-regarding-log4j-well-worn-topic/87943>\
**Category:** Logstash\
**Created:** [June 1, 2017, 3:39pm UTC](https://discuss.elastic.co/t/error-regarding-log4j-well-worn-topic/87943 "2017-06-01T15:39:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![reswob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/reswob/32/38015_2.png) [@reswob](https://discuss.elastic.co/u/reswob)\
**Post date:** [June 1, 2017, 3:39pm UTC](https://discuss.elastic.co/t/error-regarding-log4j-well-worn-topic/87943/1 "2017-06-01T15:39:07Z")

</div>

I'm brand new to Logstash, I'm trying to get an Filebeats - LogStash - Elasticsearch pipeline set up using the online documentation. But I'm running into a problem where I get the following error:

[root@elastic-01 logstash]# /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/first-pipeline.conf --path.settings /etc/logstash  
Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties  
log4j:WARN No appenders could be found for logger (io.netty.util.internal.logging.InternalLoggerFactory).  
log4j:WARN Please initialize the log4j system properly.  
log4j:WARN See [Apache log4j 1.2 - Frequently Asked Technical Questions](http://logging.apache.org/log4j/1.2/faq.html#noconfig) for more info.

While researching, it appears this error has popped up a NUMBER of times over time regarding logstash and even elasticsearch. I've read through the following posts and bug reports:

> [@Logstash giving error regarding log4j](https://discuss.elastic.co/t/logstash-giving-error-regarding-log4j/84767):
>
> Using latest logstash 5.4.0, getting this error on startup ERROR StatusLogger No log4j2 configuration file found. Using default configuration: logging only errors to the console. Sending Logstash's logs to /var/log/ which is now configured via log4j2.properties log4j:WARN No appenders could be found for logger (org.apache.kafka.clients.producer.ProducerConfig). log4j:WARN Please initialize the log4j system properly. log4j:WARN See [http://logging.apache.org/log4j/1.2/faq.html#noconfig](http://logging.apache.org/log4j/1.2/faq.html#noconfig) for mo…

> [@How to configure log4j in ELK statck](https://discuss.elastic.co/t/how-to-configure-log4j-in-elk-statck/85236):
>
> I have installed logstash log4j filter plugin.When i check logstash Configtest ,i have the following Warning log4j:WARN No appenders could be found for logger (org.apache.http.impl.conn.PoolingHttpClientConnectionManager). log4j:WARN Please initialize the log4j system properly. log4j:WARN See [http://logging.apache.org/log4j/1.2/faq.html#noconfig](http://logging.apache.org/log4j/1.2/faq.html#noconfig) for more info.

> <https://github.com/logstash-plugins/logstash-input-beats/issues/132>
>
> When you start the plugin in 2.4 we get a warning.
> 
> \`\`\`
> rclarke@es-rclarke:10045…6$ ~/elastic/stack/logstash-2.4.0/bin/logstash agent --config ./logstash.conf --log ./logstash.log --quiet
> Sending logstash logs to ./logstash.log.
> Settings: Default pipeline workers: 4
> log4j:WARN No appenders could be found for logger (io.netty.util.internal.logging.InternalLoggerFactory).
> log4j:WARN Please initialize the log4j system properly.
> log4j:WARN See http://logging.apache.org/log4j/1.2/faq.html#noconfig for more info.
> \`\`\`

> <https://github.com/logstash-plugins/logstash-input-beats/issues/193>
>
> When checking the logstash config, I get this "warning":
> 
> \`\`\`
> \# service logst…ash configtest
> log4j:WARN No appenders could be found for logger (io.netty.util.internal.logging.InternalLoggerFactory).
> log4j:WARN Please initialize the log4j system properly.
> log4j:WARN See http://logging.apache.org/log4j/1.2/faq.html#noconfig for more info.
> Configuration OK
> \`\`\`
> 
> When I start logstash, no events flow into elasticsearch. But when I disable all beats inputs, the error messages disappear and events do flow into elasticsearch.
> 
> Yes it's a warning, but when running logstash with beats inputs enabled, logstash stops handling all events. Even stopping logstash doesn't work anymore, it looks like it is really stuck, but shows no errors in the log files. Only way to stop logstash is using a dirty "kill -9"

> [@WARN No appenders could be found for logger (org.apache.kafka.clients.producer.ProducerConfig)](https://discuss.elastic.co/t/warn-no-appenders-could-be-found-for-logger-org-apache-kafka-clients-producer-producerconfig/82515):
>
> Hi, I am using Logstash 5.3.0. When I use Kafka output plugin in my config file as follows: output { kafka { codec =\> plain { format =\> "%{message}" } bootstrap\_servers =\> "dev02n.wh:9092" topic\_id =\> "hdfs\_audit\_log\_test" retries =\> 3 batch\_size =\> 3 client\_id =\> "hdp-nn-audit" } } I get the following warnings: log4j:WARN No appenders could be found for logger (org.apache.kafka.clients.producer.ProducerConfig). log4j:WARN Please initialize the log4j system properly. log4j:WARN S…

> [@Fresh logstash 5.2 install gives log4j warnings and no logging from plugins](https://discuss.elastic.co/t/fresh-logstash-5-2-install-gives-log4j-warnings-and-no-logging-from-plugins/75530/5):
>
> Any news on this? I was hoping to hear from the logstash team...

