# ETA on Support for ubuntu 18.04 Server?

**URL:** <https://discuss.elastic.co/t/eta-on-support-for-ubuntu-18-04-server/150844>\
**Category:** Logstash\
**Created:** [October 3, 2018, 9:00am UTC](https://discuss.elastic.co/t/eta-on-support-for-ubuntu-18-04-server/150844 "2018-10-03T09:00:36Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![SpaceMoose](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spacemoose/32/35972_2.png) [@SpaceMoose](https://discuss.elastic.co/u/SpaceMoose)\
**Post date:** [October 3, 2018, 9:00am UTC](https://discuss.elastic.co/t/eta-on-support-for-ubuntu-18-04-server/150844/1 "2018-10-03T09:00:36Z")

</div>

Hi...

I've had a go at getting ELK up and running on ubuntu 18.04 Server (with Java 8).

I installed elasticsearch and logstash a day apart and got elasticsearch 6.4.1 and logstash 6.4.2 as a result. Both installed using apt-get.

I managed to get Elasticsearch working and logstash installed seemingly without incident. But, firing up logstash is a disappointment. It hangs. I'll happily paste in my logstash.conf file below.

The logstash server claims to start but then hangs, never progressing on successfully loading/filtering/and subsequently routing the data. Running logstash with the --debug flag creates a lot of spew, too much to post here. But I see this message a lot:

```auto
[DEBUG] 2018-10-03 08:57:29.975 [pool-2-thread-2] cgroup - Error, cannot retrieve cgroups information {:exception=&gt;"NoMethodError", :message=&gt;"undefined method `[]' for nil:NilClass"}

```

Below is my logstash.conf file. It's a pretty simple thing that just takes an access log file and then does some simple filtering/output:

```auto
stretch@stretch:/usr/share/logstash$ cat /etc/logstash/conf.d/logstash.conf 
input {
      file {
      	   path => "/home/stretch/access_log"
	   start_position => "beginning"
	   ignore_older => 0
      }
}
filter {
       grok {
       	    match => {"message" => "%{COMBINEDAPACHELOG}"}
       }
       date {
	    match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
       }
}
output {
       elasticsearch {
       		     hosts => ["localhost:9200"]
       }
       stdout {
              codec => rubydebug
       }
}

```

Any thoughts on what's wrong?

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 3, 2018, 10:13am UTC](https://discuss.elastic.co/t/eta-on-support-for-ubuntu-18-04-server/150844/2 "2018-10-03T10:13:41Z")

</div>

Unless you are adding new data to the input file, you are likely running into `sincedb` problems.  
Try setting to to `/dev/null`

---

<div class="post-metadata">

**Author:** ![SpaceMoose](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spacemoose/32/35972_2.png) [@SpaceMoose](https://discuss.elastic.co/u/SpaceMoose)\
**Post date:** [October 3, 2018, 1:22pm UTC](https://discuss.elastic.co/t/eta-on-support-for-ubuntu-18-04-server/150844/3 "2018-10-03T13:22:50Z")

</div>

Thanks Mark for your speedy reply. The file is just a static example file from an online course.

I modified my logstash.conf file to include a sincedb\_path =\> /dev/null to the input file block. Logged out and logged back in. But things did not improve.

