# ERROR Unable to locate appender "${sys:ls.log.format}\_rolling" for logger config "root"

**URL:** <https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942>\
**Category:** Logstash\
**Created:** [November 16, 2017, 1:04pm UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942 "2017-11-16T13:04:32Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Juliette](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@Juliette](https://discuss.elastic.co/u/Juliette)\
**Post date:** [November 16, 2017, 1:04pm UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/1 "2017-11-16T13:04:32Z")

</div>

Hi,

I need your help ! I'm working on Elasticsearch ELK since 2 weeks and I have some issues when a try to create my first pipeline. I saw many blog, article and documentation before coming here and disturb you.

```
Version Linux : **Red Hat Enterprise Linux Server release 7.3 (Maipo)**
 Architecture : x86_64
 Kernel : 3.10.0-514.el7.x86_64

```

So, when I try to execute :

`sudo /usr/share/logstash/bin/logstash -e 'input { stdin { } } output { stdout {} }' --path.settings /etc/logstash`

Sometimes I have this issue :

`2017-11-16 13:36:07,258 main ERROR Unable to locate appender "${sys:ls.log.format}_rolling" for logger config "root"`

Sometimes, I have nothing, just :

`Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties`

But in this two case, I can't send an input (which is the object of this test ...). It's already work, one time, I saw the log in Kibana.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/1/11e5e755a7e9c56fb4266e2282b65e6775db0135.png)

I didn't change the default configuration for log4j2.properties :

status = error  
name = LogstashPropertiesConfig

```
appender.rolling.type = RollingFile
appender.rolling.name = plain_rolling
appender.rolling.fileName = ${sys:ls.logs}/logstash-${sys:ls.log.format}.log
appender.rolling.filePattern = ${sys:ls.logs}/logstash-${sys:ls.log.format}-%d{yyyy-MM-dd}.log
appender.rolling.policies.type = Policies
appender.rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.rolling.policies.time.interval = 1
appender.rolling.policies.time.modulate = true
appender.rolling.layout.type = PatternLayout
appender.rolling.layout.pattern = [%d{ISO8601}][%-5p][%-25c] %-.10000m%n

appender.json_rolling.type = RollingFile
appender.json_rolling.name = json_rolling
appender.json_rolling.fileName = ${sys:ls.logs}/logstash-${sys:ls.log.format}.log
appender.json_rolling.filePattern = ${sys:ls.logs}/logstash-${sys:ls.log.format}-%d{yyyy-MM-dd}.log
appender.json_rolling.policies.type = Policies
appender.json_rolling.policies.time.type = TimeBasedTriggeringPolicy
appender.json_rolling.policies.time.interval = 1
appender.json_rolling.policies.time.modulate = true
appender.json_rolling.layout.type = JSONLayout
appender.json_rolling.layout.compact = true
appender.json_rolling.layout.eventEol = true

rootLogger.level = ${sys:ls.log.level}
rootLogger.appenderRef.rolling.ref = ${sys:ls.log.format}_rolling 

```

All the stack is in **5.6.3**!

**I didn't change neither the logstash.yml because I just come to reinstall it.**  
I don't know, if you need anything, maybe you'll miss some information.

I forgot ... I already test to create a logstash-simple.conf and execute :

```
$ sudo /usr/share/logstash/bin/logstash -f logstash-simple.conf --path.settings /etc/logstash
Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties
The stdin plugin is now waiting for input:
Hola
{
      "@version" => "1",
          "host" => "blabla",
    "@timestamp" => 2017-11-16T08:51:07.592Z,
       "message" => "Hola"
}

```

So obviously it's work, but i try to execute another time and same issue.

**"Rhoooo, it's always the same issue, such a noobies ..."** 😃  
I see you seeing my post !

Thank's a lot !

