# Errors running logstash, bit of a newb

**URL:** <https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269>\
**Category:** Logstash\
**Created:** [March 28, 2017, 9:47am UTC](https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269 "2017-03-28T09:47:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Keith\_Sanks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_sanks/32/16719_2.png) [@Keith\_Sanks](https://discuss.elastic.co/u/Keith_Sanks)\
**Post date:** [March 28, 2017, 9:47am UTC](https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269/1 "2017-03-28T09:47:46Z")

</div>

Trying to set logstash up properly but I'm getting the following message after running it with my config file:  
Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"\_all"=\>{"enabled"=\>true, "omit\_norms"=\>true}, "dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"string", "index"=\>"analyzed", "omit\_norms"=\>true, "fielddata"=\>{"format"=\>"disabled"}}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"string", "index"=\>"analyzed", "omit\_norms"=\>true, "fielddata"=\>{"format"=\>"disabled"}, "fields"=\>{"raw"=\>{"type"=\>"string", "index"=\>"not\_analyzed", "doc\_values"=\>true, "ignore\_above"=\>256}}}}}, {"float\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"float", "mapping"=\>{"type"=\>"float", "doc\_values"=\>true}}}, {"double\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"double", "mapping"=\>{"type"=\>"double", "doc\_values"=\>true}}}, {"byte\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"byte", "mapping"=\>{"type"=\>"byte", "doc\_values"=\>true}}}, {"short\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"short", "mapping"=\>{"type"=\>"short", "doc\_values"=\>true}}}, {"integer\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"integer", "mapping"=\>{"type"=\>"integer", "doc\_values"=\>true}}}, {"long\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"long", "mapping"=\>{"type"=\>"long", "doc\_values"=\>true}}}, {"date\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"date", "mapping"=\>{"type"=\>"date", "doc\_values"=\>true}}}, {"geo\_point\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"geo\_point", "mapping"=\>{"type"=\>"geo\_point", "doc\_values"=\>true}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date", "doc\_values"=\>true}, "@version"=\>{"type"=\>"string", "index"=\>"not\_analyzed", "doc\_values"=\>true}, "geoip"=\>{"type"=\>"object", "dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip", "doc\_values"=\>true}, "location"=\>{"type"=\>"geo\_point", "doc\_values"=\>true}, "latitude"=\>{"type"=\>"float", "doc\_values"=\>true}, "longitude"=\>{"type"=\>"float", "doc\_values"=\>true}}}}}}}}

I ran the config test file and it's results come back OK  
I'm a bit of a newb with this, please advise, thanks  
I'm hosting my elasticsearch from a different host computer than my logstash, it's able to connect over port 9200 just fine but it can't seem to send the data.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 30, 2017, 1:09am UTC](https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269/2 "2017-03-30T01:09:21Z")

</div>

That's not an error, it's just letting you know what it's doing.

What's your config look like?

---

<div class="post-metadata">

**Author:** ![Keith\_Sanks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_sanks/32/16719_2.png) [@Keith\_Sanks](https://discuss.elastic.co/u/Keith_Sanks)\
**Post date:** [March 31, 2017, 5:48pm UTC](https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269/3 "2017-03-31T17:48:54Z")

