# Fetching logs form remote host?

**URL:** <https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295>\
**Category:** Logstash\
**Created:** [June 10, 2015, 10:51am UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295 "2015-06-10T10:51:48Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [June 10, 2015, 10:51am UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/1 "2015-06-10T10:51:48Z")

</div>

Hi,  
I am using LSF as forwarder, logstash (as shipper and indexer on remote server) through redis.  
We have some windows machines which have some log files to read. Is there any way so that I can groke those log files through shipper(logstash server).  
These machines are nothing but devices and there number may change frequently and significantly in production. I don't want to install forwarder each time some device is added.  
Please guide on this. I have refered logstahs book, but it suggests syslog configuration on remote machine, again tedious job.

br,  
Sunil

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 10, 2015, 10:56am UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/2 "2015-06-10T10:56:41Z")

</div>

> I am using LSF as forwarder, logstash (as shipper and indexer on remote server) through redis.  
> We have some windows machines which have some log files to read. Is there any way so that I can groke those log files through shipper(logstash server).

If the logs are available via CIFS/SMB this should be doable, at least from a Windows machine. You should be able to point logstash-forwarder or Logstash to the remote log's UNC path (\\machinename\c$\path\to\file.log).

> These machines are nothing but devices and there number may change frequently and significantly in production. I don't want to install forwarder each time some device is added.

If you don't have automation set up for this you're working too hard.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [June 10, 2015, 12:53pm UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/4 "2015-06-10T12:53:41Z")

</div>

Hi Magnus,

I have log file on remote machine 10.xx.xxx.xxx and path is C:\var\log\common-logging\common-logging.log

I have configured path in logstash.conf as below.

path =\> "10.xx.xxx.xxx\c$\var\log\common-logging\common-logging.log"

Please let me know whats wrong in this. I am getting below error:

Plugin: \<LogStash::Inputs::File type=\>"applicationlogs\_local", path=\>["\\10.xx.xxx.xxx\c$\\var\\log\\common-logging\\common-logging.lo  
g"], start\_position=\>"end"\>  
Error: Neither current working directory (null) nor pathname (\10.xx.xxx.xxxc$\var\log\common-logging\common-logging.log) led to an absolute path  
{:level=\>:error}←[0m

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [June 10, 2015, 1:46pm UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/5 "2015-06-10T13:46:52Z")

</div>

Hi Magnus,  
about your second comment: what kind of automation you are talking about?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 10, 2015, 2:13pm UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/6 "2015-06-10T14:13:33Z")

</div>

> path =\> "10.xx.xxx.xxx\c$\var\log\common-logging\common-logging.log"

That's not a valid UNC path. They always begin with \\. Also, I suspect that Logstash requires forward slashes instead of backslashes.

> about your second comment: what kind of automation you are talking about?

You should automate how you set up machines so that installing and configuring additional software components isn't an issue.

---

<div class="post-metadata">

**Author:** ![jayaram](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@jayaram](https://discuss.elastic.co/u/jayaram)\
**Post date:** [December 2, 2015, 12:31pm UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/7 "2015-12-02T12:31:27Z")

</div>

Hi magnus,

I have give the remote path correctly even i am getting same error

It looks the text editor not taking double slash please consider this on each IP mentioned place in path and error message \\xxx.xxx.xxx.xxx  
input {  
file {  
path =\> "\xxx.xxx.xxx.xxx\d$\logs\myserver.log"  
start\_position =\> "beginning"  
}  
}

filter {  
grok {  
match =\> { "timestamp" =\> "%{TOMCAT\_DATESTAMP:timestamp}"}  
match =\> { "level" =\> "[%{LOGLEVEL:level}]" }  
match =\> { "class" =\> "[%{JAVACLASS:class}]" }  
match =\> { "logmessage" =\> "%{JAVALOGMESSAGE:logmessage}" }  
}  
grok{  
match =\> { "exceptions" =\> "%{JAVASTACKTRACEPART}" }  
}  
date {  
match =\> ["timestamp" , "yyyy-mm-dd HH:mm:ss Z"]  
}  
}

output {  
elasticsearch {  
hosts =\> ["127.0.0.1:9200"]  
}  
stdout { codec =\> rubydebug }  
}