Here's the spew with the debugging turned off. This may be more instructive?

```auto
sudo bin/logstash -f /etc/logstash/conf.d/logstash.conf

WARNING: Could not find logstash.yml which is typically located in $LS_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults

Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console

[WARN] 2018-10-03 13:00:33.924 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified

[INFO] 2018-10-03 13:00:34.955 [LogStash::Runner] runner - Starting Logstash {"logstash.version"=&gt;"6.4.1"}

[INFO] 2018-10-03 13:00:41.328 [Converge PipelineAction::Create&lt;main&gt;] pipeline - Starting pipeline {:pipeline_id=&gt;"main", "pipeline.workers"=&gt;1, "pipeline.batch.size"=&gt;125, "pipeline.batch.delay"=&gt;50}

[INFO] 2018-10-03 13:00:42.148 [[main]-pipeline-manager] elasticsearch - Elasticsearch pool URLs updated {:changes=&gt;{:removed=&gt;[], :added=&gt;[http://localhost:9200/]}}

[INFO] 2018-10-03 13:00:42.159 [[main]-pipeline-manager] elasticsearch - Running health check to see if an Elasticsearch connection is working {:healthcheck_url=&gt;http://localhost:9200/, :path=&gt;"/"}

[WARN] 2018-10-03 13:00:42.500 [[main]-pipeline-manager] elasticsearch - Restored connection to ES instance {:url=&gt;"http://localhost:9200/"}

[INFO] 2018-10-03 13:00:42.829 [[main]-pipeline-manager] elasticsearch - ES Output version determined {:es_version=&gt;6}

[WARN] 2018-10-03 13:00:42.832 [[main]-pipeline-manager] elasticsearch - Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=&gt;6}

[INFO] 2018-10-03 13:00:42.886 [[main]-pipeline-manager] elasticsearch - New Elasticsearch output {:class=&gt;"LogStash::Outputs::ElasticSearch", :hosts=&gt;["//localhost:9200"]}

[INFO] 2018-10-03 13:00:42.927 [Ruby-0-Thread-5: :1] elasticsearch - Using mapping template from {:path=&gt;nil}

[INFO] 2018-10-03 13:00:42.987 [Ruby-0-Thread-5: :1] elasticsearch - Attempting to install template {:manage_template=&gt;{"template"=&gt;"logstash-*", "version"=&gt;60001, "settings"=&gt;{"index.refresh_interval"=&gt;"5s"}, "mappings"=&gt;{"_default_"=&gt;{"dynamic_templates"=&gt;[{"message_field"=&gt;{"path_match"=&gt;"message", "match_mapping_type"=&gt;"string", "mapping"=&gt;{"type"=&gt;"text", "norms"=&gt;false}}}, {"string_fields"=&gt;{"match"=&gt;"*", "match_mapping_type"=&gt;"string", "mapping"=&gt;{"type"=&gt;"text", "norms"=&gt;false, "fields"=&gt;{"keyword"=&gt;{"type"=&gt;"keyword", "ignore_above"=&gt;256}}}}}], "properties"=&gt;{"@timestamp"=&gt;{"type"=&gt;"date"}, "@version"=&gt;{"type"=&gt;"keyword"}, "geoip"=&gt;{"dynamic"=&gt;true, "properties"=&gt;{"ip"=&gt;{"type"=&gt;"ip"}, "location"=&gt;{"type"=&gt;"geo_point"}, "latitude"=&gt;{"type"=&gt;"half_float"}, "longitude"=&gt;{"type"=&gt;"half_float"}}}}}}}}

[INFO] 2018-10-03 13:00:43.716 [Converge PipelineAction::Create&lt;main&gt;] pipeline - Pipeline started successfully {:pipeline_id=&gt;"main", :thread=&gt;"#&lt;Thread:0x27bcd905 run&gt;"}

[INFO] 2018-10-03 13:00:43.845 [Ruby-0-Thread-1: /usr/share/logstash/lib/bootstrap/environment.rb:6] agent - Pipelines running {:count=&gt;1, :running_pipelines=&gt;[:main], :non_running_pipelines=&gt;[]}

[INFO] 2018-10-03 13:00:43.893 [[main]&lt;file] observingtail - START, creating Discoverer, Watch with file and sincedb collections

[INFO] 2018-10-03 13:00:44.525 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=&gt;9600}

```

For some reason, logstash was not finding my YAML files, in spite of the fact they were sitting where logstash claims is "the usual place." Invoking logstash this way

```auto
$ sudo bin/logstash -f /etc/logstash/conf.d/logstash.conf --path.settings=/etc/logstash 

```

got rid of those messages but things still hang after logstash claims it has successfully started.

Are there quirks to ubuntu 18.04 server that are causing these problems?

Thanks!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 3, 2018, 1:23pm UTC](https://discuss.elastic.co/t/eta-on-support-for-ubuntu-18-04-server/150844/4 "2018-10-03T13:23:55Z")

</div>

> [@SpaceMoose](#):
>
> ignore\_older =\> 0

Skip this and see if that makes a difference.

---

<div class="post-metadata">

**Author:** ![SpaceMoose](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spacemoose/32/35972_2.png) [@SpaceMoose](https://discuss.elastic.co/u/SpaceMoose)\
**Post date:** [October 3, 2018, 1:52pm UTC](https://discuss.elastic.co/t/eta-on-support-for-ubuntu-18-04-server/150844/5 "2018-10-03T13:52:47Z")

</div>

Thanks Christian,

I tried this. But, as I understand things, ignore\_older =\> 0 tells logstash to look at all of the log data, even if from quite some time in the past (as it is with the log in question).

