# Help in Data collection and indexing

**URL:** <https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802>\
**Category:** Elasticsearch\
**Created:** [May 7, 2018, 9:21am UTC](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802 "2018-05-07T09:21:24Z")\
**Posts on this page:** 7\
**Page:** 2

<div class="post-metadata">

**Author:** ![thompsonlau](https://avatars.discourse-cdn.com/v4/letter/t/e9a140/32.png) [@thompsonlau](https://discuss.elastic.co/u/thompsonlau)\
**Post date:** [May 17, 2018, 1:11am UTC](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802/21 "2018-05-17T01:11:36Z")

</div>

I run the follow command to enable logstash

systemctl start logstash.service

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 17, 2018, 9:03am UTC](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802/22 "2018-05-17T09:03:12Z")

</div>

Then it's probably in logstash logs.

I'm running logstash manually while I'm still developing instead of running as a service so I can see immediately the logs in my console.

---

<div class="post-metadata">

**Author:** ![thompsonlau](https://avatars.discourse-cdn.com/v4/letter/t/e9a140/32.png) [@thompsonlau](https://discuss.elastic.co/u/thompsonlau)\
**Post date:** [May 17, 2018, 11:02am UTC](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802/23 "2018-05-17T11:02:30Z")

</div>

Do you mean logstash-plain.log?

---

<div class="post-metadata">

**Author:** ![thompsonlau](https://avatars.discourse-cdn.com/v4/letter/t/e9a140/32.png) [@thompsonlau](https://discuss.elastic.co/u/thompsonlau)\
**Post date:** [May 17, 2018, 11:11am UTC](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802/24 "2018-05-17T11:11:32Z")

</div>

The log in logstash as below,

```
[2018-05-17T19:03:38,851][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"fb_apache", :directory=>"/usr/share/logstash/modules/fb_apache/configuration"}
[2018-05-17T19:03:38,856][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"netflow", :directory=>"/usr/share/logstash/modules/netflow/configuration"}
[2018-05-17T19:03:39,006][INFO][logstash.modules.scaffold] Initializing module {:module_name=>"arcsight", :directory=>"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/x-pack-6.2.4-java/modules/arcsight/configuration"}
[2018-05-17T19:03:39,048][INFO][logstash.configmanagement.bootstrapcheck] Using Elasticsearch as config store {:pipeline_id=>["apache", "cloudwatch_logs"], :poll_interval=>"5000000000ns"}
[2018-05-17T19:03:39,167][ERROR][logstash.licensechecker.licensemanager] Unable to retrieve license information from license server {:message=>"Bad scheme 'localhost' found should be one of http/https", :class=>"LogStash::ConfigurationError"}
[2018-05-17T19:03:39,168][WARN][logstash.licensechecker.xpackinfo] Nil response from License Server
[2018-05-17T19:03:39,186][ERROR][logstash.configmanagement.elasticsearchsource] Configuration Management is not available: License information is currently unavailable. Please make sure you have added your production elasticsearch connection info in the xpack.management.elasticsearch settings.
[2018-05-17T19:03:39,192][FATAL][logstash.runner] An unexpected error occurred! {:error=>#<LogStash::LicenseChecker::LicenseError: Configuration Management is not available: License information is currently unavailable. Please make sure you have added your production elasticsearch connection info in the xpack.management.elasticsearch settings.>, :backtrace=>["/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/x-pack-6.2.4-java/lib/license_checker/licensed.rb:78:in `with_license_check'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/x-pack-6.2.4-java/lib/config_management/elasticsearch_source.rb:48:in `initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/x-pack-6.2.4-java/lib/config_management/hooks.rb:52:in `after_bootstrap_checks'", "/usr/share/logstash/logstash-core/lib/logstash/event_dispatcher.rb:34:in `block in fire'", "/usr/share/logstash/logstash-core/lib/logstash/event_dispatcher.rb:32:in `fire'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:279:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/clamp-0.6.5/lib/clamp/command.rb:67:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:219:in `run'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/clamp-0.6.5/lib/clamp/command.rb:132:in `run'", "/usr/share/logstash/lib/bootstrap/environment.rb:67:in `<main>'"]}
[2018-05-17T19:03:39,198][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: org.jruby.exceptions.RaiseException: (SystemExit) exit
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 17, 2018, 11:35am UTC](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802/25 "2018-05-17T11:35:36Z")

</div>

Please format your code, logs or configuration files using `</>` icon as explained in [this guide](https://discuss.elastic.co/t/about-the-elasticsearch-category/21) and not the citation button. It will make your post more readable.

Or use markdown style like:

````
```
CODE
```

````

There's a live preview panel for exactly this reasons.

Lots of people read these forums, and many of them will simply skip over a post that is difficult to read, because it's just too large an investment of their time to try and follow a wall of badly formatted text.  
If your goal is to get an answer to your questions, it's in your interest to make it as easy to read and understand as possible.  
Please update your post.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [May 17, 2018, 11:36am UTC](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802/26 "2018-05-17T11:36:40Z")

</div>

For a walk through of building an integration from raw data all the way to Kibana Dashboards this might help...

[https://github.com/robcowart/eslog\_tutorial/blob/master/eslog\_tutorial.pdf](https://github.com/robcowart/eslog_tutorial/blob/master/eslog_tutorial.pdf)

Also, to get started with syslog, take a look at this...

> **[koiossian/synesis\_lite\_syslog](https://github.com/koiossian/synesis_lite_syslog)**
>
> synesis\_lite\_syslog - Syslog collection with Elastic Stack

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2018, 11:36am UTC](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802/27 "2018-06-14T11:36:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

[Previous page](https://discuss.elastic.co/t/help-in-data-collection-and-indexing/130802.md?page=1)