</div>

This is part of the Logstash config file:  
input {

#Production Logs#############################  
file {  
type =\> "BRO\_httplog"  
path =\> "/var/log/.bro\_http\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_http\_sincedb"  
}  
file {  
type =\> "BRO\_known\_certslog"  
path =\> "/var/log/.bro\_known\_certs\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_known\_certs\_sincedb"  
}  
file {  
type =\> "BRO\_noticelog"  
path =\> "/var/log/.bro\_notice\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_notice\_sincedb"  
}  
file {  
type =\> "BRO\_known\_hostslog"  
path =\> "/var/log/.bro\_known\_hosts\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_known\_hosts\_sincedb"  
}  
file {  
type =\> "BRO\_known\_serviceslog"  
path =\> "/var/log/.bro\_known\_services\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_known\_services\_sincedb"  
}  
file {  
type =\> "BRO\_sshlog"  
path =\> "/var/log/.bro\_ssh\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_ssh\_sincedb"  
}  
file {  
type =\> "BRO\_dpdlog"  
path =\> "/var/log/.bro\_dpd\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_dpd\_sincedb"  
}  
file {  
type =\> "BRO\_connlog"  
path =\> "/var/log/.bro\_conn\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_conn\_sincedb"  
}  
file {  
type =\> "BRO\_weirdlog"  
path =\> "/var/log/.bro\_weird\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_weird\_sincedb"  
}  
file {  
type =\> "BRO\_app\_statslog"  
path =\> "/var/log/.bro\_appstats\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_appstats\_sincedb"  
}  
file {  
type =\> "BRO\_dhcplog"  
path =\> "/var/log/.bro\_dhcp\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_dhcp\_sincedb"  
}  
file {  
type =\> "BRO\_fileslog"  
path =\> "/var/log/.bro\_files\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_files\_sincedb"  
}  
file {  
type =\> "BRO\_ssllog"  
path =\> "/var/log/.bro\_ssl\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_ssl\_sincedb"  
}  
file {  
type =\> "BRO\_noticelog"  
path =\> "/var/log/.bro\_notice\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_notice\_sincedb"  
}  
file {  
type =\> "BRO\_softwarelog"  
path =\> "/var/log/.bro\_software\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_software\_sincedb"  
}  
file {  
type =\> "BRO\_dnslog"  
path =\> "/var/log/.bro\_dns\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_dns\_sincedb"  
}  
file {  
type =\> "BRO\_intellog"  
path =\> "/var/log/.bro\_intel\_sincedb"  
sincedb\_path =\> "/var/log/.bro\_intel\_sincedb"  
}  
}