> <https://github.com/elastic/logstash/issues/4111>
>
> When starting logstash 2.0, I'm getting
> 
> \`\`\`
> \# cat /var/log/logstash/logstash.er…r
> log4j:WARN No appenders could be found for logger (org.apache.http.impl.conn.PoolingHttpClientConnectionManager).
> log4j:WARN Please initialize the log4j system properly.
> log4j:WARN See http://logging.apache.org/log4j/1.2/faq.html#noconfig for more info.
> \`\`\`
> 
> Freshly installed from website
> 
> \`\`\`
> \# rpm -qa | grep logstash
> logstash-2.0.0-1.noarch
> \`\`\`
> 
> Looks to be the same issue as https://logstash.jira.com/browse/LOGSTASH-302

Here are my versions:

[root@elastic-01 logstash]# /usr/share/logstash/bin/logstash-plugin list --verbose beats  
logstash-input-beats (3.1.12)  
[root@elastic-01 logstash]# /usr/share/logstash/bin/logstash-plugin update logstash-input-beats  
Updating logstash-input-beats  
which: no javac in (/usr/lib64/qt-3.3/bin:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:/root/bin)  
io/console on JRuby shells out to stty for most operations  
Updated logstash-input-beats 3.1.12 to 3.1.15

[root@elastic-01 logstash]# cat /etc/\*release  
CentOS release 6.9 (Final)

[root@elastic-01 logstash]# /usr/share/logstash/bin/logstash --version  
logstash 5.4.0

I installed by downloading the .rpm (30 May 2017) and using yum -install, so it seems like I got the latest distro...?

Basically, if I set my input to stdin {} I do not get this error. But if I set it to beats { port =\> "5043" }, I get the error.

It seems like this is a bug that keeps returning.

Since I upgraded to the latest beats plugin (see above), any other suggestions?

Thanks

EDIT: BTW, this was in the entry in the log:

[2017-06-01T12:24:48,270][ERROR][logstash.pipeline] A plugin had an unrecoverable error. Will restart this plugin.  
Plugin: \<LogStash::Inputs::Beats port=\>5043, id=\>"ee0842e64d9951495df3258d05ddacc19bf85528-3", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_8db64ba9-ebec-4e05-809c-d3d456d37f45", enable\_metric=\>true, charset=\>"UTF-8"\>, host=\>"0.0.0.0", ssl=\>false, ssl\_verify\_mode=\>"none", include\_codec\_tag=\>true, ssl\_handshake\_timeout=\>10000, congestion\_threshold=\>5, target\_field\_for\_codec=\>"message", tls\_min\_version=\>1, tls\_max\_version=\>1.2, cipher\_suites=\>["TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_GCM\_SHA384", "TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384", "TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_GCM\_SHA256", "TLS\_ECDHE\_RSA\_WITH\_AES\_128\_GCM\_SHA256", "TLS\_ECDHE\_ECDSA\_WITH\_AES\_256\_CBC\_SHA384", "TLS\_ECDHE\_RSA\_WITH\_AES\_256\_CBC\_SHA384", "TLS\_ECDHE\_ECDSA\_WITH\_AES\_128\_CBC\_SHA256"], client\_inactivity\_timeout=\>60\>  
Error: event executor terminated

---

<div class="post-metadata">

**Author:** ![ernestgwilsonii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ernestgwilsonii/32/13981_2.png) [@ernestgwilsonii](https://discuss.elastic.co/u/ernestgwilsonii)\
**Post date:** [June 14, 2017, 9:31pm UTC](https://discuss.elastic.co/t/error-regarding-log4j-well-worn-topic/87943/2 "2017-06-14T21:31:33Z")

</div>

Seams like the issue is around the Beats plugin.

logstash --version  
logstash 5.4.1

cat /etc/logstash.conf  
input {  
beats {  
port =\> 5044  
}  
}

output {  
stdout {  
codec =\> rubydebug  
}  
}

/usr/share/logstash/bin/logstash -f /etc/logstash.conf  
Sending Logstash's logs to /usr/share/logstash/logs which is now configured via log4j2.properties  
[2017-06-14T21:16:44,787][INFO][logstash.pipeline] Starting pipeline {"id"=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>5, "pipeline.max\_inflight"=\>250}  
log4j:WARN No appenders could be found for logger (io.netty.util.internal.logging.InternalLoggerFactory).  
log4j:WARN Please initialize the log4j system properly.  
log4j:WARN See [http://logging.apache.org/log4j/1.2/faq.html#noconfig](http://logging.apache.org/log4j/1.2/faq.html#noconfig) for more info.

# 

# A fatal error has been detected by the Java Runtime Environment:

# 

# SIGSEGV (0xb) at pc=0x000000000002d166, pid=416, tid=0x00007f3755075ae8

# 

# JRE version: OpenJDK Runtime Environment (8.0\_131-b11) (build 1.8.0\_131-b11)

# Java VM: OpenJDK 64-Bit Server VM (25.131-b11 mixed mode linux-amd64 compressed oops)

# Derivative: IcedTea 3.4.0

# Distribution: Custom build (Tue May 30 16:19:39 GMT 2017)

# Problematic frame:

# C 0x000000000002d166

# 

# Core dump written. Default location: //core or core.416

# 

# An error report file with more information is saved as:

# //hs\_err\_pid416.log

# 

# If you would like to submit a bug report, please include

# instructions on how to reproduce the bug and visit:

# [http://icedtea.classpath.org/bugzilla](http://icedtea.classpath.org/bugzilla)

# 

Segmentation fault (core dumped)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2017, 9:31pm UTC](https://discuss.elastic.co/t/error-regarding-log4j-well-worn-topic/87943/3 "2017-07-12T21:31:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