Here's the /var/log/logstash/logstash-plain.log file:

```auto
**stretch@stretch** : **/usr/share/logstash** $ more /var/log/logstash/logstash-plain.log 

[2018-10-03T13:12:02,247][INFO][logstash.setting.writabledirectory] Creating directory {:setting=&gt;"path.queue", :path=&gt;"/var/lib/logstash/queu

e"}

[2018-10-03T13:12:02,263][INFO][logstash.setting.writabledirectory] Creating directory {:setting=&gt;"path.dead_letter_queue", :path=&gt;"/var/lib/l

ogstash/dead_letter_queue"}

[2018-10-03T13:12:02,948][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options a

re specified

[2018-10-03T13:12:03,016][INFO][logstash.agent] No persistent UUID file found. Generating new UUID {:uuid=&gt;"f3febfd1-58fa-411a-860e

-fabb85233625", :path=&gt;"/var/lib/logstash/uuid"}

[2018-10-03T13:12:04,106][INFO][logstash.runner] Starting Logstash {"logstash.version"=&gt;"6.4.1"}

[2018-10-03T13:12:10,171][INFO][logstash.pipeline] Starting pipeline {:pipeline_id=&gt;"main", "pipeline.workers"=&gt;1, "pipeline.batch.siz

e"=&gt;125, "pipeline.batch.delay"=&gt;50}

[2018-10-03T13:12:10,908][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=&gt;{:removed=&gt;[], :added=&gt;[http://loca

lhost:9200/]}}

[2018-10-03T13:12:10,925][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:health

check_url=&gt;http://localhost:9200/, :path=&gt;"/"}

[2018-10-03T13:12:11,255][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=&gt;"http://localhost:9200/"}

[2018-10-03T13:12:11,355][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es_version=&gt;6}

[2018-10-03T13:12:11,371][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to dete

rmine the document _type {:es_version=&gt;6}

[2018-10-03T13:12:11,416][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=&gt;"LogStash::Outputs::ElasticSearch", :hosts=&gt;

["//localhost:9200"]}

[2018-10-03T13:12:11,452][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=&gt;nil}

[2018-10-03T13:12:11,498][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage_template=&gt;{"template"=&gt;"logstash-*", "

version"=&gt;60001, "settings"=&gt;{"index.refresh_interval"=&gt;"5s"}, "mappings"=&gt;{"_default_"=&gt;{"dynamic_templates"=&gt;[{"message_field"=&gt;{"path_match"

=&gt;"message", "match_mapping_type"=&gt;"string", "mapping"=&gt;{"type"=&gt;"text", "norms"=&gt;false}}}, {"string_fields"=&gt;{"match"=&gt;"*", "match_mapping_typ

e"=&gt;"string", "mapping"=&gt;{"type"=&gt;"text", "norms"=&gt;false, "fields"=&gt;{"keyword"=&gt;{"type"=&gt;"keyword", "ignore_above"=&gt;256}}}}}], "properties"=&gt;{"

@timestamp"=&gt;{"type"=&gt;"date"}, "@version"=&gt;{"type"=&gt;"keyword"}, "geoip"=&gt;{"dynamic"=&gt;true, "properties"=&gt;{"ip"=&gt;{"type"=&gt;"ip"}, "location"=&gt;{"t

ype"=&gt;"geo_point"}, "latitude"=&gt;{"type"=&gt;"half_float"}, "longitude"=&gt;{"type"=&gt;"half_float"}}}}}}}}

[2018-10-03T13:12:12,183][INFO][logstash.pipeline] Pipeline started successfully {:pipeline_id=&gt;"main", :thread=&gt;"#&lt;Thread:0x77c87f1e 

run&gt;"}

[2018-10-03T13:12:12,316][INFO][logstash.agent] Pipelines running {:count=&gt;1, :running_pipelines=&gt;[:main], :non_running_pipelines=&gt;

[]}

[2018-10-03T13:12:12,342][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections

[2018-10-03T13:12:12,943][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=&gt;9600}

[2018-10-03T13:14:33,260][WARN][logstash.runner] SIGINT received. Shutting down.

[2018-10-03T13:14:33,479][INFO][filewatch.observingtail] QUIT - closing all files and shutting down.

[2018-10-03T13:14:33,794][FATAL][logstash.runner] SIGINT received. Terminating immediately..

[2018-10-03T13:14:33,929][ERROR][org.logstash.Logstash] org.jruby.exceptions.ThreadKill

[2018-10-03T13:15:20,304][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options a

re specified

[2018-10-03T13:15:26,277][INFO][logstash.runner] Using config.test_and_exit mode. Config Validation Result: OK. Exiting Logstash

[2018-10-03T13:47:27,977][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options a

re specified

[2018-10-03T13:47:33,707][INFO][logstash.runner] Using config.test_and_exit mode. Config Validation Result: OK. Exiting Logstash

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2018, 1:52pm UTC](https://discuss.elastic.co/t/eta-on-support-for-ubuntu-18-04-server/150844/6 "2018-10-31T13:52:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