filter {  
if [message] =~ /^#/ {  
drop { }  
}  
else {

```
# BRO_app_statslog ######################
  if [type] == "BRO_app_statslog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<ts_delta>(.*?))\t(?<app>(.*?))\t(?<uniq_hosts>(.*?))\t(?<hits>(.*?))\t(?<bytes>(.*))"]
    }
  }

# BRO_connlog ######################
  if [type] == "BRO_connlog" {
    grok {
	    match => [ 
		    "message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<proto>(.*?))\t(?<service>(.*?))\t(?<duration>(.*?))\t(?<orig_bytes>(.*?))\t(?<resp_bytes>(.*?))\t(?<conn_state>(.*?))\t(?<local_orig>(.*?))\t(?<missed_bytes>(.*?))\t(?<history>(.*?))\t(?<orig_pkts>(.*?))\t(?<orig_ip_bytes>(.*?))\t(?<resp_pkts>(.*?))\t(?<resp_ip_bytes>(.*?))\t(?<tunnel_parents>(.*?))\t(?<orig_cc>(.*?))\t(?<resp_cc>(.*?))\t(?<sensorname>(.*))",
		    "message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<proto>(.*?))\t(?<service>(.*?))\t(?<duration>(.*?))\t(?<orig_bytes>(.*?))\t(?<resp_bytes>(.*?))\t(?<conn_state>(.*?))\t(?<local_orig>(.*?))\t(?<missed_bytes>(.*?))\t(?<history>(.*?))\t(?<orig_pkts>(.*?))\t(?<orig_ip_bytes>(.*?))\t(?<resp_pkts>(.*?))\t(?<resp_ip_bytes>(.*?))\t(%{NOTSPACE:tunnel_parents})"
	    ]
    }
  }

# BRO_noticelog ######################
  if [type] == "BRO_noticelog" {
    grok { 
      match => ["message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<fuid>(.*?))\t(?<file_mime_type>(.*?))\t(?<file_desc>(.*?))\t(?<proto>(.*?))\t(?<note>(.*?))\t(?<msg>(.*?))\t(?<sub>(.*?))\t(?<src>(.*?))\t(?<dst>(.*?))\t(?<p>(.*?))\t(?<n>(.*?))\t(?<peer_descr>(.*?))\t(?<actions>(.*?))\t(?<suppress_for>(.*?))\t(?<dropped>(.*?))\t(?<remote_location.country_code>(.*?))\t(?<remote_location.region>(.*?))\t(?<remote_location.city>(.*?))\t(?<remote_location.latitude>(.*?))\t(?<remote_location.longitude>(.*))"]
    }
  }

# BRO_dhcplog ######################
  if [type] == "BRO_dhcplog" {
    grok { 
      match => ["message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<mac>(.*?))\t(?<assigned_ip>(.*?))\t(?<lease_time>(.*?))\t(?<trans_id>(.*))"]
    }
  }

# BRO_dnslog ######################
  if [type] == "BRO_dnslog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<proto>(.*?))\t(?<trans_id>(.*?))\t(?<query>(.*?))\t(?<qclass>(.*?))\t(?<qclass_name>(.*?))\t(?<qtype>(.*?))\t(?<qtype_name>(.*?))\t(?<rcode>(.*?))\t(?<rcode_name>(.*?))\t(?<AA>(.*?))\t(?<TC>(.*?))\t(?<RD>(.*?))\t(?<RA>(.*?))\t(?<Z>(.*?))\t(?<answers>(.*?))\t(?<TTLs>(.*?))\t(?<rejected>(.*))"]
    }
  }

# BRO_softwarelog ######################
  if [type] == "BRO_softwarelog" {
    grok { 
      match => ["message", "(?<ts>(.*?))\t(?<bro_host>(.*?))\t(?<host_p>(.*?))\t(?<software_type>(.*?))\t(?<name>(.*?))\t(?<version.major>(.*?))\t(?<version.minor>(.*?))\t(?<version.minor2>(.*?))\t(?<version.minor3>(.*?))\t(?<version.addl>(.*?))\t(?<unparsed_version>(.*))"]
    }
  }

# BRO_dpdlog ######################
  if [type] == "BRO_dpdlog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<proto>(.*?))\t(?<analyzer>(.*?))\t(?<failure_reason>(.*))"]
    }
  }

# BRO_fileslog ######################
  if [type] == "BRO_fileslog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<fuid>(.*?))\t(?<tx_hosts>(.*?))\t(?<rx_hosts>(.*?))\t(?<conn_uids>(.*?))\t(?<source>(.*?))\t(?<depth>(.*?))\t(?<analyzers>(.*?))\t(?<mime_type>(.*?))\t(?<filename>(.*?))\t(?<duration>(.*?))\t(?<local_orig>(.*?))\t(?<is_orig>(.*?))\t(?<seen_bytes>(.*?))\t(?<total_bytes>(.*?))\t(?<missing_bytes>(.*?))\t(?<overflow_bytes>(.*?))\t(?<timedout>(.*?))\t(?<parent_fuid>(.*?))\t(?<md5>(.*?))\t(?<sha1>(.*?))\t(?<sha256>(.*?))\t(?<extracted>(.*))"]
    }
  }
```

---

<div class="post-metadata">

**Author:** ![Keith\_Sanks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_sanks/32/16719_2.png) [@Keith\_Sanks](https://discuss.elastic.co/u/Keith_Sanks)\
**Post date:** [March 31, 2017, 5:49pm UTC](https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269/4 "2017-03-31T17:49:51Z")