Error while run logstash  
D:\basefarm\logstash-2.0.0\bin\>logstash -f logstashcfg.conf  
Picked up \_JAVA\_OPTIONS: -Xmx2048m -XX:MaxPermSize=512m  
Java HotSpot(TM) 64-Bit Server VM warning: ignoring option MaxPermSize=512m; support was removed in 8.0  
io/console not supported; tty will not be manipulated  
Default settings used: Filter workers: 1  
←[31mA plugin had an unrecoverable error. Will restart this plugin.  
Plugin: \<LogStash::Inputs::File path=\>["\\xxx.xxx.xxx.xxx/d$/logs/myserver.log"], start\_position=\>"beginning", codec=\>\<LogStash::Code  
cs::Plain charset=\>"UTF-8"\>, stat\_interval=\>1, discover\_interval=\>15, sincedb\_write\_interval=\>15, delimiter=\>"\n"\>  
Error: Neither current working directory (null) nor pathname (\xxx.xxx.xxx.xxx/d$/logs/myserver.log) led to an absolute path {:level=\>:  
error}←[0m  
Logstash startup completed  
←[31mA plugin had an unrecoverable error. Will restart this plugin.  
Plugin: \<LogStash::Inputs::File path=\>["\\xxx.xxx.xxx.xxx/d$/logs/myserver.log"], start\_position=\>"beginning", codec=\>\<LogStash::Code  
cs::Plain charset=\>"UTF-8"\>, stat\_interval=\>1, discover\_interval=\>15, sincedb\_write\_interval=\>15, delimiter=\>"\n"\>  
Error: Neither current working directory (null) nor pathname (\xxx.xxx.xxx.xxx/d$/logs/myserver.log) led to an absolute path {:level=\>:  
error}←[0m

Please help me

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 2, 2015, 12:48pm UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/8 "2015-12-02T12:48:17Z")

</div>

Quoting myself:

> Also, I suspect that Logstash requires forward slashes instead of backslashes.

So, have you tried with forward slashes?

---

<div class="post-metadata">

**Author:** ![jayaram](https://avatars.discourse-cdn.com/v4/letter/j/ecccb3/32.png) [@jayaram](https://discuss.elastic.co/u/jayaram)\
**Post date:** [December 2, 2015, 12:50pm UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/9 "2015-12-02T12:50:01Z")

</div>

Yes both I tried same error

D:\basefarm\logstash-2.0.0\bin\>logstash -f logstashcfg.conf  
Picked up \_JAVA\_OPTIONS: -Xmx2048m -XX:MaxPermSize=512m  
Java HotSpot(TM) 64-Bit Server VM warning: ignoring option MaxPermSize=512m; support was removed in 8.0  
io/console not supported; tty will not be manipulated  
Default settings used: Filter workers: 1  
←[31mA plugin had an unrecoverable error. Will restart this plugin.  
Plugin: \<LogStash::Inputs::File path=\>["\\xxx.xxx.xxx.xxx\d$\logs\myserver.log"], start\_position=\>"beginning", codec=\>\<LogStash::C  
odecs::Plain charset=\>"UTF-8"\>, stat\_interval=\>1, discover\_interval=\>15, sincedb\_write\_interval=\>15, delimiter=\>"\n"\>  
Error: Neither current working directory (null) nor pathname (\xxx.xxx.xxx.xxxd$logsmyserver.log) led to an absolute path {:level=\>:err  
or}←[0m  
Logstash startup completed  
←[31mA plugin had an unrecoverable error. Will restart this plugin.  
Plugin: \<LogStash::Inputs::File path=\>["\\xxx.xxx.xxx.xxx\d$\logs\myserver.log"], start\_position=\>"beginning", codec=\>\<LogStash::C  
odecs::Plain charset=\>"UTF-8"\>, stat\_interval=\>1, discover\_interval=\>15, sincedb\_write\_interval=\>15, delimiter=\>"\n"\>  
Error: Neither current working directory (null) nor pathname (\xxx.xxx.xxx.xxxd$logsmyserver.log) led to an absolute path {:level=\>:err  
or}←[0m

---

<div class="post-metadata">

**Author:** ![aviv.ratzon](https://avatars.discourse-cdn.com/v4/letter/a/ed655f/32.png) [@aviv.ratzon](https://discuss.elastic.co/u/aviv.ratzon)\
**Post date:** [December 2, 2015, 2:18pm UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/10 "2015-12-02T14:18:20Z")

</div>

> [@jayaram](#):
>
> file { path =\> "`\*\*\*\*\*\*\*\d$\logs\myserver.log" start\_position =\> "beginning" }

Hi,  
I do this normally on our servers. this should work for you:

> ```
> file {
> path => "\\\\ ****** /d$/logs/myserver.log"
> start_position => "beginning"
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![RileyShu](https://avatars.discourse-cdn.com/v4/letter/r/f05b48/32.png) [@RileyShu](https://discuss.elastic.co/u/RileyShu)\
**Post date:** [August 24, 2016, 5:11pm UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/12 "2016-08-24T17:11:31Z")

</div>

I was getting the same error before, too. Simply changing backslashes to forward slashes worked great for me. It should be //xxx,x,x,x/e$/\*.log

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:41am UTC](https://discuss.elastic.co/t/fetching-logs-form-remote-host/2295/13 "2017-07-06T04:41:47Z")

</div>