---

<div class="post-metadata">

**Author:** ![exNewbie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/exnewbie/32/24452_2.png) [@exNewbie](https://discuss.elastic.co/u/exNewbie)\
**Post date:** [November 20, 2017, 6:08am UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/2 "2017-11-20T06:08:14Z")

</div>

I have the same issue. I'm running Dock with Logstash version 5.6.4.

The weird thing is that it even dumps errors when I ran a very simple config

> [root@55b8577b1835 logstash]# bin/logstash -e 'input { stdin { } } output { stdout {} }'  
> 2017-11-20 05:59:38,609 main ERROR Unable to locate appender "${sys:ls.log.format}\_rolling" for logger config "root"  
> Sending Logstash's logs to /usr/share/logstash/log which is now configured via log4j2.properties

```
[2017-11-20T05:59:39,831][INFO][logstash.agent] Created final config by merging config string and config path {:path=>"/usr/share/logstash/config"}
[2017-11-20T05:59:39,843][ERROR][logstash.agent] Cannot create pipeline {:reason=>"Expected one of #, input, filter, output at line 1, column 41 (byte 41) after "}

```

---

<div class="post-metadata">

**Author:** ![hobo\_zo](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@hobo\_zo](https://discuss.elastic.co/u/hobo_zo)\
**Post date:** [November 23, 2017, 6:44am UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/3 "2017-11-23T06:44:37Z")

</div>

I have the same problem.

---

<div class="post-metadata">

**Author:** ![Juliette](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@Juliette](https://discuss.elastic.co/u/Juliette)\
**Post date:** [November 23, 2017, 7:04am UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/4 "2017-11-23T07:04:05Z")

</div>

Okay,  
I'm just being back at work, so I'm going to try to fix this issue, if i find something, I will telling you !  
And of course, if you find something ...

But today, the issue has desappear. When I execute the command for generate pipeline, I just have that :

`Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties`

I can't send anything in input, so I'm really confused.

I read that you need to configure`log4j2.properties` with the same logic that you configure "`path.data`" and "`path.logs`" in your `elasticsearch.yml`

I'm not sure to understand all the configuration in the example of this link but maybe you can :  
[https://www.elastic.co/guide/en/elasticsearch/reference/5.5/settings.html](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/settings.html)

Hope you success 😉

---

<div class="post-metadata">

**Author:** ![rclarke](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rclarke/32/68604_2.png) [@rclarke](https://discuss.elastic.co/u/rclarke)\
**Post date:** [November 28, 2017, 9:33am UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/5 "2017-11-28T09:33:00Z")

</div>

Have a look at this related issue: [https://github.com/elastic/logstash/issues/8744](https://github.com/elastic/logstash/issues/8744)

---

<div class="post-metadata">

**Author:** ![Juliette](https://avatars.discourse-cdn.com/v4/letter/j/8e7dd6/32.png) [@Juliette](https://discuss.elastic.co/u/Juliette)\
**Post date:** [November 29, 2017, 7:15am UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/6 "2017-11-29T07:15:35Z")

</div>

Thank's a lot !

---

<div class="post-metadata">

**Author:** ![hobo\_zo](https://avatars.discourse-cdn.com/v4/letter/h/cc9497/32.png) [@hobo\_zo](https://discuss.elastic.co/u/hobo_zo)\
**Post date:** [December 15, 2017, 2:54am UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/7 "2017-12-15T02:54:18Z")

</div>

🙂Thank U!

---

<div class="post-metadata">

**Author:** ![vigneshaj](https://avatars.discourse-cdn.com/v4/letter/v/0ea827/32.png) [@vigneshaj](https://discuss.elastic.co/u/vigneshaj)\
**Post date:** [January 3, 2018, 11:18am UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/8 "2018-01-03T11:18:41Z")

</div>

I updated the mentioned config in log4j2.properties, but I am still getting the mentioned error.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 31, 2018, 11:19am UTC](https://discuss.elastic.co/t/error-unable-to-locate-appender-sys-ls-log-format-rolling-for-logger-config-root/107942/9 "2018-01-31T11:19:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