</div>

This is the other part

# BRO\_httplog

```
  if [type] == "BRO_httplog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<trans_depth>(.*?))\t(?<method>(.*?))\t(?<bro_host>(.*?))\t(?<uri>(.*?))\t(?<referrer>(.*?))\t(?<user_agent>(.*?))\t(?<request_body_len>(.*?))\t(?<response_body_len>(.*?))\t(?<status_code>(.*?))\t(?<status_msg>(.*?))\t(?<info_code>(.*?))\t(?<info_msg>(.*?))\t(?<filename>(.*?))\t(?<http_tags>(.*?))\t(?<username>(.*?))\t(?<password>(.*?))\t(?<proxied>(.*?))\t(?<orig_fuids>(.*?))\t(?<orig_mime_types>(.*?))\t(?<resp_fuids>(.*?))\t(?<resp_mime_types>(.*))"]
    }
  }

# BRO_known_certslog ######################
  if [type] == "BRO_known_certslog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<bro_host>(.*?))\t(?<port_num>(.*?))\t(?<subject>(.*?))\t(?<issuer_subject>(.*?))\t(?<serial>(.*))"]
    }
  }

# BRO_known_hostslog ######################
  if [type] == "BRO_known_hostslog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<bro_host>(.*))"]
    }
  }

# BRO_known_serviceslog ######################
  if [type] == "BRO_known_serviceslog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<bro_host>(.*?))\t(?<port_num>(.*?))\t(?<port_proto>(.*?))\t(?<service>(.*))"]
    }
  }

# BRO_sshlog ######################
  if [type] == "BRO_sshlog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<status>(.*?))\t(?<direction>(.*?))\t(?<client>(.*?))\t(?<server>(.*?))\t(?<remote_location.country_code>(.*?))\t(?<remote_location.region>(.*?))\t(?<remote_location.city>(.*?))\t(?<remote_location.latitude>(.*?))\t(?<remote_location.longitude>(.*))"]
    }
  }

# BRO_ssllog ######################
  if [type] == "BRO_ssllog" {
    grok {
      match => ["message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<version>(.*?))\t(?<cipher>(.*?))\t(?<server_name>(.*?))\t(?<session_id>(.*?))\t(?<subject>(.*?))\t(?<issuer_subject>(.*?))\t(?<not_valid_before>(.*?))\t(?<not_valid_after>(.*?))\t(?<last_alert>(.*?))\t(?<client_subject>(.*?))\t(?<client_issuer_subject>(.*?))\t(?<cert_hash>(.*?))\t(?<validation_status>(.*))"]
    }
  }

# BRO_weirdlog ######################
if [type] == "BRO_weirdlog" {
	grok {
		match => ["message", "(?<ts>(.*?))\t(?<uid>(.*?))\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t(?<name>(.*?))\t(?<addl>(.*?))\t(?<notice>(.*?))\t(?<peer>(.*))"]
    	}
}
if [type]== "BRO_intellog" {
  grok {
    match => ["message", "(?<ts>(.*?))\t%{DATA:uid}\t(?<id.orig_h>(.*?))\t(?<id.orig_p>(.*?))\t(?<id.resp_h>(.*?))\t(?<id.resp_p>(.*?))\t%{DATA:fuid}\t%{DATA:file_mime_type}\t%{DATA:file_desc}\t(?<seen.indicator>(.*?))\t(?<seen.indicator_type>(.*?))\t(?<seen.where>(.*?))\t%{NOTSPACE:sources}"]
 }

```

}  
}  
date {  
match =\> ["ts", "UNIX"]  
}  
}  
filter {  
if [bro\_host] {  
mutate {  
replace =\> ["host", "%{bro\_host}"]  
}  
}  
}  
filter {  
if "BRO" in [type] {  
if [id.orig\_h] {  
mutate {  
add\_field =\> ["senderbase\_lookup", "[http://www.senderbase.org/lookup/?search\_string=%{id.orig\_h}](http://www.senderbase.org/lookup/?search_string=%25%7Bid.orig_h%7D)" ]  
add\_field =\> ["CBL\_lookup", "[http://cbl.abuseat.org/lookup.cgi?ip=%{id.orig\_h}](http://cbl.abuseat.org/lookup.cgi?ip=%25%7Bid.orig_h%7D)" ]  
add\_field =\> ["Spamhaus\_lookup", "[http://www.spamhaus.org/query/bl?ip=%{id.orig\_h}](http://www.spamhaus.org/query/bl?ip=%25%7Bid.orig_h%7D)" ]  
}  
}  
mutate {  
add\_tag =\> ["BRO"]  
}  
mutate {  
convert =\> ["id.orig\_p", "integer"]  
convert =\> ["id.resp\_p", "integer"]  
convert =\> ["orig\_bytes", "integer"]  
convert =\> ["resp\_bytes", "integer"]  
convert =\> ["missed\_bytes", "integer"]  
convert =\> ["orig\_pkts", "integer"]  
convert =\> ["orig\_ip\_bytes", "integer"]  
convert =\> ["resp\_pkts", "integer"]  
convert =\> ["resp\_ip\_bytes", "integer"]  
}  
}  
}  
filter {  
if [type] == "BRO\_connlog" {  
#The following makes use of the translate filter (logstash contrib) to convert conn\_state into human text. Saves having to look up values for packet introspection  
translate {  
field =\> "conn\_state"  
destination =\> "conn\_state\_full"  
dictionary =\> [  
"S0", "Connection attempt seen, no reply",  
"S1", "Connection established, not terminated",  
"S2", "Connection established and close attempt by originator seen (but no reply from responder)",  
"S3", "Connection established and close attempt by responder seen (but no reply from originator)",  
"SF", "Normal SYN/FIN completion",  
"REJ", "Connection attempt rejected",  
"RSTO", "Connection established, originator aborted (sent a RST)",  
"RSTR", "Established, responder aborted",  
"RSTOS0", "Originator sent a SYN followed by a RST, we never saw a SYN-ACK from the responder",  
"RSTRH", "Responder sent a SYN ACK followed by a RST, we never saw a SYN from the (purported) originator",  
"SH", "Originator sent a SYN followed by a FIN, we never saw a SYN ACK from the responder (hence the connection was 'half' open)",  
"SHR", "Responder sent a SYN ACK followed by a FIN, we never saw a SYN from the originator",  
"OTH", "No SYN seen, just midstream traffic (a 'partial connection' that was not later closed)"  
]  
}  
}  
}

# Resolve @source\_host to FQDN if possible if missing for some types of logging using source\_host\_ip from above

filter {  
if [id.orig\_h] {  
if ![id.orig\_h-resolved] {  
mutate {  
add\_field =\> ["id.orig\_h-resolved", "%{id.orig\_h}"]  
}  
dns {  
reverse =\> ["id.orig\_h-resolved"]  
action =\> "replace"  
}  
}  
}  
}  
filter {  
if [id.resp\_h] {  
if ![id.resp\_h-resolved] {  
mutate {  
add\_field =\> ["id.resp\_h-resolved", "%{id.resp\_h}"]  
}  
dns {  
reverse =\> ["id.resp\_h-resolved"]  
action =\> "replace"  
}  
}  
}  
}

output {  
elasticsearch{  
hosts =\> ["10.0.2.159:9200"]  
#bind\_host =\> "192.168.1.191"  
index =\> ["logstash-%(+YYYY.MM.DD)"]  
#protocol =\> ["http"]  
#port =\> 9200  
template\_overwrite =\> true  
template =\> "/opt/logstash-5.2.2/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-6.2.6-java/lib/logstash/outputs/elasticsearch/elasticsearch-template-es2x.json"  
#cluster =\> ["logstash-cluster"]  
flush\_size =\> 1  
#tdout { codec =\> rubydebug }

}  
stdout { codec =\> rubydebug }

}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 31, 2017, 9:54pm UTC](https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269/5 "2017-03-31T21:54:11Z")

</div>

Your path to read the files is the same as the path for the sincedb, this means nothing will be read.

---

<div class="post-metadata">

**Author:** ![Keith\_Sanks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/keith_sanks/32/16719_2.png) [@Keith\_Sanks](https://discuss.elastic.co/u/Keith_Sanks)\
**Post date:** [April 3, 2017, 11:25pm UTC](https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269/6 "2017-04-03T23:25:58Z")

</div>

Thank you for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2017, 11:26pm UTC](https://discuss.elastic.co/t/errors-running-logstash-bit-of-a-newb/80269/7 "2017-05-01T23:26:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
